PCI 3DS Core Security Standard
The PCI Security Standards Council's standard for the environments in which EMV 3-D Secure core components run: the Access Control Server (ACS), Directory Server (DS) and 3DS Server. Part 1 sets baseline security (policy, risk, awareness, screening, networks, secure development, configuration and change, malware and vulnerabilities, access, physical security, incident response and logging) and can be met by leveraging a recent PCI DSS assessment of the same environment; Part 2 sets 3DS-specific controls (scope, governance, third parties, ACS and DS boundaries, APIs and web configuration, availability, customer and remote access, 3DS data protection with TLS per EMVCo and storage per the PCI 3DS Data Matrix, transaction monitoring, key management with HSMs at the ACS and DS, and data-centre and CCTV controls). Version 1.0 of October 2017 is current, with Technical FAQs of September 2023 and Data Matrix v1.3 of September 2026. Built from the Council's ROC template, which restates every requirement.
PCI 3DS Core Security Standard is a compliance framework from Global (PCI Security Standards Council; applied through the payment brands' compliance programmes, e.g. listed in the Visa Core Rules of 18 April 2026 for all regions) with 14 domains and 143 controls that map to 4 other frameworks. The largest domains are Part 1 Requirement P1-3: Develop and maintain secure systems – PCI 3DS Core Security Standard (17 controls), Part 2 Requirement P2-6: Cryptography and key management – PCI 3DS Core Security Standard (17 controls), Part 2 Requirement P2-3: Protect 3DS systems and applications – PCI 3DS Core Security Standard (14 controls). Every control below carries what it requires and what an assessor expects to see.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (14)
Part 1 Requirement P1-1: Maintain security policies for all personnel – PCI 3DS Core Security Standard
| Code | Title |
|---|---|
| pci-3ds-core-security-standard::P1-1.1.1 | P1-1.1.1 Organisation-wide security policy exists and reaches everyone concerned |
| pci-3ds-core-security-standard::P1-1.1.2 | P1-1.1.2 Policy revised when business aims or risks change |
| pci-3ds-core-security-standard::P1-1.1.3 | P1-1.1.3 Policy changes communicated to the people affected |
| pci-3ds-core-security-standard::P1-1.1.4 | P1-1.1.4 Management approval of the security policy |
| pci-3ds-core-security-standard::P1-1.1.5 | P1-1.1.5 Personnel confirm they have read and understood the policy |
| pci-3ds-core-security-standard::P1-1.2.1 | P1-1.2.1 Written risk-assessment process |
| pci-3ds-core-security-standard::P1-1.2.2 | P1-1.2.2 Risk assessment run yearly and after significant change |
| pci-3ds-core-security-standard::P1-1.3.1 | P1-1.3.1 Security awareness programme in operation |
| pci-3ds-core-security-standard::P1-1.3.2 | P1-1.3.2 Awareness training at set intervals, fitted to the role |
| pci-3ds-core-security-standard::P1-1.3.3 | P1-1.3.3 Staff know the policy and their own security duties |
| pci-3ds-core-security-standard::P1-1.4.1 | P1-1.4.1 Background screening before 3DE access |
| pci-3ds-core-security-standard::P1-1.4.2 | P1-1.4.2 Screening criteria and decision process defined |
Part 1 Requirement P1-2: Secure network connectivity – PCI 3DS Core Security Standard
| Code | Title |
|---|---|
| pci-3ds-core-security-standard::P1-2.1.1 | P1-2.1.1 Boundary-protection policy and procedures for the 3DE |
| pci-3ds-core-security-standard::P1-2.1.2 | P1-2.1.2 Current network and data-flow records for every 3DS path |
| pci-3ds-core-security-standard::P1-2.1.3 | P1-2.1.3 Physical or logical limits between trusted and untrusted zones |
| pci-3ds-core-security-standard::P1-2.1.4 | P1-2.1.4 Only necessary 3DS traffic permitted, rest denied |
| pci-3ds-core-security-standard::P1-2.1.5 | P1-2.1.5 Network controls monitored or reviewed for effectiveness |
| pci-3ds-core-security-standard::P1-2.2.1 | P1-2.2.1 Detection or blocking of known and unknown network attacks |
| pci-3ds-core-security-standard::P1-2.2.2 | P1-2.2.2 Suspicious traffic blocked or alerted and acted upon |
Part 1 Requirement P1-3: Develop and maintain secure systems – PCI 3DS Core Security Standard
| Code | Title |
|---|---|
| pci-3ds-core-security-standard::P1-3.1.1 | P1-3.1.1 Secure development lifecycle policy and procedures |
| pci-3ds-core-security-standard::P1-3.1.2 | P1-3.1.2 Developers trained in secure development |
| pci-3ds-core-security-standard::P1-3.1.3 | P1-3.1.3 Development procedures address common coding weaknesses |
| pci-3ds-core-security-standard::P1-3.1.4 | P1-3.1.4 Security testing during development using documented methods |
| pci-3ds-core-security-standard::P1-3.1.5 | P1-3.1.5 Testing surfaces defects and vulnerabilities |
| pci-3ds-core-security-standard::P1-3.1.6 | P1-3.1.6 Defects and vulnerabilities fixed before release |
| pci-3ds-core-security-standard::P1-3.1.7 | P1-3.1.7 Management signs off test results before release |
| pci-3ds-core-security-standard::P1-3.2.1 | P1-3.2.1 Build and configuration management policy and procedures |
| pci-3ds-core-security-standard::P1-3.2.2 | P1-3.2.2 Current inventory of 3DS system components |
| pci-3ds-core-security-standard::P1-3.2.3 | P1-3.2.3 Configuration standards defined and applied to every 3DS system type |
| pci-3ds-core-security-standard::P1-3.2.4 | P1-3.2.4 Standards cover known weaknesses and follow hardening benchmarks |
| pci-3ds-core-security-standard::P1-3.2.5 | P1-3.2.5 Build standards remove defaults, excess functions and mixed trust levels |
| pci-3ds-core-security-standard::P1-3.3.1 | P1-3.3.1 Change-control procedures for all changes, including emergencies |
| pci-3ds-core-security-standard::P1-3.3.2 | P1-3.3.2 Changes authorised with security impact understood first |
| pci-3ds-core-security-standard::P1-3.3.3 | P1-3.3.3 Changes tested outside production |
| pci-3ds-core-security-standard::P1-3.3.4 | P1-3.3.4 Rollback prepared for every change |
| pci-3ds-core-security-standard::P1-3.3.5 | P1-3.3.5 Unauthorised configuration changes prevented or detected and handled |
Part 1 Requirement P1-4: Vulnerability management – PCI 3DS Core Security Standard
| Code | Title |
|---|---|
| pci-3ds-core-security-standard::P1-4.1.1 | P1-4.1.1 Malware-protection policy and procedures |
| pci-3ds-core-security-standard::P1-4.1.2 | P1-4.1.2 Anti-malware controls active and maintained |
| pci-3ds-core-security-standard::P1-4.2.1 | P1-4.2.1 Vulnerability-management policy and procedures |
| pci-3ds-core-security-standard::P1-4.2.2 | P1-4.2.2 Quarterly internal and external vulnerability scans |
| pci-3ds-core-security-standard::P1-4.2.3 | P1-4.2.3 Scans run by qualified parties, external by an ASV |
| pci-3ds-core-security-standard::P1-4.2.4 | P1-4.2.4 Vulnerabilities ranked by criticality |
| pci-3ds-core-security-standard::P1-4.2.5 | P1-4.2.5 Annual penetration testing |
| pci-3ds-core-security-standard::P1-4.2.6 | P1-4.2.6 Penetration tests by qualified personnel |
| pci-3ds-core-security-standard::P1-4.2.7 | P1-4.2.7 High-risk findings fixed within a month, others promptly |
Part 1 Requirement P1-5: Manage access – PCI 3DS Core Security Standard
| Code | Title |
|---|---|
| pci-3ds-core-security-standard::P1-5.1.1 | P1-5.1.1 Access-assignment policy and procedures |
| pci-3ds-core-security-standard::P1-5.1.2 | P1-5.1.2 Roles and responsibilities defined for groups and accounts |
| pci-3ds-core-security-standard::P1-5.1.3 | P1-5.1.3 Least privilege by job function, reviewed periodically |
| pci-3ds-core-security-standard::P1-5.2.1 | P1-5.2.1 Account-management policy and procedures |
| pci-3ds-core-security-standard::P1-5.2.2 | P1-5.2.2 Unique account ID per individual |
| pci-3ds-core-security-standard::P1-5.2.3 | P1-5.2.3 Accounts and credentials kept confidential and intact |
| pci-3ds-core-security-standard::P1-5.2.4 | P1-5.2.4 Account misuse prevented |
| pci-3ds-core-security-standard::P1-5.2.5 | P1-5.2.5 Third-party access identified, controlled and monitored |
| pci-3ds-core-security-standard::P1-5.3.1 | P1-5.3.1 Strong authentication for all access to 3DS systems |
Part 1 Requirement P1-6: Physical security – PCI 3DS Core Security Standard
| Code | Title |
|---|---|
| pci-3ds-core-security-standard::P1-6.1.1 | P1-6.1.1 Physical-access policy and procedures for 3DS systems |
| pci-3ds-core-security-standard::P1-6.1.2 | P1-6.1.2 Entry controls limit and monitor physical access |
| pci-3ds-core-security-standard::P1-6.1.3 | P1-6.1.3 Physical access authorised by job function |
| pci-3ds-core-security-standard::P1-6.1.4 | P1-6.1.4 Physical access removed immediately on termination |
| pci-3ds-core-security-standard::P1-6.2.1 | P1-6.2.1 Strict control over media storage and access |
Part 1 Requirement P1-7: Incident response preparedness – PCI 3DS Core Security Standard
| Code | Title |
|---|---|
| pci-3ds-core-security-standard::P1-7.1.1 | P1-7.1.1 Incident-management policy and procedures |
| pci-3ds-core-security-standard::P1-7.1.2 | P1-7.1.2 Incident response plan with its required elements |
| pci-3ds-core-security-standard::P1-7.1.3 | P1-7.1.3 Plan reviewed and tested every year |
| pci-3ds-core-security-standard::P1-7.2.1 | P1-7.2.1 Audit-logging policy and procedures |
| pci-3ds-core-security-standard::P1-7.2.2 | P1-7.2.2 Logs tie access to individuals and record security events |
| pci-3ds-core-security-standard::P1-7.2.3 | P1-7.2.3 Clocks synchronised on 3DS systems |
| pci-3ds-core-security-standard::P1-7.2.4 | P1-7.2.4 Logs and security events monitored or reviewed |
| pci-3ds-core-security-standard::P1-7.2.5 | P1-7.2.5 Audit logs protected from alteration |
| pci-3ds-core-security-standard::P1-7.2.6 | P1-7.2.6 Log retention of one year, three months at hand |
Part 2 Requirement P2-1: Validate scope – PCI 3DS Core Security Standard
| Code | Title |
|---|---|
| pci-3ds-core-security-standard::P2-1.1.1 | P2-1.1.1 In-scope networks and components identified |
| pci-3ds-core-security-standard::P2-1.1.2 | P2-1.1.2 Out-of-scope networks justified with their segmentation |
| pci-3ds-core-security-standard::P2-1.1.3 | P2-1.1.3 Connected entities with 3DE access identified |
Part 2 Requirement P2-2: Security governance – PCI 3DS Core Security Standard
| Code | Title |
|---|---|
| pci-3ds-core-security-standard::P2-2.1.1 | P2-2.1.1 Security objectives aligned with business objectives |
| pci-3ds-core-security-standard::P2-2.1.2 | P2-2.1.2 Security responsibility and accountability formally assigned |
| pci-3ds-core-security-standard::P2-2.1.3 | P2-2.1.3 Responsibility for evolving risks assigned |
| pci-3ds-core-security-standard::P2-2.2.1 | P2-2.2.1 Formal risk-management strategy defined |
| pci-3ds-core-security-standard::P2-2.2.2 | P2-2.2.2 Risk strategy approved and kept current |
| pci-3ds-core-security-standard::P2-2.3.1 | P2-2.3.1 Periodic checks that staff follow security policies |
| pci-3ds-core-security-standard::P2-2.3.2 | P2-2.3.2 Security control failures detected and responded to |
| pci-3ds-core-security-standard::P2-2.4.1 | P2-2.4.1 Third-party relationship policies and procedures |
| pci-3ds-core-security-standard::P2-2.4.2 | P2-2.4.2 Due diligence before engaging a third party |
| pci-3ds-core-security-standard::P2-2.4.3 | P2-2.4.3 Security responsibilities defined per engagement |
| pci-3ds-core-security-standard::P2-2.4.4 | P2-2.4.4 Third parties' agreed responsibilities verified periodically |
| pci-3ds-core-security-standard::P2-2.4.5 | P2-2.4.5 Written agreements maintained |
Part 2 Requirement P2-3: Protect 3DS systems and applications – PCI 3DS Core Security Standard
| Code | Title |
|---|---|
| pci-3ds-core-security-standard::P2-3.1.1 | P2-3.1.1 ACS and DS traffic limited to 3DS functions |
| pci-3ds-core-security-standard::P2-3.1.2 | P2-3.1.2 ACS and DS reachable only through approved interfaces |
| pci-3ds-core-security-standard::P2-3.2.1 | P2-3.2.1 Configurations and security documentation protected |
| pci-3ds-core-security-standard::P2-3.3.1 | P2-3.3.1 Production applications protected from unauthorised change |
| pci-3ds-core-security-standard::P2-3.3.2 | P2-3.3.2 Application protection mechanisms monitored and maintained |
| pci-3ds-core-security-standard::P2-3.3.3 | P2-3.3.3 APIs to the 3DE identified, defined and tested |
| pci-3ds-core-security-standard::P2-3.3.4 | P2-3.3.4 APIs exposed to untrusted networks protected |
| pci-3ds-core-security-standard::P2-3.4.1 | P2-3.4.1 Only required HTTP methods accepted |
| pci-3ds-core-security-standard::P2-3.4.2 | P2-3.4.2 HTTPS enforced everywhere |
| pci-3ds-core-security-standard::P2-3.4.3 | P2-3.4.3 External content rejected by default |
| pci-3ds-core-security-standard::P2-3.4.4 | P2-3.4.4 Framing by untrusted sites prevented |
| pci-3ds-core-security-standard::P2-3.4.5 | P2-3.4.5 Native framework protections enabled |
| pci-3ds-core-security-standard::P2-3.5.1 | P2-3.5.1 Availability mechanisms against loss of 3DS processing |
| pci-3ds-core-security-standard::P2-3.5.2 | P2-3.5.2 Availability mechanisms monitored and maintained |
Part 2 Requirement P2-4: Secure logical access to 3DS systems – PCI 3DS Core Security Standard
| Code | Title |
|---|---|
| pci-3ds-core-security-standard::P2-4.1.1 | P2-4.1.1 Issuer and merchant user access to their own interfaces |
| pci-3ds-core-security-standard::P2-4.2.1 | P2-4.2.1 Multi-factor for all non-console personnel access |
| pci-3ds-core-security-standard::P2-4.3.1 | P2-4.3.1 Multi-factor for remote access into the 3DE |
| pci-3ds-core-security-standard::P2-4.3.2 | P2-4.3.2 Remote access controlled and documented |
| pci-3ds-core-security-standard::P2-4.3.3 | P2-4.3.3 Rules for personally owned devices used remotely |
| pci-3ds-core-security-standard::P2-4.3.4 | P2-4.3.4 Remote access privileges reviewed at least quarterly |
| pci-3ds-core-security-standard::P2-4.4.1 | P2-4.4.1 No wireless use by 3DS components |
| pci-3ds-core-security-standard::P2-4.5.1 | P2-4.5.1 VPNs into the 3DE securely configured |
Part 2 Requirement P2-5: Protect 3DS data – PCI 3DS Core Security Standard
| Code | Title |
|---|---|
| pci-3ds-core-security-standard::P2-5.1.1 | P2-5.1.1 3DS data lifecycle policies and procedures |
| pci-3ds-core-security-standard::P2-5.1.2 | P2-5.1.2 3DS data kept only as long as needed, then purged securely |
| pci-3ds-core-security-standard::P2-5.2.1 | P2-5.2.1 Strong cryptography for 3DS sensitive data in transit |
| pci-3ds-core-security-standard::P2-5.2.2 | P2-5.2.2 No fallback to insecure protocols |
| pci-3ds-core-security-standard::P2-5.3.1 | P2-5.3.1 TLS between 3DS components uses only allowed cipher suites |
| pci-3ds-core-security-standard::P2-5.3.2 | P2-5.3.2 No EMVCo-unsupported cipher suites offered |
| pci-3ds-core-security-standard::P2-5.3.3 | P2-5.3.3 No rollback to unapproved algorithms or key sizes |
| pci-3ds-core-security-standard::P2-5.3.4 | P2-5.3.4 TLS configurations monitored for change |
| pci-3ds-core-security-standard::P2-5.4.1 | P2-5.4.1 Stored 3DS sensitive data limited to permitted elements |
| pci-3ds-core-security-standard::P2-5.4.2 | P2-5.4.2 Strong cryptography for stored 3DS sensitive data |
| pci-3ds-core-security-standard::P2-5.5.1 | P2-5.5.1 3DS transactions monitored for anomalies |
| pci-3ds-core-security-standard::P2-5.5.2 | P2-5.5.2 Anomalous transaction activity investigated promptly |
Part 2 Requirement P2-6: Cryptography and key management – PCI 3DS Core Security Standard
| Code | Title |
|---|---|
| pci-3ds-core-security-standard::P2-6.1.1 | P2-6.1.1 Cryptography and key-management policies and procedures |
| pci-3ds-core-security-standard::P2-6.1.10 | P2-6.1.10 Incident response covers key-related issues |
| pci-3ds-core-security-standard::P2-6.1.2 | P2-6.1.2 HSM for specified keys at ACS and DS |
| pci-3ds-core-security-standard::P2-6.1.3 | P2-6.1.3 HSM deployed according to its security policy |
| pci-3ds-core-security-standard::P2-6.1.4 | P2-6.1.4 Documented cryptographic architecture |
| pci-3ds-core-security-standard::P2-6.1.5 | P2-6.1.5 Keys managed securely through their whole lifecycle |
| pci-3ds-core-security-standard::P2-6.1.6 | P2-6.1.6 Key management follows recognised standards |
| pci-3ds-core-security-standard::P2-6.1.7 | P2-6.1.7 Keys used only for their intended purpose |
| pci-3ds-core-security-standard::P2-6.1.8 | P2-6.1.8 Trusted CA for all 3DS certificates |
| pci-3ds-core-security-standard::P2-6.1.9 | P2-6.1.9 Audit logs for key-management and clear-text component activity |
| pci-3ds-core-security-standard::P2-6.2.1 | P2-6.2.1 Logical HSM access at the console or through an evaluated solution |
| pci-3ds-core-security-standard::P2-6.2.2 | P2-6.2.2 Non-console HSM access originates only from the 3DE |
| pci-3ds-core-security-standard::P2-6.2.3 | P2-6.2.3 Devices used for non-console HSM access secured |
| pci-3ds-core-security-standard::P2-6.2.4 | P2-6.2.4 No clear-text key loading or export over non-console links |
| pci-3ds-core-security-standard::P2-6.2.5 | P2-6.2.5 Non-console activity meets all other HSM and key rules |
| pci-3ds-core-security-standard::P2-6.3.1 | P2-6.3.1 HSMs kept in dedicated areas |
| pci-3ds-core-security-standard::P2-6.3.2 | P2-6.3.2 Physical HSM access restricted and under dual control |
Part 2 Requirement P2-7: Physically secure 3DS systems – PCI 3DS Core Security Standard
| Code | Title |
|---|---|
| pci-3ds-core-security-standard::P2-7.1.1 | P2-7.1.1 ACS and DS hosted in data centres |
| pci-3ds-core-security-standard::P2-7.1.2 | P2-7.1.2 Single-entry portal with positive authentication |
| pci-3ds-core-security-standard::P2-7.1.3 | P2-7.1.3 Electronic access control on internal doors to 3DS areas |
| pci-3ds-core-security-standard::P2-7.1.4 | P2-7.1.4 Multi-factor entry to telecom rooms outside the data centre |
| pci-3ds-core-security-standard::P2-7.1.5 | P2-7.1.5 Anti-piggybacking entry controls |
| pci-3ds-core-security-standard::P2-7.1.6 | P2-7.1.6 Intrusion detection linked to the alarm system |
| pci-3ds-core-security-standard::P2-7.1.7 | P2-7.1.7 Physical connection points into the 3DE controlled at all times |
| pci-3ds-core-security-standard::P2-7.2.1 | P2-7.2.1 CCTV at every entrance and emergency exit |
| pci-3ds-core-security-standard::P2-7.2.2 | P2-7.2.2 CCTV recordings time-stamped |
Your Compliance Coverage
If you comply with PCI 3DS Core Security Standard, you already cover:
PCI DSS 4.0
82%
117 controls mapped
Compare →ISO 27002:2022
22%
31 controls mapped
Compare →PCI PIN Security
7%
10 controls mapped
Compare →+ 1 more: EMV 3-D Secure (3DS) - Payment Authentication Protocol (4%)
See all 4 mapped frameworks ↓Maps to 4 other frameworks
Coverage is not the same as your position
This page shows what PCI 3DS Core Security Standard overlaps with in general. Where your organisation actually stands, against the standard you are going for and the certifications you already hold, is a different question. Same graph and the same recorded refutations, scoped to you rather than to a pair.
The Compliance Position Diagnostic, $5,000 fixed, ten business daysWhat is PCI 3DS Core Security Standard and who does it apply to?
PCI 3DS Core Security Standard is a compliance framework from Global (PCI Security Standards Council; applied through the payment brands' compliance programmes, e.g. listed in the Visa Core Rules of 18 April 2026 for all regions) with 14 domains and 143 controls. The PCI Security Standards Council's standard for the environments in which EMV 3-D Secure core components run: the Access Control Server (ACS), Directory Server (DS) and 3DS Server. Part 1 sets baseline security (policy, risk, awareness, screening, networks, secure development, configuration and change, malware and vulnerabilities, access, physical security, incident response and logging) and can be met by leveraging a recent PCI DSS assessment of the same environment; Part 2 sets 3DS-specific controls (scope, governance, third parties, ACS and DS boundaries, APIs and web configuration, availability, customer and remote access, 3DS data protection with TLS per EMVCo and storage per the PCI 3DS Data Matrix, transaction monitoring, key management with HSMs at the ACS and DS, and data-centre and CCTV controls). Version 1.0 of October 2017 is current, with Technical FAQs of September 2023 and Data Matrix v1.3 of September 2026. Built from the Council's ROC template, which restates every requirement. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
What does PCI 3DS Core Security Standard actually require?
PCI 3DS Core Security Standard has 143 controls organised across 14 domains. The largest domains are Part 1 Requirement P1-3: Develop and maintain secure systems – PCI 3DS Core Security Standard (17 controls), Part 2 Requirement P2-6: Cryptography and key management – PCI 3DS Core Security Standard (17 controls), Part 2 Requirement P2-3: Protect 3DS systems and applications – PCI 3DS Core Security Standard (14 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
If I already comply with another framework, how much of PCI 3DS Core Security Standard do I already cover?
PCI 3DS Core Security Standard maps to 4 other compliance frameworks. The top mapping partners are PCI DSS 4.0 (82% coverage), ISO 27002:2022 (22% coverage), PCI PIN Security (7% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I implement PCI 3DS Core Security Standard?
Start your PCI 3DS Core Security Standard compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about PCI 3DS Core Security Standard requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 143 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 727 frameworks.
Get Started Free →Free forever — no credit card required