NRF Cybersecurity and Data Privacy Framework (National Retail Federation)
Payment Card Protection and PCI DSS

NRF Cybersecurity and Data Privacy Framework (National Retail Federation) NRFCS-3: Payment Card Data Protection and PCI DSS Scope Management

Operate payment card data protection per the NRF framework + PCI DSS v4.0.1 + card brand operating rules (Visa + Mastercard + American Express + Discover + JCB + UnionPay + regional schemes). PCI DSS scope management must (a) accurately scope the Cardholder Data Environment (CDE) including all systems that store + process + transmit cardholder data + connected systems + security systems + service providers + merchant-of-record relationships, (b) implement scope-reduction strategies (point-to-point encryption + tokenisation + outsourced payment processing + e-commerce iframe / redirect to PSP-hosted payment pages + EMV chip + contactless) with documented residual scope, (c) achieve and maintain PCI DSS compliance per applicable merchant level (Level 1 over 6M card transactions + Level 2 1M-6M + Level 3 20K-1M e-commerce + Level 4 below) + Self-Assessment Questionnaire type + or Report on Compliance via QSA where required, (d) align with PCI Software Security Framework (formerly PA-DSS) for in-scope retail software, (e) align with PCI 3DS Core Security Standard for 3D Secure implementations, (f) align with PCI Mobile Payment-Acceptance Security Guidelines + PCI Contactless Payments for mobile and contactless deployments. Operate ongoing PCI DSS programme covering quarterly internal and external network vulnerability scans + annual penetration testing + change-driven re-validation + remediation of QSA findings. Report Service Provider Attestations of Compliance from PCI-relevant suppliers.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.