PCI DSS Responsibility Matrix
Cobalt Payments Inc. — gateway.cxbolt.com
Effective Date: July 31, 2026 Standard: PCI DSS v4.0 / v4.0.1
Referenced by Terms of Use Section 11 and Privacy Policy Section 14. It allocates responsibility for PCI DSS requirements between the platform side (Cobalt together with its validated gateway and processor) and the Merchant.
⚠ READ THIS FIRST
Using the Services does NOT make you PCI DSS compliant. Card data is captured directly by NMI using hosted fields and tokenization and does not transit Cobalt-controlled servers; NMI and Fiserv, Inc. (First Data) each maintain their own PCI DSS validation. Cobalt’s environment is therefore not a cardholder data environment and Cobalt does not hold a separate Attestation of Compliance. Platform-side validation never extends to your environment. You must independently validate your own compliance — completing the correct Self-Assessment Questionnaire ("SAQ") or Report on Compliance, and maintaining a compliant environment.
This matrix is guidance, not a compliance opinion or certification. Your actual responsibilities depend on your integration method, your environment, and your acquirer’s requirements. Consult a Qualified Security Assessor. Cobalt does not determine your merchant level, your SAQ type, or your validation obligations.
1. Legend
| Mark | Meaning |
|---|---|
| C | Platform side — Cobalt and/or its validated gateway (NMI) and processor (Fiserv) |
| M | Merchant responsible |
| S | Shared — each party for its own environment |
2. Which SAQ applies to you
| Your integration | Typical SAQ | Notes |
|---|---|---|
| Hosted payment page / pay link — you fully redirect and never touch card data | SAQ A | Lowest scope |
| Embedded/iframe fields where card data is captured directly by the gateway | SAQ A-EP | Your page affects the security of the payment page |
| Virtual Terminal — your staff key card data into a browser on an isolated workstation | SAQ C-VT | Manual entry only, no card storage |
| Point of Sale / Register with a card reader or terminal | SAQ B-IP / SAQ C / SAQ P2PE | Depends on the device and whether it is validated P2PE |
| Your own application transmitting card data to the gateway | SAQ D | Largest scope |
| Mixed channels | Usually SAQ D or per-channel validation | Confirm with your acquirer |
M — You determine and complete the correct SAQ. This table is illustrative and is not a determination.
3. Requirement-Level Allocation
| PCI DSS Req. | Summary | Cobalt environment | Your environment |
|---|---|---|---|
| 1 | Network security controls, firewalls, segmentation | C | M — your network, routers, Wi-Fi, and any segmentation of POS workstations |
| 2 | Secure configurations; no vendor defaults | C | M — your workstations, terminals, routers, and servers |
| 3 | Protect stored account data; encryption, tokenization, key management | C — Cobalt tokenizes and does not retain PAN or sensitive authentication data post-authorization | M — do not store PAN, track data, CVV, or PIN. Never enter card data into free-text fields (notes, item names, task comments) |
| 4 | Protect cardholder data in transit; strong cryptography | C — TLS to and from the Portal and gateway | M — your browser, device, and network; keep TLS current; never transmit card data by email, SMS, or chat |
| 5 | Anti-malware | C | M — your endpoints and POS devices |
| 6 | Secure development and vulnerability management | C — for the Portal | M — for your website, cart, plugins, and any custom integration; patch promptly |
| 7 | Restrict access by business need to know | C — internal least privilege | M — your user roles and permissions in the Portal are yours to configure and supervise |
| 8 | Identify users and authenticate access | C — offers MFA, password hashing, session controls | M — unique logins per person (never shared), strong passwords, enable MFA, deactivate departed personnel immediately |
| 9 | Restrict physical access | C — data centers, via hosting provider | M — your premises, terminals, card readers, printed receipts, and paper records; inspect devices for tampering/skimming |
| 10 | Log and monitor all access | C — platform logging and monitoring | M — logs for your own systems; review your Portal activity and audit trails |
| 11 | Test security regularly | C — scanning and penetration testing of the Portal | M — ASV scans of your externally facing environment where required, and your own testing |
| 12 | Information security policy and program | C — Cobalt’s program | M — your written security policy, personnel screening and training, and incident-response plan |
| A1 | Multi-tenant service provider protections | C | N/A |
| A3 | Designated Entities Supplemental Validation (if imposed) | C if imposed on Cobalt | M if imposed on you |
4. Additional Allocations
| Topic | Responsible | Detail |
|---|---|---|
| Validating and documenting your PCI compliance | M | SAQ/ROC, ASV scans, attestation to your acquirer |
| Validated-provider attestations (NMI, Fiserv) | C | Requestable under confidentiality (DPA Section 10). Cobalt does not hold a separate AOC. |
| Selecting PCI-approved PIN entry devices and P2PE solutions | M | Cobalt does not certify third-party hardware |
| Device inventory and tamper inspection (Req. 9.5) | M | Maintain an inventory and inspect readers/terminals periodically |
| Vendor management for your integrations, plugins, and carts | M | Including your web host and shopping cart |
| Incident response and forensics | S | Each for its own environment; you must notify security@cxbolt.com within 24 hours and cooperate with any network-mandated PCI Forensic Investigator |
| Fines, assessments, and forensic costs from a compromise in your environment | M | Per Terms of Use Sections 9.2 and 9.3 — deemed direct damages, outside the liability cap |
| Cardholder notification after a compromise you control | M | Cobalt will assist as described in DPA Section 9 |
5. Scope-Reduction Guidance
To reduce your PCI scope: use hosted payment pages or pay links (full redirect) rather than capturing card data yourself; use validated P2PE card readers; use tokenized cards on file rather than storing card data; never accept card data by email, SMS, chat, voicemail, or paper; and isolate any Virtual Terminal workstation from other systems and from general internet browsing.
6. Disclaimer
This matrix is provided for informational purposes only. It is not legal advice, a compliance certification, a QSA opinion, or a warranty that following it will achieve or maintain PCI DSS compliance. PCI DSS is a contractual standard enforced by the card networks and your acquirer, and your obligations are determined by them — not by Cobalt. See Terms of Use Sections 16.4, 19, and 20.
© 2026 Cobalt Payments Inc. All rights reserved. Cobalt Payments Inc. is a registered ISO of Wells Fargo Bank, N.A., Concord, CA. The Clover trademark logo is owned by Clover Network, Inc., a First Data company. All other trademarks, service marks and trade names referenced in this material are the property of their respective owners.