Framework · Last verified

PCI 3DS Core Security Standard

PCI 3DS Core is PCI SSC's standard for entities operating ACS, DS or 3DSS environments, assessed by qualified 3DS Assessors — not mandated by PCI SSC itself. PCI SSC's page scopes it precisely: "For entities that provide environments where ACS, DS, and/or 3DSS functions are performed.".

Class
Framework
Owner
PCI Security Standards Council (PCI SSC)
Last verified

What it is

PCI SSC states the standard's scope directly: "For entities that provide environments where ACS, DS, and/or 3DSS functions are performed." This is an entity/environment-level standard — it assesses the organization operating ACS, DS and/or 3DSS functions, not a software product.

The current version is 1.0, published 1 October 2017 per PCI SSC's own document-library data (last updated 2017-10-01); no later version was found.

PCI SSC does not itself mandate the standard: its page carries the standard PCI SSC compliance-program language, "Compliance programs for all PCI SSC standards are managed by the payment brands."

Who owns it

The standard is owned and published by the PCI Security Standards Council (PCI SSC).

Who assesses it

Independent assessments are performed by 3DS Assessors, PCI SSC's own words: "qualified and trained by PCI SSC to perform independent assessments against the PCI 3DS Core Standard and in accordance with the 3DS Assessor Program Guide." The assessor listing is published separately by PCI SSC.

Who asks for it

Voluntary. PCI SSC's own page states: "Compliance programs for all PCI SSC standards are managed by the payment brands." PCI SSC itself imposes no mandate; a payment brand or acquirer may make compliance to this standard contractually mandatory — the specific contractual clauses that do so have not been opened and verified in this record (open question, see below).

PCI SSC's own page puts the decision to require compliance with the entity that manages the relevant compliance program: "Compliance programs for all PCI SSC standards are managed by the payment brands." PCI SSC itself names no universal requirement.

Sources

Last verified:

This page is for information only; it does not accredit, certify or endorse any organisation. Requirements and programs change — always confirm against the primary source linked above.

Cite this page

Attributing this record helps other researchers verify it independently.

"PCI 3DS Core Security Standard." Certifidex, FutureTechnologies. Last verified 31 August 2026. https://certifidex.com/frameworks/pci-3ds-core

All frameworks & audits →