Skip to content
Graphviz (DOT) templates

PCI-DSS Cardholder Data Scope

Cardholder data environment (CDE), segmentation, and out-of-scope systems.

Template previewGraphviz (DOT)
Rendering…

Make it your own.

digraph pci {
  rankdir=LR;
  graph [bgcolor=transparent, compound=true];
  node [shape=box, style="rounded,filled", fontname=Inter, fontsize=10];

  subgraph cluster_cde {
    label="Cardholder Data Environment (in scope)";
    color="#dc2626"; style=dashed;
    Web [label="Checkout web", fillcolor="#fee2e2"];
    API [label="Payment API", fillcolor="#fee2e2"];
    Vault [label="Tokenisation vault", fillcolor="#fee2e2"];
  }

  subgraph cluster_conn {
    label="Connected (in scope)";
    color="#f59e0b"; style=dashed;
    Auth [label="IAM / SSO", fillcolor="#fef3c7"];
    Log [label="Central logs", fillcolor="#fef3c7"];
  }

  subgraph cluster_oos {
    label="Out of scope";
    color="#16a34a"; style=dashed;
    Cat [label="Catalogue service", fillcolor="#dcfce7"];
    BI [label="BI tools", fillcolor="#dcfce7"];
  }

  Web -> API -> Vault;
  API -> Auth; API -> Log; Web -> Log;
  Cat -> BI;
  Web -> Cat [style=dotted, label="firewalled, no CHD"];
}