Framework · Last verified
Token Service Provider (TSP) Standard
PCI TSP sets requirements for token service providers issuing EMV payment tokens, assessed by specially qualified P2PE Assessors — not mandated by PCI SSC. PCI SSC scopes it precisely: "For TSPs that generate and issue EMV payment tokens, as defined under the EMV® Payment Tokenisation Specification Technical Framework.".
- Class
- Framework
- Owner
- PCI Security Standards Council (PCI SSC)
- Last verified
What it is
PCI SSC states the standard's scope directly: "For TSPs that generate and issue EMV payment tokens, as defined under the EMV® Payment Tokenisation Specification Technical Framework." The scope is entities that generate and issue EMV payment tokens — this record does not extend that scope to any other party in a tokenized transaction.
The current version is 1.0, published 1 December 2015 per PCI SSC's own document-library data (last updated 2015-12-01); no later version was found.
There is no product listing for this standard. PCI SSC's own page states: "There is no product listing for Token Service Provider."
PCI SSC does not itself mandate the standard: its page carries the standard PCI SSC compliance-program language, "Compliance programs for all PCI SSC standards are managed by the payment brands."
Who owns it
The standard is owned and published by the PCI Security Standards Council (PCI SSC).
Who assesses it
TSP has no assessor program of its own. PCI SSC's own page states: "Point-to-Point Encryption (P2PE) Assessors are additionally qualified and trained by PCI SSC to perform independent assessments against the TSP Standard."
Who asks for it
Voluntary. PCI SSC's own page states: "Compliance programs for all PCI SSC standards are managed by the payment brands." PCI SSC itself imposes no mandate; a payment brand or acquirer may make compliance to this standard contractually mandatory — the specific contractual clauses that do so have not been opened and verified in this record (open question, see below).
PCI SSC's own page puts the decision to require compliance with the entity that manages the relevant compliance program: "Compliance programs for all PCI SSC standards are managed by the payment brands." PCI SSC itself names no universal requirement.
Sources
- PCI Security Standards Council — Token Service Provider (TSP) Standard page (scheme owner) ↗ — accessed
- PCI SSC official document-library endpoint — confirms v1.0 (last updated 2015-12-01) is the only non-archived version ↗ — accessed
Last verified:
This page is for information only; it does not accredit, certify or endorse any organisation. Requirements and programs change — always confirm against the primary source linked above.