What Falls Inside Cardholder Data Scope
Cardholder data scope covers every system that stores, processes, or transmits a card number, and every system connected to those. Scope is what determines the obligation, which is why reducing it matters more than securing it: one terminal that never sees a full card number is outside it entirely.
Frontline staff rarely hear scope explained and consequently create it by accident. A card number written on a notepad, emailed to a colleague, or read aloud into a recorded call pulls an ordinary system into scope and into an assessment nobody planned for. What does not belong on screen is your own network diagram and assessment findings: segmentation detail and open remediation items are exactly what an attacker or a competitor would want.
The template covers it in nine scenes: two on what cardholder data is and what scope means, two on the three prohibited storage behaviours staff most often perform, one on taking a payment by phone, one on refunds and chargebacks, one on what to do when a card number arrives somewhere it should not, one on access control, and one on where to ask before improvising.

