Framework · Last verified
PIN Security Standard
PIN Security is a PCI SSC standard for secure PIN management, assessed by independent Qualified PIN Assessors — PCI SSC itself does not mandate it. PCI SSC's own page states compliance is "at the discretion of organizations that manage compliance programs, such as a payment brand, acquirer, or other entity" — PCI SSC does not impose the standard directly.
- Class
- Framework
- Owner
- PCI Security Standards Council (PCI SSC)
- Last verified
What it is
PCI SSC states the standard's purpose directly: "The PIN Security Standard is intended for the secure management, processing, and transmission of personal identification numbers (PINs) and associated cryptographic keys."
Its stated scope names a specific audience, verbatim from the PCI SSC page: "Acquiring institutions and agents responsible for PIN transaction processing on payment card industry participants' denominated accounts."
The current version is 3.1. PCI SSC's own blog announced it ("Just Released: Version 3.1 of the PCI PIN Security Standard", posted 12 Mar 2021), and PCI SSC's own document-library data lists it as the only non-archived version, last updated 2021-03-11 — no later version was found.
PCI SSC does not itself mandate the standard: "Whether an entity is required to comply with or validate compliance to a PCI SSC standard is at the discretion of organizations that manage compliance programs, such as a payment brand, acquirer, or other entity."
PCI SSC lists PIN Security as a standard separate from PCI DSS on its own standards overview page, each with its own name, description and page.
Who owns it
The standard is owned and published by the PCI Security Standards Council (PCI SSC).
Who assesses it
Independent assessments are performed by Qualified PIN Assessors: "Qualified PIN Assessors (QPAs) are qualified and trained by PCI SSC to perform independent assessments of environments where PINs are processed against the PIN Security Requirements." QPA is PCI SSC's own, separate qualification program — distinct from the Qualified Security Assessor (QSA) program used for PCI DSS.
Who asks for it
Voluntary. PCI SSC's own page states: "Whether an entity is required to comply with or validate compliance to a PCI SSC standard is at the discretion of organizations that manage compliance programs, such as a payment brand, acquirer, or other entity." PCI SSC itself imposes no mandate; a payment brand or acquirer may make compliance contractually mandatory — the specific contractual clauses that do so have not been opened and verified in this record (open question, see below).
PCI SSC's own page puts the decision to require compliance with the entity that manages the relevant compliance program: "Whether an entity is required to comply with or validate compliance to a PCI SSC standard is at the discretion of organizations that manage compliance programs, such as a payment brand, acquirer, or other entity." PCI SSC itself names no universal requirement.
Sources
- PCI Security Standards Council — PIN Security Standard page (scheme owner) ↗ — accessed
- PCI SSC blog — "Just Released: Version 3.1 of the PCI PIN Security Standard" (12 Mar 2021) ↗ — accessed
- PCI SSC — Qualified PIN Assessor (QPA) qualification page ↗ — accessed
- PCI SSC — Standards overview page (confirms PIN Security is listed separately from PCI DSS) ↗ — accessed
- PCI SSC official document-library endpoint — confirms v3.1 (last updated 2021-03-11) is the only non-archived version ↗ — accessed
Last verified:
This page is for information only; it does not accredit, certify or endorse any organisation. Requirements and programs change — always confirm against the primary source linked above.