Hello,
Does Atlassian have a PCI DSS Attestation of Compliance for 2025?
PCI 4.0 now includes tooling like code repositories, so Bitbucket has been included in our audit scope. As such, we need to upload Atlassian's AoC as part of our evidence.
Thanks
We are in the same situation. Atlassian still states that they're not in PCI scope for not having PCI data. They don't seem to be aware that connectivity to a CDE for Bitbucket automation will also bring them into PCI scope for impacting security. Will they allow Atlassian Cloud to be assessed by their clients' QSAs? Will they undergo a PCI assessment? Or will they remain in denial?