Framework (sunset) · Last verified

PCI 3DS SDK Security Standard

PCI 3DS SDK is PCI SSC's product-level standard for 3DS Software Development Kits, evaluated by PCI-Recognized Laboratories — now in its formal sunset period. PCI SSC offers security requirements for 3DS SDKs to help prevent unauthorized card-not-present transactions; the sunset window runs 1 May to 31 October 2026.

Class
Framework (sunset)
Owner
PCI Security Standards Council (PCI SSC)
Last verified

What it is

PCI SSC states the standard's purpose directly: "This standard offers security requirements, assessment procedures, and guidance for 3DS Software Development Kits (SDKs), as defined in the EMV® 3-D Secure SDK Specification, to help prevent unauthorized card-not-present (CNP) transactions and to protect merchants from CNP exposure to fraud." This is a product-level standard: the SDK itself is the assessed unit, not the organization operating it — unlike PCI 3DS Core, which assesses the entity/environment running ACS, DS and/or 3DSS functions.

The current version is 1.1, published 1 December 2018 per PCI SSC's own document-library data (last updated 2018-12-01); no later version was found.

PCI SSC announces, on this same page, a formal sunset period for the standard running from 1 May to 31 October 2026 — a window that was open as of this record's last verification (1 September 2026).

PCI SSC does not itself mandate the standard. Its page carries the full compliance-program language: "Compliance programs for all PCI SSC standards are managed by the payment brands. Questions about which entities need to validate compliance to any PCI SSC standard, or whether use of a PCI-listed product is required and for which entities, should be referred to the payment brands."

Who owns it

The standard is owned and published by the PCI Security Standards Council (PCI SSC).

Who assesses it

Assessments are performed by independent PCI-Recognized Laboratories, PCI SSC's own words: "These assessments are performed by independent PCI-Recognized Laboratories that are also EMVCo Laboratories, and that are qualified and approved by PCI SSC to evaluate 3DS SDKs against PCI 3DS SDK security requirements and in accordance with the PCI 3DS SDK Program Guide." A separate listing of evaluated SDKs is published by PCI SSC.

Who asks for it

Voluntary. PCI SSC's own page states, in full: "Compliance programs for all PCI SSC standards are managed by the payment brands. Questions about which entities need to validate compliance to any PCI SSC standard, or whether use of a PCI-listed product is required and for which entities, should be referred to the payment brands." PCI SSC itself imposes no mandate; a payment brand or acquirer may make compliance to this standard contractually mandatory — the specific contractual clauses that do so have not been opened and verified in this record (open question, see below).

PCI SSC's own page puts the decision to require compliance, or to require use of a PCI-listed product, with the entity that manages the relevant compliance program: "Compliance programs for all PCI SSC standards are managed by the payment brands. Questions about which entities need to validate compliance to any PCI SSC standard, or whether use of a PCI-listed product is required and for which entities, should be referred to the payment brands." PCI SSC itself names no universal requirement.

Sources

Last verified:

This page is for information only; it does not accredit, certify or endorse any organisation. Requirements and programs change — always confirm against the primary source linked above.

Cite this page

Attributing this record helps other researchers verify it independently.

"PCI 3DS SDK Security Standard." Certifidex, FutureTechnologies. Last verified 31 August 2026. https://certifidex.com/frameworks/pci-3ds-sdk

All frameworks & audits →