Skip to content

InsightsPublished 7 min read

PCI DSS IT Provider Claims in Chicago, 2026

two doorways, one dim and one bright, joined by a bridge
Listen to this article · 11:06 · AI-generated narration
0:00 / 11:06
Chapters

Disclosure: this site is owned and operated by XL.net, a Chicago MSP that is itself ranked here. How we handle that conflict.

How often is PCI DSS listed among Chicago providers?

PCI DSS is the most common framework entry in our data. As of 2026-09-29, we track 97 active Chicago vendors, most of them Managed Service Providers (MSPs). IT Support Chicago's vendor records list PCI DSS for 20 of the Chicago vendors we track, more than any other security framework.

The next most common entries in our records are Cybersecurity Maturity Model Certification (CMMC) Level 1 at 17 vendors and System and Organization Controls (SOC) 2 Type I at 11 vendors. SOC 2 Type II and International Organization for Standardization (ISO) 27001 follow at 7 vendors each. These counts show how often a framework is listed in our records. They say nothing about how many of those entries are third-party documented.

A count of firms is a count of what our records hold. A Chicago provider outside the 20 is one we hold no PCI DSS record for. That does not mean the provider lacks PCI DSS work or qualifications. A frequently listed framework also does not mean many providers meet it. Treat any PCI DSS entry you find as a question to put to the provider, not as an answer.

TL;DR

When reading PCI DSS IT provider claims, start with frequency: the Payment Card Industry Data Security Standard (PCI DSS) is the most frequently listed security framework in our records, appearing for 20 of the Chicago vendors we track. In our tables, a (claimed) PCI DSS entry is the firm's own claim. We hold no third-party documentation for it, and it is neither an audit result nor a verdict on security. Such claims add 5 points each to our Security Certification criterion, capped at 25/100, so buyers should request PCI DSS evidence directly from any shortlisted provider.

  • PCI DSS is listed for 20 of the Chicago vendors we track, more than any other framework in our records.
  • A (claimed) entry is the firm's own claim. It is not a certification, an audit finding, or a security rating.
  • Our Security Certification criterion adds 5 points per entry that is the firm's own claim, capped at 25/100.
  • Treat any PCI DSS listing as a prompt to request evidence, not as proof.

What does the Payment Card Industry Data Security Standard cover?

PCI DSS is the standard the card brands require of firms that store, process, or transmit cardholder data. That is why a buyer handling card payments should read a provider's PCI DSS entry closely. If your business never touches card data, ask whether the entry bears on your engagement at all before weighing it.

IT Support Chicago advises any business taking card payments to confirm which of its systems store, process, or transmit cardholder data before comparing providers. List the point-of-sale terminals, payment pages, networks, and back-office systems involved. Then note which of them a provider would manage. If the provider will administer those systems, give its PCI DSS entry more scrutiny than you would for an engagement limited to help desk support.

Ask each provider how the services in its proposal relate to your own PCI DSS obligations, and get the answer in writing. Industry labels help only a little here. Of the 63 firms that publish industries on their own websites, 18 advertise retail. That is a claim we recorded, not a capability we assessed. Retailers can use our Chicago retail IT provider checklist for related questions.

What does a (claimed) PCI DSS entry mean?

In our tables, a (claimed) PCI DSS entry is the firm's own claim. It means we hold no third-party documentation for it. It does not mean the firm has been certified or audited, and it is no verdict on how secure the firm is.

The other mark we use, ✓, means an entry is third-party documented. For those entries we hold a named third-party issuer's document, evidence hosted off the firm's own domain, or a public registry entry. Both marks describe our own records. IT Support Chicago's certification marks record documentation we hold, never an audit result or a judgment of a firm's security.

Read the mark in both directions. A (claimed) entry may reflect genuine PCI DSS work backed by evidence we have simply not obtained. Equally, a listing on its own proves nothing. Either way, a buyer reaches the same conclusion: the evidence has to come from the provider, and checking it is your job, not something our table has done for you.

How does our Security Certification criterion score a PCI DSS claim?

A PCI DSS entry that is the firm's own claim adds 5 points to our Security Certification criterion. Claims of this kind are capped at 25/100, so listing more frameworks cannot inflate that part of the score without limit. Certifications that are third-party documented are scored additively by tier and checked automatically per certification.

IT Support Chicago's Security Certification criterion carries a weight of 24 of 100 in our published score. It is one of 4 criteria. The others are Client Reputation (weight 29 of 100), Employee Reputation (weight 20 of 100), and Proactive Issue Reduction (weight 27 of 100). We scored Security Certification for 87 of 97 firms, with a median of 10.0, a mean of 11.6, and a middle half from 0.0 to 20.0.

The cap has a limit of its own. It bounds what entries that are the firm's own claim can add within the Security Certification criterion, but it cannot tell you whether any single claim is sound. Our certification claim scoring guide walks through the model in more detail.

The pattern in our top-scored table

In IT Support Chicago's top-scored table, PCI DSS entries carrying the firm's own claim mark appear repeatedly in the certification cells. The pattern tells a buyer to request PCI DSS evidence directly from any provider they shortlist rather than read the listing as proof.

We read the table as a pattern, not a ranking. A firm's position comes from 4 weighted criteria, and a certification mark says nothing about where a provider belongs on your shortlist. We do not order firms by their marks, and buyers should not either.

The same table records weaknesses next to the certification cells. They include client reviews on a single platform only, recent ratings trending down, below-average employee reviews, and a heavily reactive support model. Weigh a PCI DSS entry together with notes like these, not in isolation. A provider that looks strong on paper for payment security still has to run your systems day to day, so ask each shortlisted provider how it would address any weakness our data records for it.

What should you ask before relying on a PCI DSS entry?

Ask for the evidence itself, then confirm that it covers the services you are buying. IT Support Chicago advises buyers to request the third-party document behind any PCI DSS entry, with the issuer's name, before signing.

Check where that evidence lives: a named issuer's document, a page hosted off the provider's own domain, or a public registry entry. Check its date and scope, including which entities, locations, and services it covers, and whether those match what the provider will run for you. Ask which party is responsible for each control on systems that touch cardholder data, and write that split into the agreement. Apply the same questions to broader IT provider security framework claims, such as SOC 2 and ISO 27001 entries. Our certification verification checklist sets these steps out in order.

Contract terms matter too. Our position is that shorter agreements are generally better for the buyer, and that long lock-ins primarily benefit the vendor. If PCI DSS evidence is promised but not yet delivered, we advise against committing to a multi-year term on the strength of a listing.

Limits of our PCI DSS data

Our marks describe documentation we hold, not a provider's compliance, and certainly not yours. IT Support Chicago's certification records cannot tell a buyer whether their own card-handling environment meets PCI DSS. Our tables do not record the scope, date, or issuer behind a (claimed) entry, which is why the questions above fall to the buyer.

Absence works the same way. A provider with no PCI DSS entry is one we hold no record for, and a provider may do relevant work it has never listed. The industry figures we cite come from firms' own websites, as read by our crawler. They are claims we recorded, never capabilities we assessed. Use our data to decide which questions to ask and which providers to ask first, then rely on the evidence each provider puts in front of you.

Frequently asked questions

Does a (claimed) PCI DSS entry mean an IT provider is certified?

No. In our tables, a (claimed) PCI DSS entry is the firm's own claim: we hold no third-party documentation for it, and it does not mean the firm has been certified or audited. Ask the provider for the underlying evidence.

How many points does a PCI DSS entry that is the firm's own claim add to a provider's score?

It adds 5 points to our Security Certification criterion. Claims of this kind are capped at 25/100, and the criterion carries a weight of 24 of 100 in our published score.

Should I rule out a provider whose PCI DSS entry is the firm's own claim?

Not on that basis alone. The mark describes our records, not the firm's security. Request the third-party document behind the entry, check that its scope matches your services, and weigh it alongside the provider's review and weakness data.

All articles