About This Architecture
PCI-DSS compliant payment architecture with isolated CDE VPC, WAF+Shield, ECS Fargate processing, Lambda tokenization, RDS encrypted with CMK, KMS, CloudHSM for crypto operations, Security Hub PCI compliance, and CloudTrail.
PCI-DSS Payment Processing Architecture
PCI-DSS compliant payment architecture with isolated CDE VPC, WAF+Shield, ECS Fargate processing, Lambda tokenization, RDS encrypted with CMK, KMS, CloudHSM for crypto operations, Security Hub PCI compliance, and CloudTrail.
aws · architecture diagram.
PCI-DSS compliant payment architecture with isolated CDE VPC, WAF+Shield, ECS Fargate processing, Lambda tokenization, RDS encrypted with CMK, KMS, CloudHSM for crypto operations, Security Hub PCI compliance, and CloudTrail.
Created by
February 9, 2026
Updated
February 13, 2026 at 5:47 PM
Type
architecture
Describe your architecture in plain English and get a production-ready Draw.io diagram in seconds. Works for AWS, Azure, GCP, Kubernetes, and more.