The people, processes and technology that store, process or transmit cardholder data or sensitive authentication data, including any connected system component. Defining the CDE boundary correctly determines the scope of every other PCI DSS control, making it the foundational term for that framework in the same way Controller functions for GDPR.
