{"id":66513,"date":"2026-07-21T14:11:50","date_gmt":"2026-07-21T12:11:50","guid":{"rendered":"https:\/\/www.usd.de\/?p=66513"},"modified":"2026-07-21T14:11:53","modified_gmt":"2026-07-21T12:11:53","slug":"epi-security-requirements-v1-2-released","status":"publish","type":"post","link":"https:\/\/www.usd.de\/en\/epi-security-requirements-v1-2-released\/","title":{"rendered":"EPI Security Requirements v1.2 Released: Key Updates, Requirements and Impacts at a Glance"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">The European Payment Initiative (<a href=\"https:\/\/epicompany.eu\/\" data-type=\"link\" data-id=\"https:\/\/epicompany.eu\/\" target=\"_blank\" rel=\"noopener\">EPI<\/a>) released <strong>Security Requirements v1.2<\/strong> on 17.07.2026. The update focuses on governance, application security, and evidence requirements - areas that directly impact implementation and audit readiness.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">As an <a href=\"https:\/\/www.usd.de\/en\/pci-payment-security\/epi\/\" data-type=\"link\" data-id=\"https:\/\/www.usd.de\/en\/pci-payment-security\/epi\/\">accredited External Security Evaluator<\/a>, we support EPI participants in security assessments and audit preparation. Our colleague Phillip Meyer reviewed the new version to highlight what changes for you in practice. This is particularly important as EPI will only accept evaluations based on Version 1.2 from 01. August 2026 onward.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Key takeaways:<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>DORA replaces EBA Guidelines<\/strong>: Stronger alignment with binding EU regulation, with a focus on ICT risk management and incident handling.<\/li>\n\n\n\n<li><strong>More focus on AppSec<\/strong>: Mobile security gains independence. A new control for APIs and web applications introduces a dedicated assessment area, aligned with OWASP ASVS.<\/li>\n\n\n\n<li><strong>Flexible Key Management<\/strong>: No longer limited to HSMs, but also software solutions with equivalent security (relevant for cloud operations).<\/li>\n\n\n\n<li><strong>More precise vulnerability management<\/strong>: CVSS v4.0 and defined assessment intervals tighten requirements.<\/li>\n\n\n\n<li><strong>Supply Chain security<\/strong>: Version pinning for dependencies is now explicitly mandatory.<\/li>\n\n\n\n<li><strong>Certificate validation<\/strong>: EPI now offers more deployment options for mobile applications, including Certificate Transparency Monitoring as an alternative to pinning.<\/li>\n<\/ul>\n\n\n\n<div style=\"height:21px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 class=\"wp-block-heading\">Regulatory Context: Dora Replaces the EBA Guidelines<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">In version 1.2, EPI no longer refers to the EBA Guidelines but to the DORA Regulation. This places greater emphasis on binding requirements, particularly regarding ICT risk management, third-party risk management, and incident handling and reporting.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>The implications for you: <\/strong>Align your ISMS and risk management framework so that you not only meet requirements regarding third parties and incidents, but also manage them consistently and demonstrate resilience.<\/p>\n\n\n\n<div style=\"height:21px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 class=\"wp-block-heading\">Application Security: New Structure, New Assessment Criteria<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Control 8.0: Mobile Application Security: In v1.2, mobile security is defined more clearly as a standalone control. This increases the need for specific evidence, such as architecture, security controls, and testing, separate from secure development in general.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">New Control 9.0: APIs &amp; Web Applications (incl. OWASP ASVS): EPI has added a new control for APIs and web applications and references OWASP ASVS as the standard for verifiable technical security controls and secure development requirements.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>The implications for you:<\/strong> You need a specific checklist for testing and verification that can be applied to each application, for example:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Define ASVS levels per application<\/li>\n\n\n\n<li>Make controls testable (definition, test case, result, evidence)<\/li>\n\n\n\n<li>Organize verification so that it is repeatable (not a one-time action)<\/li>\n<\/ul>\n\n\n\n<div style=\"height:21px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 class=\"wp-block-heading\">Key Management: Greater Flexibility, but with Proof of Effectiveness<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Version 1.2 allows for software-based solutions in addition to HSMs, provided they offer equivalent security (e.g., hardening, access control, logging, and no disclosure of key material).<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Especially in cloud environments, many teams use managed services for key management (e.g., AWS KMS, Azure Key Vault). The new version opens up additional implementation options in this area.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>The implications for you:<\/strong> You gain flexibility. However, for the assessment, it is crucial that you provide verifiable evidence of your solution\u2019s protective effectiveness, particularly regarding operations, roles, logs, key lifecycle, and technical hardening.<\/p>\n\n\n\n<div style=\"height:21px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 class=\"wp-block-heading\">Vulnerability Management: CVSS v4.0 and Consistent Timing<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">EPI is transitioning to CVSS v4.0. This changes the scoring logic for vulnerabilities. Scores can no longer be directly compared with CVSS v3.1 and may vary significantly in individual cases. As a result, existing scoring logic, thresholds, and the support provided by the tools in use should be reviewed. Example: If a vulnerability is classified as high under CVSS v3.1 starting at a score of 7.0, shifts may occur under CVSS v4.0, meaning that findings that previously fell below this threshold may now reach it.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Additionally, v1.2 formalizes vulnerability management through fixed testing intervals for scans and penetration tests, as well as clear thresholds. Monthly vulnerability scans and annual penetration tests are thus mandated.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>The implications for you:<\/strong> Configure your tools, assessment logic, and release gates so that you consistently process CVSS v4.0 and prioritize findings in a transparent manner.<\/p>\n\n\n\n<div style=\"height:21px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 class=\"wp-block-heading\">Supply Chain Security: Version Pinning Becomes Mandatory<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">In v1.2, EPI tightens its requirements for managing software dependencies: dependencies must be pinned to specific versions. The goal is to ensure reproducible builds, controlled updates, and reduced risk from untested version jumps.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>The implications for you:<\/strong> To implement and demonstrate compliance, you need binding rules in your CI\/CD setup, such as lockfiles, approval gates, and a defined update process that controls dependency updates and makes them reproducible.<\/p>\n\n\n\n<div style=\"height:21px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 class=\"wp-block-heading\">Certificate Validation: Certificate Transparency Monitoring as an Alternative<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Version 1.2 maintains the core principle of strong certificate validation but allows for more implementation options: In addition to certificate pinning, EPI also accepts Certificate Transparency (CT) monitoring as an alternative. CT is a protocol for publicly logging TLS certificates to make CA activity auditable and to detect suspicious certificates more quickly.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>The implications for you:<\/strong> It is crucial that you provide verifiable evidence of the chosen solution, for example through documented monitoring and response processes as well as corresponding proof.<\/p>\n\n\n\n<div style=\"height:21px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 class=\"wp-block-heading\">What You Should Specifically Prepare Now<\/h2>\n\n\n\n<div style=\"height:13px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<div class=\"wp-block-columns is-layout-flex wp-container-core-columns-is-layout-8f761849 wp-block-columns-is-layout-flex\">\n<div class=\"wp-block-column is-vertically-aligned-center is-layout-flow wp-block-column-is-layout-flow\" style=\"flex-basis:70%\">\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\">The new EPI Security Requirements sharpen regulatory expectations, expand technical checkpoints, and increase the requirements for verifiable evidence. My advice to affected companies is to conduct a targeted review now to identify where governance, secure development, and evidence of controls need to be strengthened, before this creates time pressure during the audit.<\/p>\n\n\n\n<div style=\"height:8px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p class=\"has-small-font-size wp-block-paragraph\"><em>Phillip Meyer, Managing Security Consultant, usd AG<\/em><\/p>\n<\/blockquote>\n<\/div>\n\n\n\n<div class=\"wp-block-column is-vertically-aligned-center is-layout-flow wp-block-column-is-layout-flow\" style=\"flex-basis:30%\">\n<figure class=\"wp-block-image aligncenter size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"480\" height=\"480\" src=\"https:\/\/www.usd.de\/wp-content\/uploads\/Phillip-Meyer.png\" alt=\"\" class=\"wp-image-53798\" style=\"width:160px\" \/><\/figure>\n<\/div>\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Our recommendation, start with these four points:<\/strong><\/p>\n\n\n\n<ol start=\"1\" class=\"wp-block-list\">\n<li>DORA Mapping: Embed DORA references in controls, policies, and evidence<\/li>\n\n\n\n<li>ASVS as an assessment benchmark: Define ASVS levels for each application and build tests and evidence around them.<\/li>\n\n\n\n<li>CVSS v4.0 transition: Adapt tools and processes, including severity thresholds and reporting.<\/li>\n\n\n\n<li>Dependency governance: Enforce version pinning via CI gates and define a controlled update process.<\/li>\n<\/ol>\n\n\n\n<div style=\"height:13px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\" \/>\n\n\n\n<div style=\"height:13px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p class=\"wp-block-paragraph\">Would you like to know how well prepared you are for the EPI Security Requirements v1.2? We assist you with the assessment, audit preparation, and implementation. <a href=\"https:\/\/www.usd.de\/en\/contact-form-security-audits\/\" data-type=\"link\" data-id=\"https:\/\/www.usd.de\/en\/contact-form-security-audits\/\">Contact us<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The European Payment Initiative (EPI) released Security Requirements v1.2 on 17.07.2026. The update focuses on governance, application security, and evidence requirements - areas that directly impact implementation and audit readiness. As an accredited External Security Evaluator, we support EPI participants in security assessments and audit preparation. Our colleague Phillip Meyer reviewed the new version to [&hellip;]<\/p>\n","protected":false},"author":117,"featured_media":67237,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_et_pb_use_builder":"off","_et_pb_old_content":"","_et_gb_content_width":"","inline_featured_image":false,"footnotes":""},"categories":[373,15194,389],"tags":[12541,15132,12542,439,12544],"class_list":["post-66513","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news-en","category-payment-security","category-security-audits-en","tag-epi-en","tag-epi-security-requirements-v1-2","tag-european-payments-initiative-en","tag-payment-security-en","tag-wero-en"],"_links":{"self":[{"href":"https:\/\/www.usd.de\/en\/wp-json\/wp\/v2\/posts\/66513","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.usd.de\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.usd.de\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.usd.de\/en\/wp-json\/wp\/v2\/users\/117"}],"replies":[{"embeddable":true,"href":"https:\/\/www.usd.de\/en\/wp-json\/wp\/v2\/comments?post=66513"}],"version-history":[{"count":5,"href":"https:\/\/www.usd.de\/en\/wp-json\/wp\/v2\/posts\/66513\/revisions"}],"predecessor-version":[{"id":67912,"href":"https:\/\/www.usd.de\/en\/wp-json\/wp\/v2\/posts\/66513\/revisions\/67912"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.usd.de\/en\/wp-json\/wp\/v2\/media\/67237"}],"wp:attachment":[{"href":"https:\/\/www.usd.de\/en\/wp-json\/wp\/v2\/media?parent=66513"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.usd.de\/en\/wp-json\/wp\/v2\/categories?post=66513"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.usd.de\/en\/wp-json\/wp\/v2\/tags?post=66513"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}