Framework · Last verified

PIN Security Standard

PIN Security is a PCI SSC standard for secure PIN management, assessed by independent Qualified PIN Assessors — PCI SSC itself does not mandate it. PCI SSC's own page states compliance is "at the discretion of organizations that manage compliance programs, such as a payment brand, acquirer, or other entity" — PCI SSC does not impose the standard directly.

Class
Framework
Owner
PCI Security Standards Council (PCI SSC)
Last verified

What it is

PCI SSC states the standard's purpose directly: "The PIN Security Standard is intended for the secure management, processing, and transmission of personal identification numbers (PINs) and associated cryptographic keys."

Its stated scope names a specific audience, verbatim from the PCI SSC page: "Acquiring institutions and agents responsible for PIN transaction processing on payment card industry participants' denominated accounts."

The current version is 3.1. PCI SSC's own blog announced it ("Just Released: Version 3.1 of the PCI PIN Security Standard", posted 12 Mar 2021), and PCI SSC's own document-library data lists it as the only non-archived version, last updated 2021-03-11 — no later version was found.

PCI SSC does not itself mandate the standard: "Whether an entity is required to comply with or validate compliance to a PCI SSC standard is at the discretion of organizations that manage compliance programs, such as a payment brand, acquirer, or other entity."

PCI SSC lists PIN Security as a standard separate from PCI DSS on its own standards overview page, each with its own name, description and page.

Who owns it

The standard is owned and published by the PCI Security Standards Council (PCI SSC).

Who assesses it

Independent assessments are performed by Qualified PIN Assessors: "Qualified PIN Assessors (QPAs) are qualified and trained by PCI SSC to perform independent assessments of environments where PINs are processed against the PIN Security Requirements." QPA is PCI SSC's own, separate qualification program — distinct from the Qualified Security Assessor (QSA) program used for PCI DSS.

Who asks for it

Voluntary. PCI SSC's own page states: "Whether an entity is required to comply with or validate compliance to a PCI SSC standard is at the discretion of organizations that manage compliance programs, such as a payment brand, acquirer, or other entity." PCI SSC itself imposes no mandate; a payment brand or acquirer may make compliance contractually mandatory — the specific contractual clauses that do so have not been opened and verified in this record (open question, see below).

PCI SSC's own page puts the decision to require compliance with the entity that manages the relevant compliance program: "Whether an entity is required to comply with or validate compliance to a PCI SSC standard is at the discretion of organizations that manage compliance programs, such as a payment brand, acquirer, or other entity." PCI SSC itself names no universal requirement.

Sources

Last verified:

This page is for information only; it does not accredit, certify or endorse any organisation. Requirements and programs change — always confirm against the primary source linked above.

Cite this page

Attributing this record helps other researchers verify it independently.

"PIN Security Standard." Certifidex, FutureTechnologies. Last verified 31 August 2026. https://certifidex.com/frameworks/pci-pin-security

All frameworks & audits →