PCI PIN Assessment FAQs

PCI PIN refers to the security requirements and assessment for merchants that accept, process or transmit payment card personal identification numbers (PIN). The PIN Security requirements are set by the Payment Card Industry Security Standards Council (PCI SSC) and outlined in the PCI PIN Security Documents and Procedures V.3.

What is a PCI PIN Assessment?

The purpose of a PCI PIN Assessment is to assess that organizations are securely managing, processing, and transmitting PIN data during online and offline payment card transactions. A PCI PIN Assessment involves encryption and key management of PIN transactions, as well as the secure management of processing equipment. POS devices (where you enter your PIN) and the hardware security module (HSM) used to decrypt the PIN and to manage the keys are all key parts of a PIN Assessment. Your PIN is encrypted and its unique key is stored on the device. Any part of this chain–processing the PIN and managing keys used to protect the PIN–is considered in scope.

PCI PIN Security Assessment

Who needs PCI PIN Assessments?

The PCI PIN Assessment is required for: