Attacks on unsecured or outdated payment terminals have been increasing lately. Therefore, it is more important than ever to secure electronic transactions and protect credit card data and PINs with effective security measures. The PCI Security Standards Council (PCI SSC) has therefore published the PCI PIN Standard Version 3.0 this year.
We have summarized the essential points for you:
What is the objective of the standard?
The PCI PIN Standard includes security requirements to protect Personal Identification Numbers (PINs), which confirm the identity of a credit card holder during the payment process. The requirements are aimed at the secure administration, processing and transmission of PINs in online and offline transactions at ATMs and at attended and unattended payment terminals (e.g. ticket vending machines).
To whom does it apply?
The requirements of the PCI PIN standard must be met by all organizations that accept or process transactions from ATMs or point-of-sale terminals on the acquiring side. This applies in particular to banks, payment providers and network operators.
When will it become mandatory?
The PCI PIN Standard will replace the previously valid VISA PIN Security Requirements as of October 1, 2019. Certification by a Visa approved PIN Security Assessor will then no longer be viable.
How do you validate compliance?
As of October 1, 2019, affected organizations are required to have an annual onsite assessment conducted by a Qualified PIN Assessor (QPA) in order to successfully prove PCI PIN compliance. For this purpose, certified Qualified PIN Assessors carry out an assessment at your premises. They identify deviations from the standard through interviews with your employees, document reviews and technical tests.
How can we help you?
usd AG has been accredited by the PCI Council as a Qualified PIN Assessor (QPA) as one of the first companies in Europe. We are therefore qualified to assess and certify compliance with the PCI PIN Standard.
We also offer combined audits in connection with other PCI standards (such as P2PE). We are happy to advise you on your options.