Where things stand
PCI DSS v4.0.1 has been mandatory since 31 March 2025. Version 4.0 sunset on 31 December 2024. So the transition period is over — v4.0.1 is simply the standard now.
On the point that matters most for voice, v4.0.1 is unambiguous: call recordings must not contain cardholder data. Recordings that capture PANs, CVVs, or PINs in audio form violate Requirement 3.
Why pause-and-resume no longer holds up
The traditional control is procedural: agents are trained to pause the recording before the customer reads their card details, and resume afterwards.
The problem is arithmetic. Agent compliance with pause/resume typically runs somewhere in the 80–95% range — which means 5 to 20% of recordings still capture card data. At any meaningful call volume that is a large number of non-compliant recordings, and each one drags its storage, its backups, and its downstream consumers into scope.
The position now is that pause-and-resume, which depends on an agent remembering under pressure, is not adequate. Organizations are expected to use technical masking architectures rather than relying on manual agent compliance.
DTMF masking: the accepted technical control
DTMF masking is the preferred control. The customer enters their card number on the telephone keypad rather than speaking it, and the tones are suppressed in real time.
Three things happen simultaneously:
- The tones are suppressed during payment data entry, so the agent cannot decode them by ear or by recording. Typically the customer hears flat tones or the agent hears masked audio while the call stays connected.
- The payment entry segment is automatically excluded from the recording — by the system, not by the agent.
- The agent has no access to the payment data at any point. The digits are captured by the payment component and passed to the processor, commonly returning a token rather than the number.
Tokenization and DTMF masking together — where customers input card numbers via their keypad, bypassing agent ears and call recording entirely — are now the accepted standard for inbound calls where payments are taken. Critically, the agent stays on the line throughout, so the customer experience is preserved rather than being pushed to an IVR and back.
Map where cardholder data actually flows
This is the step most often done incompletely. Card data in a contact center goes further than people expect, and every destination inherits scope.
| Destination | Frequently overlooked because |
|---|---|
| Call recording storage | It is the obvious one, and usually the only one addressed. |
| Backups and archives | Retention is often years. A recording deleted from primary storage may persist in backup well beyond that. |
| Speech-to-text transcripts | A transcript of a spoken card number is cardholder data in text form — arguably worse, because it is searchable. |
| Quality management samples | QM tooling pulls copies into a separate system with its own access model. |
| Speech and interaction analytics | Another copy, another platform, often a third-party cloud service. |
| AI systems reading transcripts | The newest and least-governed path. Agent-assist, summarization, and coaching tools consume transcripts wholesale — including any card data in them. |
| Screen recording | If an agent types a card number into a CRM field, the screen capture contains it too. |
| Agent notes and CRM free text | Agents write things down. Free-text fields are a persistent source of stray PANs. |
| Chat and email channels | Customers send card details over any channel available to them, regardless of instruction. |
Scope reduction is the real prize
The compliance argument for a technical control is straightforward. The financial argument is usually stronger.
Every system that touches cardholder data falls within the assessed environment. Once card data never enters the voice path in the first place, a substantial estate — recording platform, storage, backups, transcription, QM, analytics — can move out of scope. For most organizations that reduction is the largest saving in the project, and it recurs every assessment cycle.
Design questions worth asking early
- Where does masking happen? In the network at the SBC, in the CCaaS platform, or in a hosted payment service? This determines what is in scope and who carries what responsibility.
- What does the agent see and hear? Confirm they get progress feedback without any digits.
- What happens on failure? If the masking service is unavailable, does the call fall back to an unmasked path? That fallback is a compliance hole.
- How are outbound and callback flows handled? Masking is usually designed for inbound and quietly missing on outbound.
- What about the other channels? Chat, email, and web forms need their own controls.
- How is evidence produced? Your QSA will want to see that the control operated continuously, not that it exists.
- What about historical recordings? Existing archives containing card data remain a liability. Remediation — targeted deletion or redaction — is a separate piece of work that needs a plan.
Where this intersects with migration
A CCaaS migration or a move to SIP is the natural moment to fix this, because the media path is being redesigned anyway. Retrofitting masking into a settled architecture is considerably more expensive than designing it in.
Conversely, a migration that does not address it will faithfully reproduce the existing problem on a new platform — and the new platform frequently adds transcription and AI features that widen the exposure.
Related reading
- CCaaS migration — the moment to design this in.
- SIP trunking & SBCs — where network-level masking sits.
Sources
- PCI Security Standards Council — PCI DSS v4.0.1
- Paytia — PCI DSS 4.0.1: 2025 compliance guide for telephone payments
- Paytia — PCI compliance and call recording: complete US guide
- Paytia — PCI DSS v4 for US contact centers: a practical guide
- Balto — Call center PCI compliance checklist
- WFM Labs — PCI-DSS in contact centers
Current as of July 2026. This is architectural guidance, not a compliance opinion. We design toward the standard and work alongside your QSA — validation is theirs to give, not ours.
Scope reduction usually pays for the whole project. We map the data flow first.
Book a call