Framework (sunset) · Last verified
PCI 3DS SDK Security Standard
PCI 3DS SDK is PCI SSC's product-level standard for 3DS Software Development Kits, evaluated by PCI-Recognized Laboratories — now in its formal sunset period. PCI SSC offers security requirements for 3DS SDKs to help prevent unauthorized card-not-present transactions; the sunset window runs 1 May to 31 October 2026.
- Class
- Framework (sunset)
- Owner
- PCI Security Standards Council (PCI SSC)
- Last verified
What it is
PCI SSC states the standard's purpose directly: "This standard offers security requirements, assessment procedures, and guidance for 3DS Software Development Kits (SDKs), as defined in the EMV® 3-D Secure SDK Specification, to help prevent unauthorized card-not-present (CNP) transactions and to protect merchants from CNP exposure to fraud." This is a product-level standard: the SDK itself is the assessed unit, not the organization operating it — unlike PCI 3DS Core, which assesses the entity/environment running ACS, DS and/or 3DSS functions.
The current version is 1.1, published 1 December 2018 per PCI SSC's own document-library data (last updated 2018-12-01); no later version was found.
PCI SSC announces, on this same page, a formal sunset period for the standard running from 1 May to 31 October 2026 — a window that was open as of this record's last verification (1 September 2026).
PCI SSC does not itself mandate the standard. Its page carries the full compliance-program language: "Compliance programs for all PCI SSC standards are managed by the payment brands. Questions about which entities need to validate compliance to any PCI SSC standard, or whether use of a PCI-listed product is required and for which entities, should be referred to the payment brands."
Who owns it
The standard is owned and published by the PCI Security Standards Council (PCI SSC).
Who assesses it
Assessments are performed by independent PCI-Recognized Laboratories, PCI SSC's own words: "These assessments are performed by independent PCI-Recognized Laboratories that are also EMVCo Laboratories, and that are qualified and approved by PCI SSC to evaluate 3DS SDKs against PCI 3DS SDK security requirements and in accordance with the PCI 3DS SDK Program Guide." A separate listing of evaluated SDKs is published by PCI SSC.
Who asks for it
Voluntary. PCI SSC's own page states, in full: "Compliance programs for all PCI SSC standards are managed by the payment brands. Questions about which entities need to validate compliance to any PCI SSC standard, or whether use of a PCI-listed product is required and for which entities, should be referred to the payment brands." PCI SSC itself imposes no mandate; a payment brand or acquirer may make compliance to this standard contractually mandatory — the specific contractual clauses that do so have not been opened and verified in this record (open question, see below).
PCI SSC's own page puts the decision to require compliance, or to require use of a PCI-listed product, with the entity that manages the relevant compliance program: "Compliance programs for all PCI SSC standards are managed by the payment brands. Questions about which entities need to validate compliance to any PCI SSC standard, or whether use of a PCI-listed product is required and for which entities, should be referred to the payment brands." PCI SSC itself names no universal requirement.
Sources
- PCI Security Standards Council — PCI 3DS SDK Security Standard page (scheme owner) ↗ — accessed
- PCI SSC — 3DS SDKs listing ↗ — accessed
- PCI SSC official document-library endpoint — confirms v1.1 (last updated 2018-12-01) is the only non-archived version ↗ — accessed
Last verified:
This page is for information only; it does not accredit, certify or endorse any organisation. Requirements and programs change — always confirm against the primary source linked above.