Portnox Cloud Responsibility Matrix for PCI DSS

Most NAC responsibility matrices assume you’re running the platform yourself. Portnox Cloud isn’t — it’s fully SaaS, which means Portnox absorbs the parts of the stack that traditionally sit on your team: physical and data center security, platform patching, the RADIUS service itself, backups, and disaster recovery. What’s left on your side is what should stay on your side: your network hardware, your identity provider, your endpoints, and the access policies you set. If you run an optional on-prem component, that piece follows the customer-managed rules too.

PCI DSS Area & Function Portnox / Cloud Provider Responsibility Customer / Organization Responsibility
Physical security (Req 9) Owns physical and data center security — hardware, hypervisors, and core networking, since delivery is SaaS. Secures on-prem network closets and switches, plus the physical host for any optional local RADIUS or connector.
OS and application patching (Req 6) Develops, patches, and secures the NAC SaaS platform, APIs, and application code; ships endpoint-agent updates. Patches the OS of any local RADIUS/connector host, deploys agent updates via MDM, keeps endpoints patched.
Network control planes (Req 1) Provides the Cloud RADIUS service, RADIUS endpoints and attributes, and secure default platform features and APIs. Configures network access devices (switches, APs, WLCs, VPNs, firewalls) and firewall/port rules, including allowing Portnox's cloud IP ranges.
Data encryption (Req 3 & 4) Encrypts and stores tenant data with multi-tenant isolation; supports RadSec and EAP-TLS; RADIUS cert signed by DigiCert. Enables encryption in transit by turning on RadSec and choosing an EAP method; sets data classification, attribute sync, retention.
Identity and authentication (Req 7 & 8) Supplies IdP connectors (Entra ID, Okta, Google, AD, LDAP), RBAC, and SCEP/Cloud PKI for passwordless EAP-TLS. Owns IdP design, groups, and MFA; manages Portnox roles and joiner/mover/leaver processes; defines access policies.
Auditing and monitoring (Req 10) Generates logs and APIs; leads detection and response for platform-level incidents. Sets alert thresholds and SOC actions; exports and monitors logs in a SIEM/XDR; leads endpoint/network incident response.

Built on Certified Ground

Portnox Cloud maintains SOC 2 Type II and ISO 27001 for its platform. You still own mapping those controls into your own frameworks — PCI DSS, HIPAA, or whatever applies to your business — but you’re not starting from zero.

These PCI requirement groupings are mapped to match the reference Cisco ISE table for easy comparison. Portnox’s official shared responsibility model is organized by control domain rather than PCI requirement number — view it here.

Schedule a 
Portnox demo today.

[Webinar with Forrester] The Identity Blind Spot: AI Agents & Access Control (Sept. 10)

X