Your Certification against PCI PIN – What You Need to Know

17. September 2019

Attacks on unsecured or outdated payment terminals have been increasing lately. Therefore, it is more important than ever to secure electronic transactions and protect credit card data and PINs with effective security measures. The PCI Security Standards Council (PCI SSC) has therefore published the PCI PIN Standard Version 3.0 this year.

We have summarized the essential points for you:

What is the objective of the standard?

The PCI PIN Standard includes security requirements to protect Personal Identification Numbers (PINs), which confirm the identity of a credit card holder during the payment process. The requirements are aimed at the secure administration, processing and transmission of PINs in online and offline transactions at ATMs and at attended and unattended payment terminals (e.g. ticket vending machines).

To whom does it apply?

The requirements of the PCI PIN standard must be met by all organizations that accept or process transactions from ATMs or point-of-sale terminals on the acquiring side. This applies in particular to banks, payment providers and network operators.

When will it become mandatory?

The PCI PIN Standard will replace the previously valid VISA PIN Security Requirements as of October 1, 2019. Certification by a Visa approved PIN Security Assessor will then no longer be viable.

How do you validate compliance?

As of October 1, 2019, affected organizations are required to have an annual onsite assessment conducted by a Qualified PIN Assessor (QPA) in order to successfully prove PCI PIN compliance. For this purpose, certified Qualified PIN Assessors carry out an assessment at your premises. They identify deviations from the standard through interviews with your employees, document reviews and technical tests.

How can we help you?

usd AG has been accredited by the PCI Council as a Qualified PIN Assessor (QPA) as one of the first companies in Europe. We are therefore qualified to assess and certify compliance with the PCI PIN Standard.

We also offer combined audits in connection with other PCI standards (such as P2PE). We are happy to advise you on your options.

Also interesting:

Red Teaming: 5 Questions Every IT Leader Wants Answered

Red Teaming: 5 Questions Every IT Leader Wants Answered

Many companies invest in firewalls, endpoint protection, and awareness training, assuming that this puts them in a strong position. But the reality is different: attackers do not think in terms of tools, but in terms of targets. They combine technical vulnerabilities...

Stronger Together: usd AG Joins Security Network Munich

Stronger Together: usd AG Joins Security Network Munich

We are convinced that real progress in cyber security can only be achieved through open knowledge sharing and collaboration. That is why we contribute our expertise to international committees, promote dialogue within the security community and maintain close...

Categories

Categories