Back to Frameworks

PCI 3DS Core Security Standard

Global (PCI Security Standards Council; applied through the payment brands' compliance programmes, e.g. listed in the Visa Core Rules of 18 April 2026 for all regions)
vv1.0 (October 2017), the only version; Technical FAQs September 2023; PCI 3DS Data Matrix v1.3 (September 2026)
14 domains
143 controls

The PCI Security Standards Council's standard for the environments in which EMV 3-D Secure core components run: the Access Control Server (ACS), Directory Server (DS) and 3DS Server. Part 1 sets baseline security (policy, risk, awareness, screening, networks, secure development, configuration and change, malware and vulnerabilities, access, physical security, incident response and logging) and can be met by leveraging a recent PCI DSS assessment of the same environment; Part 2 sets 3DS-specific controls (scope, governance, third parties, ACS and DS boundaries, APIs and web configuration, availability, customer and remote access, 3DS data protection with TLS per EMVCo and storage per the PCI 3DS Data Matrix, transaction monitoring, key management with HSMs at the ACS and DS, and data-centre and CCTV controls). Version 1.0 of October 2017 is current, with Technical FAQs of September 2023 and Data Matrix v1.3 of September 2026. Built from the Council's ROC template, which restates every requirement.

Verified

PCI 3DS Core Security Standard is a compliance framework from Global (PCI Security Standards Council; applied through the payment brands' compliance programmes, e.g. listed in the Visa Core Rules of 18 April 2026 for all regions) with 14 domains and 143 controls that map to 4 other frameworks. The largest domains are Part 1 Requirement P1-3: Develop and maintain secure systems – PCI 3DS Core Security Standard (17 controls), Part 2 Requirement P2-6: Cryptography and key management – PCI 3DS Core Security Standard (17 controls), Part 2 Requirement P2-3: Protect 3DS systems and applications – PCI 3DS Core Security Standard (14 controls). Every control below carries what it requires and what an assessor expects to see.

Maintained by Gerard Blokdyk

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (14)

Part 1 Requirement P1-1: Maintain security policies for all personnel – PCI 3DS Core Security Standard

12 controls
Controls in the Part 1 Requirement P1-1: Maintain security policies for all personnel – PCI 3DS Core Security Standard domain of PCI 3DS Core Security Standard — 12 controls
CodeTitle
pci-3ds-core-security-standard::P1-1.1.1P1-1.1.1 Organisation-wide security policy exists and reaches everyone concerned
pci-3ds-core-security-standard::P1-1.1.2P1-1.1.2 Policy revised when business aims or risks change
pci-3ds-core-security-standard::P1-1.1.3P1-1.1.3 Policy changes communicated to the people affected
pci-3ds-core-security-standard::P1-1.1.4P1-1.1.4 Management approval of the security policy
pci-3ds-core-security-standard::P1-1.1.5P1-1.1.5 Personnel confirm they have read and understood the policy
pci-3ds-core-security-standard::P1-1.2.1P1-1.2.1 Written risk-assessment process
pci-3ds-core-security-standard::P1-1.2.2P1-1.2.2 Risk assessment run yearly and after significant change
pci-3ds-core-security-standard::P1-1.3.1P1-1.3.1 Security awareness programme in operation
pci-3ds-core-security-standard::P1-1.3.2P1-1.3.2 Awareness training at set intervals, fitted to the role
pci-3ds-core-security-standard::P1-1.3.3P1-1.3.3 Staff know the policy and their own security duties
pci-3ds-core-security-standard::P1-1.4.1P1-1.4.1 Background screening before 3DE access
pci-3ds-core-security-standard::P1-1.4.2P1-1.4.2 Screening criteria and decision process defined

Part 1 Requirement P1-2: Secure network connectivity – PCI 3DS Core Security Standard

7 controls
Controls in the Part 1 Requirement P1-2: Secure network connectivity – PCI 3DS Core Security Standard domain of PCI 3DS Core Security Standard — 7 controls
CodeTitle
pci-3ds-core-security-standard::P1-2.1.1P1-2.1.1 Boundary-protection policy and procedures for the 3DE
pci-3ds-core-security-standard::P1-2.1.2P1-2.1.2 Current network and data-flow records for every 3DS path
pci-3ds-core-security-standard::P1-2.1.3P1-2.1.3 Physical or logical limits between trusted and untrusted zones
pci-3ds-core-security-standard::P1-2.1.4P1-2.1.4 Only necessary 3DS traffic permitted, rest denied
pci-3ds-core-security-standard::P1-2.1.5P1-2.1.5 Network controls monitored or reviewed for effectiveness
pci-3ds-core-security-standard::P1-2.2.1P1-2.2.1 Detection or blocking of known and unknown network attacks
pci-3ds-core-security-standard::P1-2.2.2P1-2.2.2 Suspicious traffic blocked or alerted and acted upon

Part 1 Requirement P1-3: Develop and maintain secure systems – PCI 3DS Core Security Standard

17 controls
Controls in the Part 1 Requirement P1-3: Develop and maintain secure systems – PCI 3DS Core Security Standard domain of PCI 3DS Core Security Standard — 17 controls
CodeTitle
pci-3ds-core-security-standard::P1-3.1.1P1-3.1.1 Secure development lifecycle policy and procedures
pci-3ds-core-security-standard::P1-3.1.2P1-3.1.2 Developers trained in secure development
pci-3ds-core-security-standard::P1-3.1.3P1-3.1.3 Development procedures address common coding weaknesses
pci-3ds-core-security-standard::P1-3.1.4P1-3.1.4 Security testing during development using documented methods
pci-3ds-core-security-standard::P1-3.1.5P1-3.1.5 Testing surfaces defects and vulnerabilities
pci-3ds-core-security-standard::P1-3.1.6P1-3.1.6 Defects and vulnerabilities fixed before release
pci-3ds-core-security-standard::P1-3.1.7P1-3.1.7 Management signs off test results before release
pci-3ds-core-security-standard::P1-3.2.1P1-3.2.1 Build and configuration management policy and procedures
pci-3ds-core-security-standard::P1-3.2.2P1-3.2.2 Current inventory of 3DS system components
pci-3ds-core-security-standard::P1-3.2.3P1-3.2.3 Configuration standards defined and applied to every 3DS system type
pci-3ds-core-security-standard::P1-3.2.4P1-3.2.4 Standards cover known weaknesses and follow hardening benchmarks
pci-3ds-core-security-standard::P1-3.2.5P1-3.2.5 Build standards remove defaults, excess functions and mixed trust levels
pci-3ds-core-security-standard::P1-3.3.1P1-3.3.1 Change-control procedures for all changes, including emergencies
pci-3ds-core-security-standard::P1-3.3.2P1-3.3.2 Changes authorised with security impact understood first
pci-3ds-core-security-standard::P1-3.3.3P1-3.3.3 Changes tested outside production
pci-3ds-core-security-standard::P1-3.3.4P1-3.3.4 Rollback prepared for every change
pci-3ds-core-security-standard::P1-3.3.5P1-3.3.5 Unauthorised configuration changes prevented or detected and handled

Part 1 Requirement P1-4: Vulnerability management – PCI 3DS Core Security Standard

9 controls
Controls in the Part 1 Requirement P1-4: Vulnerability management – PCI 3DS Core Security Standard domain of PCI 3DS Core Security Standard — 9 controls
CodeTitle
pci-3ds-core-security-standard::P1-4.1.1P1-4.1.1 Malware-protection policy and procedures
pci-3ds-core-security-standard::P1-4.1.2P1-4.1.2 Anti-malware controls active and maintained
pci-3ds-core-security-standard::P1-4.2.1P1-4.2.1 Vulnerability-management policy and procedures
pci-3ds-core-security-standard::P1-4.2.2P1-4.2.2 Quarterly internal and external vulnerability scans
pci-3ds-core-security-standard::P1-4.2.3P1-4.2.3 Scans run by qualified parties, external by an ASV
pci-3ds-core-security-standard::P1-4.2.4P1-4.2.4 Vulnerabilities ranked by criticality
pci-3ds-core-security-standard::P1-4.2.5P1-4.2.5 Annual penetration testing
pci-3ds-core-security-standard::P1-4.2.6P1-4.2.6 Penetration tests by qualified personnel
pci-3ds-core-security-standard::P1-4.2.7P1-4.2.7 High-risk findings fixed within a month, others promptly

Part 1 Requirement P1-5: Manage access – PCI 3DS Core Security Standard

9 controls
Controls in the Part 1 Requirement P1-5: Manage access – PCI 3DS Core Security Standard domain of PCI 3DS Core Security Standard — 9 controls
CodeTitle
pci-3ds-core-security-standard::P1-5.1.1P1-5.1.1 Access-assignment policy and procedures
pci-3ds-core-security-standard::P1-5.1.2P1-5.1.2 Roles and responsibilities defined for groups and accounts
pci-3ds-core-security-standard::P1-5.1.3P1-5.1.3 Least privilege by job function, reviewed periodically
pci-3ds-core-security-standard::P1-5.2.1P1-5.2.1 Account-management policy and procedures
pci-3ds-core-security-standard::P1-5.2.2P1-5.2.2 Unique account ID per individual
pci-3ds-core-security-standard::P1-5.2.3P1-5.2.3 Accounts and credentials kept confidential and intact
pci-3ds-core-security-standard::P1-5.2.4P1-5.2.4 Account misuse prevented
pci-3ds-core-security-standard::P1-5.2.5P1-5.2.5 Third-party access identified, controlled and monitored
pci-3ds-core-security-standard::P1-5.3.1P1-5.3.1 Strong authentication for all access to 3DS systems

Part 1 Requirement P1-6: Physical security – PCI 3DS Core Security Standard

5 controls
Controls in the Part 1 Requirement P1-6: Physical security – PCI 3DS Core Security Standard domain of PCI 3DS Core Security Standard — 5 controls
CodeTitle
pci-3ds-core-security-standard::P1-6.1.1P1-6.1.1 Physical-access policy and procedures for 3DS systems
pci-3ds-core-security-standard::P1-6.1.2P1-6.1.2 Entry controls limit and monitor physical access
pci-3ds-core-security-standard::P1-6.1.3P1-6.1.3 Physical access authorised by job function
pci-3ds-core-security-standard::P1-6.1.4P1-6.1.4 Physical access removed immediately on termination
pci-3ds-core-security-standard::P1-6.2.1P1-6.2.1 Strict control over media storage and access

Part 1 Requirement P1-7: Incident response preparedness – PCI 3DS Core Security Standard

9 controls
Controls in the Part 1 Requirement P1-7: Incident response preparedness – PCI 3DS Core Security Standard domain of PCI 3DS Core Security Standard — 9 controls
CodeTitle
pci-3ds-core-security-standard::P1-7.1.1P1-7.1.1 Incident-management policy and procedures
pci-3ds-core-security-standard::P1-7.1.2P1-7.1.2 Incident response plan with its required elements
pci-3ds-core-security-standard::P1-7.1.3P1-7.1.3 Plan reviewed and tested every year
pci-3ds-core-security-standard::P1-7.2.1P1-7.2.1 Audit-logging policy and procedures
pci-3ds-core-security-standard::P1-7.2.2P1-7.2.2 Logs tie access to individuals and record security events
pci-3ds-core-security-standard::P1-7.2.3P1-7.2.3 Clocks synchronised on 3DS systems
pci-3ds-core-security-standard::P1-7.2.4P1-7.2.4 Logs and security events monitored or reviewed
pci-3ds-core-security-standard::P1-7.2.5P1-7.2.5 Audit logs protected from alteration
pci-3ds-core-security-standard::P1-7.2.6P1-7.2.6 Log retention of one year, three months at hand

Part 2 Requirement P2-1: Validate scope – PCI 3DS Core Security Standard

3 controls
Controls in the Part 2 Requirement P2-1: Validate scope – PCI 3DS Core Security Standard domain of PCI 3DS Core Security Standard — 3 controls
CodeTitle
pci-3ds-core-security-standard::P2-1.1.1P2-1.1.1 In-scope networks and components identified
pci-3ds-core-security-standard::P2-1.1.2P2-1.1.2 Out-of-scope networks justified with their segmentation
pci-3ds-core-security-standard::P2-1.1.3P2-1.1.3 Connected entities with 3DE access identified

Part 2 Requirement P2-2: Security governance – PCI 3DS Core Security Standard

12 controls
Controls in the Part 2 Requirement P2-2: Security governance – PCI 3DS Core Security Standard domain of PCI 3DS Core Security Standard — 12 controls
CodeTitle
pci-3ds-core-security-standard::P2-2.1.1P2-2.1.1 Security objectives aligned with business objectives
pci-3ds-core-security-standard::P2-2.1.2P2-2.1.2 Security responsibility and accountability formally assigned
pci-3ds-core-security-standard::P2-2.1.3P2-2.1.3 Responsibility for evolving risks assigned
pci-3ds-core-security-standard::P2-2.2.1P2-2.2.1 Formal risk-management strategy defined
pci-3ds-core-security-standard::P2-2.2.2P2-2.2.2 Risk strategy approved and kept current
pci-3ds-core-security-standard::P2-2.3.1P2-2.3.1 Periodic checks that staff follow security policies
pci-3ds-core-security-standard::P2-2.3.2P2-2.3.2 Security control failures detected and responded to
pci-3ds-core-security-standard::P2-2.4.1P2-2.4.1 Third-party relationship policies and procedures
pci-3ds-core-security-standard::P2-2.4.2P2-2.4.2 Due diligence before engaging a third party
pci-3ds-core-security-standard::P2-2.4.3P2-2.4.3 Security responsibilities defined per engagement
pci-3ds-core-security-standard::P2-2.4.4P2-2.4.4 Third parties' agreed responsibilities verified periodically
pci-3ds-core-security-standard::P2-2.4.5P2-2.4.5 Written agreements maintained

Part 2 Requirement P2-3: Protect 3DS systems and applications – PCI 3DS Core Security Standard

14 controls
Controls in the Part 2 Requirement P2-3: Protect 3DS systems and applications – PCI 3DS Core Security Standard domain of PCI 3DS Core Security Standard — 14 controls
CodeTitle
pci-3ds-core-security-standard::P2-3.1.1P2-3.1.1 ACS and DS traffic limited to 3DS functions
pci-3ds-core-security-standard::P2-3.1.2P2-3.1.2 ACS and DS reachable only through approved interfaces
pci-3ds-core-security-standard::P2-3.2.1P2-3.2.1 Configurations and security documentation protected
pci-3ds-core-security-standard::P2-3.3.1P2-3.3.1 Production applications protected from unauthorised change
pci-3ds-core-security-standard::P2-3.3.2P2-3.3.2 Application protection mechanisms monitored and maintained
pci-3ds-core-security-standard::P2-3.3.3P2-3.3.3 APIs to the 3DE identified, defined and tested
pci-3ds-core-security-standard::P2-3.3.4P2-3.3.4 APIs exposed to untrusted networks protected
pci-3ds-core-security-standard::P2-3.4.1P2-3.4.1 Only required HTTP methods accepted
pci-3ds-core-security-standard::P2-3.4.2P2-3.4.2 HTTPS enforced everywhere
pci-3ds-core-security-standard::P2-3.4.3P2-3.4.3 External content rejected by default
pci-3ds-core-security-standard::P2-3.4.4P2-3.4.4 Framing by untrusted sites prevented
pci-3ds-core-security-standard::P2-3.4.5P2-3.4.5 Native framework protections enabled
pci-3ds-core-security-standard::P2-3.5.1P2-3.5.1 Availability mechanisms against loss of 3DS processing
pci-3ds-core-security-standard::P2-3.5.2P2-3.5.2 Availability mechanisms monitored and maintained

Part 2 Requirement P2-4: Secure logical access to 3DS systems – PCI 3DS Core Security Standard

8 controls
Controls in the Part 2 Requirement P2-4: Secure logical access to 3DS systems – PCI 3DS Core Security Standard domain of PCI 3DS Core Security Standard — 8 controls
CodeTitle
pci-3ds-core-security-standard::P2-4.1.1P2-4.1.1 Issuer and merchant user access to their own interfaces
pci-3ds-core-security-standard::P2-4.2.1P2-4.2.1 Multi-factor for all non-console personnel access
pci-3ds-core-security-standard::P2-4.3.1P2-4.3.1 Multi-factor for remote access into the 3DE
pci-3ds-core-security-standard::P2-4.3.2P2-4.3.2 Remote access controlled and documented
pci-3ds-core-security-standard::P2-4.3.3P2-4.3.3 Rules for personally owned devices used remotely
pci-3ds-core-security-standard::P2-4.3.4P2-4.3.4 Remote access privileges reviewed at least quarterly
pci-3ds-core-security-standard::P2-4.4.1P2-4.4.1 No wireless use by 3DS components
pci-3ds-core-security-standard::P2-4.5.1P2-4.5.1 VPNs into the 3DE securely configured

Part 2 Requirement P2-5: Protect 3DS data – PCI 3DS Core Security Standard

12 controls
Controls in the Part 2 Requirement P2-5: Protect 3DS data – PCI 3DS Core Security Standard domain of PCI 3DS Core Security Standard — 12 controls
CodeTitle
pci-3ds-core-security-standard::P2-5.1.1P2-5.1.1 3DS data lifecycle policies and procedures
pci-3ds-core-security-standard::P2-5.1.2P2-5.1.2 3DS data kept only as long as needed, then purged securely
pci-3ds-core-security-standard::P2-5.2.1P2-5.2.1 Strong cryptography for 3DS sensitive data in transit
pci-3ds-core-security-standard::P2-5.2.2P2-5.2.2 No fallback to insecure protocols
pci-3ds-core-security-standard::P2-5.3.1P2-5.3.1 TLS between 3DS components uses only allowed cipher suites
pci-3ds-core-security-standard::P2-5.3.2P2-5.3.2 No EMVCo-unsupported cipher suites offered
pci-3ds-core-security-standard::P2-5.3.3P2-5.3.3 No rollback to unapproved algorithms or key sizes
pci-3ds-core-security-standard::P2-5.3.4P2-5.3.4 TLS configurations monitored for change
pci-3ds-core-security-standard::P2-5.4.1P2-5.4.1 Stored 3DS sensitive data limited to permitted elements
pci-3ds-core-security-standard::P2-5.4.2P2-5.4.2 Strong cryptography for stored 3DS sensitive data
pci-3ds-core-security-standard::P2-5.5.1P2-5.5.1 3DS transactions monitored for anomalies
pci-3ds-core-security-standard::P2-5.5.2P2-5.5.2 Anomalous transaction activity investigated promptly

Part 2 Requirement P2-6: Cryptography and key management – PCI 3DS Core Security Standard

17 controls
Controls in the Part 2 Requirement P2-6: Cryptography and key management – PCI 3DS Core Security Standard domain of PCI 3DS Core Security Standard — 17 controls
CodeTitle
pci-3ds-core-security-standard::P2-6.1.1P2-6.1.1 Cryptography and key-management policies and procedures
pci-3ds-core-security-standard::P2-6.1.10P2-6.1.10 Incident response covers key-related issues
pci-3ds-core-security-standard::P2-6.1.2P2-6.1.2 HSM for specified keys at ACS and DS
pci-3ds-core-security-standard::P2-6.1.3P2-6.1.3 HSM deployed according to its security policy
pci-3ds-core-security-standard::P2-6.1.4P2-6.1.4 Documented cryptographic architecture
pci-3ds-core-security-standard::P2-6.1.5P2-6.1.5 Keys managed securely through their whole lifecycle
pci-3ds-core-security-standard::P2-6.1.6P2-6.1.6 Key management follows recognised standards
pci-3ds-core-security-standard::P2-6.1.7P2-6.1.7 Keys used only for their intended purpose
pci-3ds-core-security-standard::P2-6.1.8P2-6.1.8 Trusted CA for all 3DS certificates
pci-3ds-core-security-standard::P2-6.1.9P2-6.1.9 Audit logs for key-management and clear-text component activity
pci-3ds-core-security-standard::P2-6.2.1P2-6.2.1 Logical HSM access at the console or through an evaluated solution
pci-3ds-core-security-standard::P2-6.2.2P2-6.2.2 Non-console HSM access originates only from the 3DE
pci-3ds-core-security-standard::P2-6.2.3P2-6.2.3 Devices used for non-console HSM access secured
pci-3ds-core-security-standard::P2-6.2.4P2-6.2.4 No clear-text key loading or export over non-console links
pci-3ds-core-security-standard::P2-6.2.5P2-6.2.5 Non-console activity meets all other HSM and key rules
pci-3ds-core-security-standard::P2-6.3.1P2-6.3.1 HSMs kept in dedicated areas
pci-3ds-core-security-standard::P2-6.3.2P2-6.3.2 Physical HSM access restricted and under dual control

Part 2 Requirement P2-7: Physically secure 3DS systems – PCI 3DS Core Security Standard

9 controls
Controls in the Part 2 Requirement P2-7: Physically secure 3DS systems – PCI 3DS Core Security Standard domain of PCI 3DS Core Security Standard — 9 controls
CodeTitle
pci-3ds-core-security-standard::P2-7.1.1P2-7.1.1 ACS and DS hosted in data centres
pci-3ds-core-security-standard::P2-7.1.2P2-7.1.2 Single-entry portal with positive authentication
pci-3ds-core-security-standard::P2-7.1.3P2-7.1.3 Electronic access control on internal doors to 3DS areas
pci-3ds-core-security-standard::P2-7.1.4P2-7.1.4 Multi-factor entry to telecom rooms outside the data centre
pci-3ds-core-security-standard::P2-7.1.5P2-7.1.5 Anti-piggybacking entry controls
pci-3ds-core-security-standard::P2-7.1.6P2-7.1.6 Intrusion detection linked to the alarm system
pci-3ds-core-security-standard::P2-7.1.7P2-7.1.7 Physical connection points into the 3DE controlled at all times
pci-3ds-core-security-standard::P2-7.2.1P2-7.2.1 CCTV at every entrance and emergency exit
pci-3ds-core-security-standard::P2-7.2.2P2-7.2.2 CCTV recordings time-stamped

Your Compliance Coverage

If you comply with PCI 3DS Core Security Standard, you already cover:

Maps to 4 other frameworks

143 total controls
PCI DSS 4.0
117 source controls mapped|103 target controls covered
82%
ISO 27002:2022
31 source controls mapped|27 target controls covered
22%
PCI PIN Security
10 source controls mapped|9 target controls covered
7%
EMV 3-D Secure (3DS) - Payment Authentication Protocol
6 source controls mapped|4 target controls covered
4%

Coverage is not the same as your position

This page shows what PCI 3DS Core Security Standard overlaps with in general. Where your organisation actually stands, against the standard you are going for and the certifications you already hold, is a different question. Same graph and the same recorded refutations, scoped to you rather than to a pair.

The Compliance Position Diagnostic, $5,000 fixed, ten business days

What is PCI 3DS Core Security Standard and who does it apply to?

PCI 3DS Core Security Standard is a compliance framework from Global (PCI Security Standards Council; applied through the payment brands' compliance programmes, e.g. listed in the Visa Core Rules of 18 April 2026 for all regions) with 14 domains and 143 controls. The PCI Security Standards Council's standard for the environments in which EMV 3-D Secure core components run: the Access Control Server (ACS), Directory Server (DS) and 3DS Server. Part 1 sets baseline security (policy, risk, awareness, screening, networks, secure development, configuration and change, malware and vulnerabilities, access, physical security, incident response and logging) and can be met by leveraging a recent PCI DSS assessment of the same environment; Part 2 sets 3DS-specific controls (scope, governance, third parties, ACS and DS boundaries, APIs and web configuration, availability, customer and remote access, 3DS data protection with TLS per EMVCo and storage per the PCI 3DS Data Matrix, transaction monitoring, key management with HSMs at the ACS and DS, and data-centre and CCTV controls). Version 1.0 of October 2017 is current, with Technical FAQs of September 2023 and Data Matrix v1.3 of September 2026. Built from the Council's ROC template, which restates every requirement. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

What does PCI 3DS Core Security Standard actually require?

PCI 3DS Core Security Standard has 143 controls organised across 14 domains. The largest domains are Part 1 Requirement P1-3: Develop and maintain secure systems – PCI 3DS Core Security Standard (17 controls), Part 2 Requirement P2-6: Cryptography and key management – PCI 3DS Core Security Standard (17 controls), Part 2 Requirement P2-3: Protect 3DS systems and applications – PCI 3DS Core Security Standard (14 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

If I already comply with another framework, how much of PCI 3DS Core Security Standard do I already cover?

PCI 3DS Core Security Standard maps to 4 other compliance frameworks. The top mapping partners are PCI DSS 4.0 (82% coverage), ISO 27002:2022 (22% coverage), PCI PIN Security (7% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I implement PCI 3DS Core Security Standard?

Start your PCI 3DS Core Security Standard compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about PCI 3DS Core Security Standard requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 143 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 727 frameworks.

Get Started Free →

Free forever — no credit card required