PCI PIN Security Requirements v3.1
PCI requirements for the secure management of PINs and cryptographic keys used in payment transactions. Covers Hardware Security Module (HSM) physical and logical security, key management lifecycle, PIN entry device validation, PIN transmission encryption (ISO 9564), key injection ceremonies, DUKPT key derivation, and certificate management. Mandatory for acquirers, processors, and their agents handling PIN-based transactions.
| Clause | Title | SP 800-53 Controls |
|---|---|---|
| 1 | PIN Security Management | |
| 2 | PIN Entry Devices | |
| 3 | PIN Transmission | |
| 4 | PIN Processing | |
| 5 | Key Management | |
| 6 | Key Loading | |
| 7 | HSM Physical Security | |
| 8 | HSM Logical Security | |
| 9 | Certificate and Asymmetric Key Management | |
| 10 | Audit and Compliance |