Framework · Last verified

Card Production and Provisioning Security Requirements

Card Production and Provisioning is two PCI SSC standards — Logical and Physical — assessed by CPSA-P/CPSA-L assessors, with no product listing. PCI SSC publishes them as two separate standards, each with its own assessor qualification: CPSA-L for Logical, CPSA-P for Physical.

Class
Framework
Owner
PCI Security Standards Council (PCI SSC)
Last verified

What it is

PCI SSC publishes two separate standards under this heading. The Logical standard's scope, verbatim: "This standard provides the logical security requirements for card production and provisioning functions to protect payment card data. They address the logical security activities associated with card production and provisioning such as data preparation, pre-personalization, card personalization, and PIN generation."

The Physical standard's scope, verbatim: "This standard provides the physical security requirements for card production and provisioning functions to protect payment card material. This addresses physical security requirements for entities involved in card production and provisioning, which may include manufacturers, personalizers, pre-personalizers, chip embedders, data-preparation, and fulfillment."

Both standards also reach cloud-based and remote personalization work. The Logical standard's page lists, among the activities in scope: "Perform cloud-based or secure element (SE) provisioning services," and "Manage over-the-air (OTA) personalization, lifecycle management, and preparation of personalization data."

The current version of both standards is 3.0.1, last updated 2022-06-30, per PCI SSC's own document-library data — no later version was found for either.

Neither standard has a product listing. The Physical standard's page states: "There is no product listing for Card Production and Provisioning – Physical Security Requirements." The Logical page carries the same pattern under its own name. Assessment here produces a facility-level assessment result, not an entry on a public product register.

Who owns it

Both standards are owned and published by the PCI Security Standards Council (PCI SSC).

Who assesses it

Assessments are performed by two distinct, separately qualified assessor types: "Card Production Security Assessors–Physical (CPSA-P)" assess against the Physical standard, and "Card Production Security Assessors–Logical (CPSA-L)" assess against the Logical standard. These are not the same qualification, and PCI SSC lists them on its Card Production Security Assessors listing page.

Standards in this record

  • Logical Security Requirements — This standard provides the logical security requirements for card production and provisioning functions to protect payment card data. They address the logical security activities associated with card production and provisioning such as data preparation, pre-personalization, card personalization, and PIN generation.
  • Physical Security Requirements — This standard provides the physical security requirements for card production and provisioning functions to protect payment card material. This addresses physical security requirements for entities involved in card production and provisioning, which may include manufacturers, personalizers, pre-personalizers, chip embedders, data-preparation, and fulfillment.

Who asks for it

Voluntary. Both standard pages carry only the short form of PCI SSC's standing statement: "Compliance programs for all PCI SSC standards are managed by the payment brands." A fuller explanation of which entities must validate against this specific standard was not found on either page.

Both standard pages carry only the short form of PCI SSC's standing statement on compliance programs: "Compliance programs for all PCI SSC standards are managed by the payment brands." Neither page names, in that sentence, which entities are required to validate against these two standards specifically.

Sources

Last verified:

This page is for information only; it does not accredit, certify or endorse any organisation. Requirements and programs change — always confirm against the primary source linked above.

Cite this page

Attributing this record helps other researchers verify it independently.

"Card Production and Provisioning Security Requirements." Certifidex, FutureTechnologies. Last verified 31 August 2026. https://certifidex.com/frameworks/pci-card-production

All frameworks & audits →