Knowledge center
What is the cardholder data environment or CDE?
The CDE includes the people, processes and technologies that store, process or transmit cardholder data or sensitive authentication data.
Why it matters
Connected systems or components that can affect CDE security may also influence scope.
What to confirm
- Where payment information flows
- Connected networks and systems
- People and third parties with access or change capability
Official PCI DSS documentation · PCI DSS v4.0.1 · reviewed 2026-07-31
This content is informational and is not legal advice. The applicable route and validation method depend on the operation and requesting party.