Cloudflare Expands PCI DSS Coverage to More Products
Cloudflare has maintained PCI DSS compliance since 2014, operating as both a Level 1 Merchant and as a service provider. Level 1 is the highest merchant tier, reserved for organizations handling the largest transaction volumes. Each year, a Qualified Security Assessor performs a full review of Cloudflare's technical environment, validating that controls around the transmission, processing, and storage of cardholder data meet the PCI Data Security Standard.
The PCI standard applies to any organization that accepts credit or debit cards for payment. The compliance framework exists to protect financial institutions and customers from payment card information compromise. Payment card brands sort merchants into tiers based on annual transaction volume, with each tier requiring different levels of compliance activity.
This year, Cloudflare has expanded its Service Provider scope beyond its WAF to include additional products under its latest Attestation of Compliance.
New Products Added to Compliance Scope
The Cloudflare Content Delivery Network, Cloudflare Access, and the Cloudflare Time Service are now certified under Cloudflare's latest Attestation of Compliance. This designation applies to all Business and Enterprise accounts. Customers can use the attestation to simplify their own PCI audits, removing the burden of managing these services or appliances locally.
The expansion gives customers additional tools to meet specific PCI DSS requirements:
- WAF and OWASP ruleset: Enabling the WAF with the OWASP ruleset, tuned to the specific environment, satisfies PCI requirement 6.6 for protecting web-facing applications.
- Cloudflare Access: Organizations often rely on VPNs and segmentation to reduce PCI scope. Cloudflare Access offers an alternative segmentation method by using Cloudflare's global network as a VPN service for internal resources. Sessions can be configured to time out after 15 minutes of inactivity, helping customers meet requirement 8.1.8.
- Cloudflare Time Service: The time.cloudflare.com NTP service, announced in 2019, synchronizes all Cloudflare servers with stratum 1 time service providers. Using Cloudflare's anycast network of 200 locations worldwide routes packets to the closest server, offering latency and accuracy advantages. Accurate time services support audit logging and incident response, helping meet requirement 10.4.3.
- TLS configuration: Cloudflare supports up to TLS 1.3 in the Cloudflare dashboard, exceeding the TLS 1.1 minimum referenced in requirement 4.1.
Cloudflare uses these same products internally to secure its own cardholder data environment.
Verifying Compliance Status
Cloudflare's compliance posture applies to Cloudflare's own transmission and processing of cardholder data, provides assurance to customers who transmit cardholder data through Cloudflare products, and ensures anyone interacting with Cloudflare services has their information transmitted securely.
Customers can track Cloudflare's latest certifications on the compliance certification page at www.cloudflare.com/compliance, which currently lists compliance status across all certifications and provides access to the SOC 3 report.



