PCI PIN: Replace Your Assessor after Two Assessment Cycles

6. October 2022

As the successor to the VISA PIN Security Requirements valid until 2019, the PCI PIN Security Standard PCI PIN Security Standard includes security requirements for the protection of Personal Identification Numbers (PINs), which are used to confirm the identity of a credit card holder during the payment process.

The requirements are aimed at secure management, processing, and transmission of PINs in online and offline transactions at ATMs as well as at supervised and unsupervised payment terminals (e.g., ticket vending machines) and must be met by all organizations that accept or process transactions from ATMs or point-of-sale terminals on the acquiring side. The standard is thus aimed in particular at banks, payment providers and network operators.

To successfully demonstrate PCI PIN compliance, affected companies are required to have an audit performed by an accredited Qualified PIN Assessor (QPA) every two years. During such an audit, certified and specially trained assessors identify deviations from the standard in the company by means of interviews, document reviews and technical tests.

Important: Companies subject to certification must change their PIN assessor regularly

In its VISA PIN Security Program Guide, VISA formulates some basic requirements for PIN security. These include the rule that companies subject to certification must replace their QPA Company after two consecutive assessment cycles at the latest. This practice is intended to help ensure that security assessments are conducted objectively and thoroughly on a permanent basis.

How can we help?

usd AG is officially accredited by the PCI SSC as a Qualified PIN Assessor. We are also happy to offer you combined audits in conjunction with other PCI standards (for example P2PE). Contact us - we will support you with your PCI certification project.

Also interesting:

Charity Runs 2023 - A Statement For Diversity And Solidarity

Charity Runs 2023 - A Statement For Diversity And Solidarity

This year, charity runs took place once again throughout Germany. The runs not only offer the opportunity to keep fit but also set a statement for diversity and solidarity. Organized by the usd Responsibility Circle, we supported our colleagues in their joint...

The Top 3 Security Aspects of Pentests in Automotive Cyber Security

The Top 3 Security Aspects of Pentests in Automotive Cyber Security

Connected Vehicles: Infotainment. Autonomous Driving. Cloud Backend. Amidst these developments, new opportunities are emerging for businesses, but also entirely new attack paths for cybercriminals. At the same time, they pose new challenges for cybersecurity...

NIS-2 and Dora: Why Two Pieces of EU Cybersecurity Legislation?

NIS-2 and Dora: Why Two Pieces of EU Cybersecurity Legislation?

Within a few months, the European Union has published two important pieces of legislation to strengthen cybersecurity: NIS-2 and DORA. Both are intended to strengthen companies in the financial sector and other businesses that are critical to the economy and society...

Categories

Categories