2026-01-28
Keeping PCI scope honest in a multi-account AWS estate
How cardholder data environments sprawl across accounts—and how audit sampling can catch silent expansions.
Multi-account AWS layouts help isolate workloads, yet PCI scope often creeps when shared logging accounts, CI runners, or analytics pipelines can reach cardholder data stores.
During cloud compliance audits we trace data flows, not org-chart boxes. A staging account that mirrors production schemas, or a data lake that ingests tokenized-but-reversible payloads, can pull systems into scope without anyone updating the network diagram.
Quarterly control sampling—focused on IAM trust policies, VPC peering, and KMS grants—keeps the documented CDE aligned with reality between annual assessments.