PCI DSS v4.0
Operational

Vendor & Third-Party Management Policy Template

Management of third-party service providers with access to or impact on cardholder data and the CDE.

What This Policy Covers

Purpose and Scope-Policy objectives and TPSP definition.
TPSP Inventory-Maintaining a list of all service providers and their CDE access.
Due Diligence Requirements-Pre-engagement security assessment process.
Contractual Security Requirements-PCI DSS responsibility matrix and contractual obligations.
Ongoing Monitoring-Annual confirmation of TPSP PCI DSS compliance status.
TPSP Termination-Off-boarding and access revocation procedures.

Required Sections

A compliant Vendor & Third-Party Management Policy for PCI DSS v4.0 must include the following6 sections. Each section addresses a specific control requirement that auditors will review.

1

Purpose and Scope

Policy objectives and TPSP definition.

2

TPSP Inventory

Maintaining a list of all service providers and their CDE access.

3

Due Diligence Requirements

Pre-engagement security assessment process.

4

Contractual Security Requirements

PCI DSS responsibility matrix and contractual obligations.

5

Ongoing Monitoring

Annual confirmation of TPSP PCI DSS compliance status.

6

TPSP Termination

Off-boarding and access revocation procedures.

Generate a Customized Version

This template shows the required structure. PoliWriter generates a fully customized Vendor & Third-Party Management Policy that references your actual cloud providers, identity systems, tools, and team practices — ready for auditor review.