Your Certification against PCI PIN – What You Need to Know

17. September 2019

Attacks on unsecured or outdated payment terminals have been increasing lately. Therefore, it is more important than ever to secure electronic transactions and protect credit card data and PINs with effective security measures. The PCI Security Standards Council (PCI SSC) has therefore published the PCI PIN Standard Version 3.0 this year.

We have summarized the essential points for you:

What is the objective of the standard?

The PCI PIN Standard includes security requirements to protect Personal Identification Numbers (PINs), which confirm the identity of a credit card holder during the payment process. The requirements are aimed at the secure administration, processing and transmission of PINs in online and offline transactions at ATMs and at attended and unattended payment terminals (e.g. ticket vending machines).

To whom does it apply?

The requirements of the PCI PIN standard must be met by all organizations that accept or process transactions from ATMs or point-of-sale terminals on the acquiring side. This applies in particular to banks, payment providers and network operators.

When will it become mandatory?

The PCI PIN Standard will replace the previously valid VISA PIN Security Requirements as of October 1, 2019. Certification by a Visa approved PIN Security Assessor will then no longer be viable.

How do you validate compliance?

As of October 1, 2019, affected organizations are required to have an annual onsite assessment conducted by a Qualified PIN Assessor (QPA) in order to successfully prove PCI PIN compliance. For this purpose, certified Qualified PIN Assessors carry out an assessment at your premises. They identify deviations from the standard through interviews with your employees, document reviews and technical tests.

How can we help you?

usd AG has been accredited by the PCI Council as a Qualified PIN Assessor (QPA) as one of the first companies in Europe. We are therefore qualified to assess and certify compliance with the PCI PIN Standard.

We also offer combined audits in connection with other PCI standards (such as P2PE). We are happy to advise you on your options.

Also interesting:

DORA Countdown: One Month Left Until the Deadline

DORA Countdown: One Month Left Until the Deadline

DORA, the Digital Operational Resilience Act, will fully apply as of 17 January 2025. We have summarized everything you need to know about the EU regulation, preparation and best practices from our news blog.

Sunset of PCI DSS v4.0 on 31 December 2024: Get Ready!

Sunset of PCI DSS v4.0 on 31 December 2024: Get Ready!

PCI DSS v4.0: In March 2024, version 4.0 of the Payment Card Industry Data Security Standard became mandatory after a two-year transition phase. Just a few months later, version 4.0.1 was released as a minor update of the standard, which will become mandatory on...

Top 3 Vulnerabilities in SSO Pentests

Top 3 Vulnerabilities in SSO Pentests

During their penetration tests (pentests), our security analysts at usd HeroLab repeatedly uncover vulnerabilities that pose significant risks to corporate security. They increasingly encounter the same vulnerabilities. Our blog series "Top 3 Vulnerabilities" presents...

Categories

Categories