Framework · Last verified

Token Service Provider (TSP) Standard

PCI TSP sets requirements for token service providers issuing EMV payment tokens, assessed by specially qualified P2PE Assessors — not mandated by PCI SSC. PCI SSC scopes it precisely: "For TSPs that generate and issue EMV payment tokens, as defined under the EMV® Payment Tokenisation Specification Technical Framework.".

Class
Framework
Owner
PCI Security Standards Council (PCI SSC)
Last verified

What it is

PCI SSC states the standard's scope directly: "For TSPs that generate and issue EMV payment tokens, as defined under the EMV® Payment Tokenisation Specification Technical Framework." The scope is entities that generate and issue EMV payment tokens — this record does not extend that scope to any other party in a tokenized transaction.

The current version is 1.0, published 1 December 2015 per PCI SSC's own document-library data (last updated 2015-12-01); no later version was found.

There is no product listing for this standard. PCI SSC's own page states: "There is no product listing for Token Service Provider."

PCI SSC does not itself mandate the standard: its page carries the standard PCI SSC compliance-program language, "Compliance programs for all PCI SSC standards are managed by the payment brands."

Who owns it

The standard is owned and published by the PCI Security Standards Council (PCI SSC).

Who assesses it

TSP has no assessor program of its own. PCI SSC's own page states: "Point-to-Point Encryption (P2PE) Assessors are additionally qualified and trained by PCI SSC to perform independent assessments against the TSP Standard."

Who asks for it

Voluntary. PCI SSC's own page states: "Compliance programs for all PCI SSC standards are managed by the payment brands." PCI SSC itself imposes no mandate; a payment brand or acquirer may make compliance to this standard contractually mandatory — the specific contractual clauses that do so have not been opened and verified in this record (open question, see below).

PCI SSC's own page puts the decision to require compliance with the entity that manages the relevant compliance program: "Compliance programs for all PCI SSC standards are managed by the payment brands." PCI SSC itself names no universal requirement.

Sources

Last verified:

This page is for information only; it does not accredit, certify or endorse any organisation. Requirements and programs change — always confirm against the primary source linked above.

Cite this page

Attributing this record helps other researchers verify it independently.

"Token Service Provider (TSP) Standard." Certifidex, FutureTechnologies. Last verified 31 August 2026. https://certifidex.com/frameworks/pci-tsp

All frameworks & audits →