---
title: How to Create a PCI DSS Payment Data Flow Diagram
description: PCI-DSS Payment Data Flow Diagram
---

[Skip to content](https://knowledge.adoptech.co.uk/how-to-create-a-pci-dss-payment-data-flow-diagram#main-content)

[![Adoptech-logo-GreyWithoutStrapline-1.png\]](https://knowledge.adoptech.co.uk/hs-fs/hubfs/Adoptech-logo-GreyWithoutStrapline-1.png?height=39&name=Adoptech-logo-GreyWithoutStrapline-1.png)](https://knowledge.adoptech.co.uk/?hsLang=en)

Open main navigation

Close main navigation

 Adoptech Help Centre

- There are no suggestions because the search field is empty.

1. [Knowledge base](https://knowledge.adoptech.co.uk/?hsLang=en)
2. [Frameworks & Certifications](https://knowledge.adoptech.co.uk/frameworks-certifications?hsLang=en)
3. [PCI-DSS](https://knowledge.adoptech.co.uk/frameworks-certifications?hsLang=en#pci-dss)

# How to Create a PCI DSS Payment Data Flow Diagram

## This article explains how to create a PCI DSS payment data flow diagram in a simple, practical way.

You do **not** need to be a security architect or draw a highly technical diagram.

The goal is to clearly show **how cardholder data moves through (or around) your systems** so PCI DSS scope can be defined accurately.

---

#### Why PCI DSS requires a payment data flow diagram

PCI DSS scope is determined by **where cardholder data flows**.

A payment data flow diagram helps to:

- Identify systems in scope (the Cardholder Data Environment, or CDE)
- Identify systems connected to the CDE
- Support correct SAQ selection
- Explain scope decisions to banks, processors, or assessors
- Reduce unnecessary PCI DSS effort

Under PCI DSS v4.x, organisations are expected to **understand and document their payment architecture** — this diagram is a key part of that.

---

#### What a payment data flow diagram should (and shouldn’t) be

### It **should**

- Show how card data enters, moves through, and exits your environment
- Focus on *flows*, not deep technical detail
- Be understandable by a non-technical reviewer
- Reflect how payments work **today**

### It **should not**

- Be a full network diagram
- Include IP addresses or firewall rules
- Try to cover your entire IT estate
- Be overly complex

If someone unfamiliar with your systems can understand it, you’ve done it right.

---

#### Step-by-step: How to create your diagram

### Step 1: Start with the customer

Begin with where the card data originates.

Examples:

- Customer web browser
- Customer mobile app
- Customer on the phone (manual entry)
- Customer at a physical terminal

This is always the **starting point**.

---

### Step 2: Show how card details are entered

Next, show **how card details are captured**, for example:

- Redirect to a hosted payment page
- Embedded payment form or iFrame
- Card details entered directly into your website or app
- Card details entered into a virtual terminal

This step often determines PCI DSS scope and SAQ selection.

---

### Step 3: Identify your payment provider

Add your payment service provider (PSP), such as:

- Stripe
- PayPal
- Adyen
- Worldpay

Show clearly:

- Where card data is sent
- Whether it goes directly to the PSP or passes through your systems

---

### Step 4: Add your systems (only if relevant)

Include your systems **only if they can affect payment security**, such as:

- Website or web application
- Mobile app
- Backend services or APIs
- Admin or support portals
- Logging or monitoring systems

If card data **never touches** a system, it may still need to appear if it can impact the payment flow.

---

### Step 5: Indicate where card data is (and is not) stored

Clearly show:

- Where card data is **not stored** (most modern setups)
- If tokenisation or references are used instead of raw card data
- Any temporary handling or redirection

Explicitly stating “No card data stored” is helpful.

---

### Step 6: Show access paths (at a high level)

Indicate:

- Admin or staff access to payment-related systems
- Third-party access (e.g. MSPs)

This helps identify **connected-to-CDE** systems.

---

### Step 7: Keep it high-level and label clearly

Use:

- Simple boxes
- Clear arrows
- Short labels

Avoid:

- Technical acronyms without explanation
- Overcrowding

---

#### Common mistakes to avoid

- ❌ Forgetting embedded scripts or iFrames
- ❌ Excluding admin or support access paths
- ❌ Including systems unrelated to payments
- ❌ Treating the diagram as “one-and-done”

The diagram should be reviewed whenever payment flows change.

---

#### When this diagram should be created and reviewed

- **Created:** During PCI DSS scoping (Step 1)
- **Reviewed:** During readiness assessment (Step 3)
- **Referenced:** During SAQ completion and validation

---

#### What happens after you create the diagram

We’ll use your diagram to:

- Confirm PCI DSS scope
- Validate your SAQ selection
- Identify in-scope and connected systems
- Support evidence and audit discussions

This diagram becomes part of your PCI DSS evidence set.

---

#### Key takeaway

A good PCI DSS payment data flow diagram is:

- Simple
- Accurate
- Easy to explain

It doesn’t need to be perfect — it needs to be **useful**.

- [Getting Started](https://knowledge.adoptech.co.uk/getting-started?hsLang=en#main-content)

    - [Getting Started](https://knowledge.adoptech.co.uk/getting-started?hsLang=en#getting-started)
    - [Accounts & Billing](https://knowledge.adoptech.co.uk/getting-started?hsLang=en#accounts-billing)
- [FAQ's on Adoptech](https://knowledge.adoptech.co.uk/faqs-on-adoptech?hsLang=en#main-content)

    - [Frameworks](https://knowledge.adoptech.co.uk/faqs-on-adoptech?hsLang=en#frameworks)
    - [Policies & Documents](https://knowledge.adoptech.co.uk/faqs-on-adoptech?hsLang=en#policies-documents)
    - [Risk Management](https://knowledge.adoptech.co.uk/faqs-on-adoptech?hsLang=en#risk-management)
    - [Supplier Management](https://knowledge.adoptech.co.uk/faqs-on-adoptech?hsLang=en#supplier-management)
    - [Audit Preparation](https://knowledge.adoptech.co.uk/faqs-on-adoptech?hsLang=en#audit-preparation)
    - [Trust Centre](https://knowledge.adoptech.co.uk/faqs-on-adoptech?hsLang=en#trust-centre)
    - [User Management](https://knowledge.adoptech.co.uk/faqs-on-adoptech?hsLang=en#user-management)
- [Frameworks & Certifications](https://knowledge.adoptech.co.uk/frameworks-certifications?hsLang=en#main-content)

    - [ISO 27001](https://knowledge.adoptech.co.uk/frameworks-certifications?hsLang=en#iso-27001)
    - [ISO 42001](https://knowledge.adoptech.co.uk/frameworks-certifications?hsLang=en#iso-42001)
    - [Cyber Essentials](https://knowledge.adoptech.co.uk/frameworks-certifications?hsLang=en#cyber-essentials)
    - [CAF](https://knowledge.adoptech.co.uk/frameworks-certifications?hsLang=en#caf)
    - [PCI-DSS](https://knowledge.adoptech.co.uk/frameworks-certifications?hsLang=en#pci-dss)
    - [SOC2](https://knowledge.adoptech.co.uk/frameworks-certifications?hsLang=en#soc2)
    - [Data Privacy (GDPR)](https://knowledge.adoptech.co.uk/frameworks-certifications?hsLang=en#data-privacy-gdpr)
    - [DORA](https://knowledge.adoptech.co.uk/frameworks-certifications?hsLang=en#dora)
    - [ISO 9001](https://knowledge.adoptech.co.uk/frameworks-certifications?hsLang=en#iso-9001)
    - [ISO 22301](https://knowledge.adoptech.co.uk/frameworks-certifications?hsLang=en#iso-22301)
    - [ISO 14001](https://knowledge.adoptech.co.uk/frameworks-certifications?hsLang=en#iso-14001)
    - [NIST 800-53](https://knowledge.adoptech.co.uk/frameworks-certifications?hsLang=en#nist-800-53)
    - [NIST-CSF](https://knowledge.adoptech.co.uk/frameworks-certifications?hsLang=en#nist-csf)
    - [NIS2](https://knowledge.adoptech.co.uk/frameworks-certifications?hsLang=en#nis2)
    - [ISO 20000-1](https://knowledge.adoptech.co.uk/frameworks-certifications?hsLang=en#iso-20000-1)
    - [HIPAA](https://knowledge.adoptech.co.uk/frameworks-certifications?hsLang=en#hipaa)
- [Integrations](https://knowledge.adoptech.co.uk/integrations?hsLang=en#main-content)

    - [Cloud Infrastructure](https://knowledge.adoptech.co.uk/integrations?hsLang=en#cloud-infrastructure)
    - [Identity & Access](https://knowledge.adoptech.co.uk/integrations?hsLang=en#identity-access)
    - [DevOps & Code](https://knowledge.adoptech.co.uk/integrations?hsLang=en#devops-code)
    - [Project Management](https://knowledge.adoptech.co.uk/integrations?hsLang=en#project-management)
    - [HR & People Systems](https://knowledge.adoptech.co.uk/integrations?hsLang=en#hr-people-systems)
    - [Security & Devices](https://knowledge.adoptech.co.uk/integrations?hsLang=en#security-devices)
    - [Communication & Collaboration](https://knowledge.adoptech.co.uk/integrations?hsLang=en#communication-collaboration)
- [Legal & Regulations](https://knowledge.adoptech.co.uk/legal-regulations?hsLang=en)
- [Security Guidance](https://knowledge.adoptech.co.uk/security-guidance?hsLang=en)
- [Troubleshooting](https://knowledge.adoptech.co.uk/troubleshooting?hsLang=en)

[![Chill listening crop-3](https://knowledge.adoptech.co.uk/hs-fs/hubfs/adoptech-logo-1.png?width=209&height=54&name=adoptech-logo-1.png "Chill listening crop-3")](https://adoptech.co.uk/)

<https://uk.linkedin.com/company/adoptech>

Copyright © 2026, Adoptech Ltd.