PCI DSS Responsibility Matrix

Cobalt Payments Inc. — gateway.cxbolt.com

Effective Date: July 31, 2026 Standard: PCI DSS v4.0 / v4.0.1

Referenced by Terms of Use Section 11 and Privacy Policy Section 14. It allocates responsibility for PCI DSS requirements between the platform side (Cobalt together with its validated gateway and processor) and the Merchant.


⚠ READ THIS FIRST

Using the Services does NOT make you PCI DSS compliant. Card data is captured directly by NMI using hosted fields and tokenization and does not transit Cobalt-controlled servers; NMI and Fiserv, Inc. (First Data) each maintain their own PCI DSS validation. Cobalt’s environment is therefore not a cardholder data environment and Cobalt does not hold a separate Attestation of Compliance. Platform-side validation never extends to your environment. You must independently validate your own compliance — completing the correct Self-Assessment Questionnaire ("SAQ") or Report on Compliance, and maintaining a compliant environment.

This matrix is guidance, not a compliance opinion or certification. Your actual responsibilities depend on your integration method, your environment, and your acquirer’s requirements. Consult a Qualified Security Assessor. Cobalt does not determine your merchant level, your SAQ type, or your validation obligations.


1. Legend

Mark Meaning
C Platform side — Cobalt and/or its validated gateway (NMI) and processor (Fiserv)
M Merchant responsible
S Shared — each party for its own environment

2. Which SAQ applies to you

Your integration Typical SAQ Notes
Hosted payment page / pay link — you fully redirect and never touch card data SAQ A Lowest scope
Embedded/iframe fields where card data is captured directly by the gateway SAQ A-EP Your page affects the security of the payment page
Virtual Terminal — your staff key card data into a browser on an isolated workstation SAQ C-VT Manual entry only, no card storage
Point of Sale / Register with a card reader or terminal SAQ B-IP / SAQ C / SAQ P2PE Depends on the device and whether it is validated P2PE
Your own application transmitting card data to the gateway SAQ D Largest scope
Mixed channels Usually SAQ D or per-channel validation Confirm with your acquirer

M — You determine and complete the correct SAQ. This table is illustrative and is not a determination.

3. Requirement-Level Allocation

PCI DSS Req. Summary Cobalt environment Your environment
1 Network security controls, firewalls, segmentation C M — your network, routers, Wi-Fi, and any segmentation of POS workstations
2 Secure configurations; no vendor defaults C M — your workstations, terminals, routers, and servers
3 Protect stored account data; encryption, tokenization, key management C — Cobalt tokenizes and does not retain PAN or sensitive authentication data post-authorization Mdo not store PAN, track data, CVV, or PIN. Never enter card data into free-text fields (notes, item names, task comments)
4 Protect cardholder data in transit; strong cryptography C — TLS to and from the Portal and gateway M — your browser, device, and network; keep TLS current; never transmit card data by email, SMS, or chat
5 Anti-malware C M — your endpoints and POS devices
6 Secure development and vulnerability management C — for the Portal M — for your website, cart, plugins, and any custom integration; patch promptly
7 Restrict access by business need to know C — internal least privilege Myour user roles and permissions in the Portal are yours to configure and supervise
8 Identify users and authenticate access C — offers MFA, password hashing, session controls Munique logins per person (never shared), strong passwords, enable MFA, deactivate departed personnel immediately
9 Restrict physical access C — data centers, via hosting provider Myour premises, terminals, card readers, printed receipts, and paper records; inspect devices for tampering/skimming
10 Log and monitor all access C — platform logging and monitoring M — logs for your own systems; review your Portal activity and audit trails
11 Test security regularly C — scanning and penetration testing of the Portal MASV scans of your externally facing environment where required, and your own testing
12 Information security policy and program C — Cobalt’s program Myour written security policy, personnel screening and training, and incident-response plan
A1 Multi-tenant service provider protections C N/A
A3 Designated Entities Supplemental Validation (if imposed) C if imposed on Cobalt M if imposed on you

4. Additional Allocations

Topic Responsible Detail
Validating and documenting your PCI compliance M SAQ/ROC, ASV scans, attestation to your acquirer
Validated-provider attestations (NMI, Fiserv) C Requestable under confidentiality (DPA Section 10). Cobalt does not hold a separate AOC.
Selecting PCI-approved PIN entry devices and P2PE solutions M Cobalt does not certify third-party hardware
Device inventory and tamper inspection (Req. 9.5) M Maintain an inventory and inspect readers/terminals periodically
Vendor management for your integrations, plugins, and carts M Including your web host and shopping cart
Incident response and forensics S Each for its own environment; you must notify security@cxbolt.com within 24 hours and cooperate with any network-mandated PCI Forensic Investigator
Fines, assessments, and forensic costs from a compromise in your environment M Per Terms of Use Sections 9.2 and 9.3 — deemed direct damages, outside the liability cap
Cardholder notification after a compromise you control M Cobalt will assist as described in DPA Section 9

5. Scope-Reduction Guidance

To reduce your PCI scope: use hosted payment pages or pay links (full redirect) rather than capturing card data yourself; use validated P2PE card readers; use tokenized cards on file rather than storing card data; never accept card data by email, SMS, chat, voicemail, or paper; and isolate any Virtual Terminal workstation from other systems and from general internet browsing.

6. Disclaimer

This matrix is provided for informational purposes only. It is not legal advice, a compliance certification, a QSA opinion, or a warranty that following it will achieve or maintain PCI DSS compliance. PCI DSS is a contractual standard enforced by the card networks and your acquirer, and your obligations are determined by them — not by Cobalt. See Terms of Use Sections 16.4, 19, and 20.


© 2026 Cobalt Payments Inc. All rights reserved. Cobalt Payments Inc. is a registered ISO of Wells Fargo Bank, N.A., Concord, CA. The Clover trademark logo is owned by Clover Network, Inc., a First Data company. All other trademarks, service marks and trade names referenced in this material are the property of their respective owners.

© 2026 Cobalt Payments Inc. All rights reserved. Registered ISO of Wells Fargo Bank, N.A., Concord, CA.

← Back to gateway.cxbolt.com