Framework · Last verified
PCI 3DS Core Security Standard
PCI 3DS Core is PCI SSC's standard for entities operating ACS, DS or 3DSS environments, assessed by qualified 3DS Assessors — not mandated by PCI SSC itself. PCI SSC's page scopes it precisely: "For entities that provide environments where ACS, DS, and/or 3DSS functions are performed.".
- Class
- Framework
- Owner
- PCI Security Standards Council (PCI SSC)
- Last verified
What it is
PCI SSC states the standard's scope directly: "For entities that provide environments where ACS, DS, and/or 3DSS functions are performed." This is an entity/environment-level standard — it assesses the organization operating ACS, DS and/or 3DSS functions, not a software product.
The current version is 1.0, published 1 October 2017 per PCI SSC's own document-library data (last updated 2017-10-01); no later version was found.
PCI SSC does not itself mandate the standard: its page carries the standard PCI SSC compliance-program language, "Compliance programs for all PCI SSC standards are managed by the payment brands."
Who owns it
The standard is owned and published by the PCI Security Standards Council (PCI SSC).
Who assesses it
Independent assessments are performed by 3DS Assessors, PCI SSC's own words: "qualified and trained by PCI SSC to perform independent assessments against the PCI 3DS Core Standard and in accordance with the 3DS Assessor Program Guide." The assessor listing is published separately by PCI SSC.
Who asks for it
Voluntary. PCI SSC's own page states: "Compliance programs for all PCI SSC standards are managed by the payment brands." PCI SSC itself imposes no mandate; a payment brand or acquirer may make compliance to this standard contractually mandatory — the specific contractual clauses that do so have not been opened and verified in this record (open question, see below).
PCI SSC's own page puts the decision to require compliance with the entity that manages the relevant compliance program: "Compliance programs for all PCI SSC standards are managed by the payment brands." PCI SSC itself names no universal requirement.
Sources
- PCI Security Standards Council — PCI 3DS Core Security Standard page (scheme owner) ↗ — accessed
- PCI SSC — 3DS Assessors listing ↗ — accessed
- PCI SSC — Standards overview page (confirms 3DS Core is listed separately from 3DS SDK) ↗ — accessed
- PCI SSC official document-library endpoint — confirms v1.0 (last updated 2017-10-01) is the only non-archived version ↗ — accessed
Last verified:
This page is for information only; it does not accredit, certify or endorse any organisation. Requirements and programs change — always confirm against the primary source linked above.