PCI 3DS Core Security Standard
Part 2 Requirement P2-6: Cryptography and key management – PCI 3DS Core Security Standard

PCI 3DS Core Security Standard P2-6.1.8: P2-6.1.8 Trusted CA for all 3DS certificates

Every certificate the 3DS Server, ACS and DS present to one another comes from a certificate authority that can be trusted. The assessor examines evidence of CA validation (such as security assessments or certifications) and observes the certificates in use.

Maintained by Gerard Blokdyk

What else in your programme already covers this

This control maps to 2 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • 6.1.2-3 6.1.2-3 Links b and c: 3DS Server to DS and DS to ACS

PCI DSS 4.0 · 1 control

  • 4.2.1.1 4.2.1.1 Inventory of trusted transmission keys and certificates

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Part 2 Requirement P2-6: Cryptography and key management – PCI 3DS Core Security Standard

Query this from an agent

The graph holds this control, the 2 it maps to, and the evidence behind each claim, over MCP and REST.