When your business uses Microsoft 365 for email and needs to undergo a PCI DSS supplier security check, it's important to prepare clear and accurate information about how your email system is managed and secured. PCI DSS (Payment Card Industry Data Security Standard) requires organisations handling payment card data to demonstrate strong controls around data security, including email systems that may process or transmit sensitive information.
Failing to properly prepare your Microsoft 365 email details can lead to delays in supplier approval, increased audit scrutiny, or even potential compliance gaps. This can impact your business through increased risk of data breaches, interruptions to email service, and damage to customer trust—especially if payment data is involved. Ensuring your email environment is secure and well-documented helps maintain smooth operations and supports your wider compliance efforts under UK GDPR and the Data Protection Act 2018.
Typical scenario for a UK SME
Consider a UK business with around 50 staff that processes card payments online and via email. Their IT provider manages Microsoft 365, but when the PCI DSS audit arrives, the business struggles to provide clear evidence of email security controls. The auditor requests details on multi-factor authentication (MFA), access controls, email encryption, and logging. The IT partner steps in to gather this information by reviewing Microsoft 365 security settings, confirming MFA is enabled for all users, checking mailbox access permissions, and verifying email retention policies. They then compile a report demonstrating compliance with PCI DSS email-related requirements, helping the business pass the audit without costly delays.
Key information to prepare for your PCI DSS supplier check
- Multi-factor authentication (MFA): Confirm MFA is enabled for all Microsoft 365 accounts, especially those with access to payment data.
- Access controls: Review and document who has mailbox access, including delegated permissions and shared mailboxes.
- Email encryption: Ensure sensitive emails are protected using Microsoft 365's encryption features or secure email gateways.
- Audit logs: Check that mailbox and login activity is logged and retained according to PCI DSS requirements.
- Backup and recovery: Verify that email data is regularly backed up and can be restored promptly if needed.
- Security policies: Gather your organisation's email usage policies, password policies, and incident response procedures relevant to email security.
- Vendor questionnaire responses: Prepare clear answers to supplier security questionnaires about Microsoft 365 email controls.
Questions to ask your IT provider
- Can you provide documentation on Microsoft 365 security settings related to email?
- Do you enforce MFA for all users accessing email?
- How do you manage mailbox access permissions and monitor for unusual activity?
- What encryption methods are in place for emails containing payment or personal data?
- How often are email backups performed, and how quickly can data be restored?
- Can you assist with completing PCI DSS supplier security questionnaires?
Preparing Microsoft 365 email information for a PCI DSS supplier security check is a practical step that helps protect your business and supports compliance with industry standards. A trusted managed IT provider or advisor can help you gather the necessary evidence, review your security settings, and guide you through the process. This proactive approach reduces risk, minimises disruption, and builds confidence with your suppliers and customers.