
Episode #7
The PCI Scope Trap
An ISV doesn’t have to store card data to have PCI responsibilities. If its software, integrations, access, vendors, or deployment processes can impact the security of cardholder data, it may already be operating as a service provider. In this episode, Kitty and Chris sit down with Steve Levinson of LHC Advisors to break down the PCI scope trap, the service-provider requirements many ISVs overlook, and why relying on a compliant payment vendor doesn’t make the responsibility disappear. They also discuss Level 1 versus Level 2 validation, QSA-led assessments, vendor-chain attacks, breach exposure, and why strong PCI evidence is quickly becoming a commercial requirement, not just a compliance exercise.






