# Instaclustr Announces PCI-DSS Certification

[Blog](/blog/)&gt;[Technology](/blog/category/technical/)&gt;Instaclustr Announces PCI-DSS Certification 

Instaclustr Announces PCI-DSS Certification
===========================================

February 19, 2020 | By [ Ben Slater](https://www.instaclustr.com/blog/author/bens/)

 

 

 

 



   [ ](https://x.com/intent/tweet?text=Instaclustr%20Announces%20PCI-DSS%20Certification&url=https://www.instaclustr.com/blog/instaclustr-announces-pci-dss-certification/) [ ](https://www.linkedin.com/shareArticle?mini=true&url=https://www.instaclustr.com/blog/instaclustr-announces-pci-dss-certification/&title=&summary=Instaclustr%20Announces%20PCI-DSS%20Certification&source=) 

Instaclustr is pleased to announce that we have achieved PCI-DSS certification for our Managed Apache Cassandra and Managed Apache Kafka offerings running in AWS.

### What is PCI-DSS?

PCI-DSS (Payment Card Industry – Data Security Standard) is a mandated standard for many financial applications and we increasingly see the PCI-DSS controls adopted as the “gold standard” in other industries where the highest standards of security are crucial. PCI-DSS certification adds to our existing SOC 2 accreditation to provide the levels of security assurance required by even the most demanding business requirements.

Overall, this certification effort was the most significant single engineering project in the history of Instaclustr, requiring several person-years of engineering effort to implement well over 100 changes touching every aspect of our systems over the course of several months. We’re very proud that, despite this level of change, impact to our customers has been absolutely minimal and we’re able to deliver another very significant piece of background infrastructure, allowing a wider range of customers to focus their efforts on building innovative business applications based on open source data technologies.

### How PCI-DSS improves security

While PCI-DSS compliance may not be required by all customers and is only supported on selected Instaclustr products, most of the security enhancements we have implemented will result in improved levels of security for all our Managed Service customers, regardless of product or platform. The most significant of these changes are:

- Tightening of our admin access environment with technical controls to prevent egress of data via our admin systems.
- Improved logging and auditing infrastructure.
- Tightened operating system hardening and crypto standards.
- Addition of a WAF (Web Application Firewall) in front of our console and APIs.
- More automated scanning, and tightened resolution policies, for code dependency vulnerabilities.
- More frequent security scanning of our central management systems.
- More developer security training.

### How to achieve PCI-DSS

Customers wishing to achieve full PCI-DSS compliance will need to opt-in when creating a cluster as achieving PCI compliance will enforce a range of more restrictive security options (for example, password complexity in the Instaclustr console and use of [Private Network Clusters](https://www.instaclustr.com/blog/announcing-instaclustr-private-network-clusters-cassandra-elassandra/)) and enabling the required additional logging on the cluster incurs a performance penalty of approximately 5%. There are also a set of customer responsibilities that customers must implement for full compliance. Additional technical controls activated for PCI compliant clusters include:

- Logging of all user access to the managed applications (Cassandra, Kafka)
- Locked-down outbound firewall rules
- Second approver system for sudo access for our admins

For full details please see our [support page](https://www.instaclustr.com/support/documentation/useful-information/pci-compliance/).

Customers with existing clusters who wish to move to full PCI compliance should contact <support@instaclustr.com> who will arrange a plan to apply the new controls to your cluster.

We will be publishing more detail on many of these controls in the coming weeks and holding webinars to cover the Cassandra and Kafka specific implementation details which we expect will be of broad interest. In the meantime, should you have any interest in any further information please contact your Instaclustr Customer Success representative or <sales@instaclustr.com> who will be able to arrange technical briefings.

 

### About the author

**[Ben Slater](https://www.instaclustr.com/blog/author/bens/)** | Chief Product Officer

Chief Product Officer, charged with steering Instaclustr’s development roadmap and overseeing the product engineering, production support, open source, and consulting teams.

 



 

 ![mail icon]()#### Get the latest articles for open sourceIn your inbox

 <a class="btn btn-primary btn-popup text-dark" href="">Sign up now</a> 

 

 

 

  ### Related content

 [ Zero Downtime Migration to Instaclustr 

 

 Yes, we can migrate existing Cassandra clusters to Instaclustr without any downtime. Here's what to expect from the process... 

 

 

 

 

 

 

 ](https://www.instaclustr.com/blog/zero-downtime-migration-to-instaclustr/) 

 [ Workflow Comparison: Uber Cadence vs Netflix Conductor 

 

 When choosing what’s right for your company’s opensource workflow needs it is important to know the difference and similarities ... 

 

 

 

 

 

 

 ](https://www.instaclustr.com/blog/workflow-comparison-uber-cadence-vs-netflix-conductor/) 

 [ Will Your Cassandra Database Project Succeed?: The New Stack 

 

 Open source Apache Cassandra® continues to stand out as an enterprise-proven solution for organizations seeking high availability... 

 

 

 

 

 

 

 ](https://www.instaclustr.com/blog/will-your-cassandra-database-project-succeed-the-new-stack/) 

 

  <a class="close-modal" href="">×</a>Sign upto ourNewsletter
-----------------------
