Skip to main content

PCI PIN Compliance and Certification

PCI PIN Adaptation and Certification

Payment Card Industry PIN Security (PCI PIN) is a security standard that defines the set of requirements for the secure management, processing, and transmission of personal identification number (PIN) data during the processing of payment card transactions online and offline at ATMs and attended and unattended point-of-sale (POS) terminals.

Its purpose is to reduce fraud, protect sensitive payment information, and increase the security of this data.

PCI PIN, together with the rest of the PCI family programs, is the result of the efforts of the PCI Security Standards Council (PCI SSC), formed by the main payment card issuing companies (VISA, MASTERCARD, AMERICAN EXPRESS, JCB, DISCOVER), and is intended to be used by all institutions and acquiring agents such as key injection facilities and certificate processors responsible for processing PIN transactions in the accounts of participants in the payment card industry, and must be used together with other applicable industry standards.

The PCI PIN program, which had been managed by VISA since its first version in 2011, underwent a transition process to become the responsibility of the PCI SSC following the publication of version 3.0 in August 2018. Internet Security Auditors was one of the first 5 companies worldwide to pass the approval process defined by the PCI SSC in the QPA (Qualified PIN Assessor) program initiated in 2019.

Internet Security Auditors, with its experience in information security consulting and auditing, is in a position to help all organizations that are required to define and maintain a compliance program for the requirements demanded by PCI PIN, being the only Ibero-American company with QPA accreditation.

The process followed in the implementation, certification, and maintenance of PCI PIN is as follows:

 

PCI PIN Technical Office

Internet Security Auditors, through its implementation consulting service, aims to provide organizations with all the necessary support and guide them in defining and maintaining the PCI PIN compliance program.

Compliance Analysis and Action Plan

The first step to comply with PCI PIN requirements is to perform an analysis of the company processes involving the PIN, key injection processes, encryption key management, etc.

Once these processes are clearly identified, risks must be assessed and alignment activities defined to establish and maintain the necessary security measures to comply with the requirements defined in the applicable standard for those processes. In the case of KIF (Key Injection Facilities), the set of requirements will be a subset of those required by the standard.

 

Implementation of Requirements for Adaptation

The Implementation of Requirements for Adaptation executes the compliance program for the non-conformities detected in previous phases, carrying out consulting and advisory activities in any task that must be developed to achieve PCI PIN compliance.

PCI PIN Compliance Certification Audit

Internet Security Auditors is accredited by the PCI SSC, through its QPA certificate, to perform the required annual on-site biennial audits. During the audit process, technical and procedural reviews are conducted to verify that the requirements established in PCI PIN are being met. For all points that are not met, an action plan is defined to resolve the non-conformities.

 

What Our Clients Say


Do not hesitate to contact us if you need more information

Send us your questions and we will contact you as soon as possible.
CAPTCHA