We use essential cookies to run this site. Analytics & marketing cookies load only with your consent — see our Cookie Policy and Privacy Policy.

Airlines and travel

PCI DSS for Airlines, OTAs and Travel Platforms

Travel is the hardest PCI DSS environment to scope: card data arrives through web, app, call centre, agents and GDS integrations, and often persists in booking records and support tooling long after the transaction. Scope, not control maturity, is what drives cost here.

What PCI DSS requires of airlines and travel

  • Data-flow mapping across every acceptance channel, including agent and GDS paths.
  • Call-centre controls — recording, pause-and-resume, and agent desktop restrictions where card data is spoken.
  • Retention review of booking records, PNR data and support tickets that may hold card data.
  • Tokenisation of stored card data to take systems out of scope, which is the dominant cost lever.
  • Third-party management across GDS, payment gateways and outsourced contact centres.

Evidence assessors actually ask for

Documentation is rarely the blocker — evidence that controls genuinely operate is. These are the artefacts requested first in this sector.

  • Channel-by-channel data-flow diagrams reconciled against actual traffic
  • Call recording configuration proving card data is not captured
  • Retention and deletion evidence for booking and support records
  • Tokenisation architecture and the systems it removes from scope
  • Vendor attestations across GDS, gateway and contact-centre partners

Where airlines and travel usually come unstuck

  • Card data captured in call recordings and quality-monitoring systems.
  • PNR and support tickets retaining card data outside the defined CDE.
  • Outsourced contact centres treated as out of scope without attestation.

Related

PCI DSS assessmentAirlines & travelPCI DSS consultantsTravel case study
Scope this engagement →What it costs
PCI SSC Qualified Security Assessor — CYBERSIGMA CONSULTING SERVICES LLP

QSA Authorised
CEMEA · Asia Pacific · USA

Ready to discuss your PCI DSS requirement?

CERT-In empanelled · PCI QSA authorised — a senior consultant responds within 4 business hours. Free, no obligation.

Delivering from Noida · Mumbai · Bengaluru · Pune · Dubai · Cairo · Melbourne see all locations & addresses →