PCI 3DS Core Security Standard
Part 2 Requirement P2-5: Protect 3DS data – PCI 3DS Core Security Standard

PCI 3DS Core Security Standard P2-5.4.1: P2-5.4.1 Stored 3DS sensitive data limited to permitted elements

Only the 3DS sensitive data elements that are permitted may be stored. Which elements count, and which component may store each, is set in the Council's Data Matrix, whose September 2026 release (v1.3) dropped the Authentication Value from the authentication-data category. The assessor examines data flows and 3DS transaction processes and observes data storage.

Maintained by Gerard Blokdyk

What else in your programme already covers this

This control maps to 2 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • A.1-6 A.1-6 Data elements: presence, edit criteria, AReq encryption, detailed values and message extensions

PCI DSS 4.0 · 1 control

  • 3.3.1 3.3.1 SAD not retained after authorization, even encrypted

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Part 2 Requirement P2-5: Protect 3DS data – PCI 3DS Core Security Standard

Query this from an agent

The graph holds this control, the 2 it maps to, and the evidence behind each claim, over MCP and REST.