PCI PIN Security
PCI PIN Transaction Security for payment terminals
PCI PIN Security is a compliance framework from International with 14 domains and 43 controls that map to 193 other frameworks. The largest domains are Key Management (11 controls), PCI PIN Security: Cybersecurity Controls (5 controls), PCI PIN Security: Incident Management & Reporting (5 controls). Every control below carries what it requires and what an assessor expects to see.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (14)
Access Control
| Code | Title |
|---|---|
| CO-17 | Access to Secret and Private Cryptographic Keys and Key Material Is Restricted |
Device Approval
Equipment Management
| Code | Title |
|---|---|
| CO-10 | Equipment Used to Process PINs and Keys Is Managed in a Secure Manner |
Key Distribution
| Code | Title |
|---|---|
| CO-Annex-A | Symmetric Key Distribution Using Asymmetric Techniques |
Key Injection
| Code | Title |
|---|---|
| CO-Annex-B | Key-Injection Facility Requirements |
Key Management
| Code | Title |
|---|---|
| CO-11 | Secret and Private Keys and Key Components Are Generated, Conveyed, and Used in a Manner That Prevents or Detects Their Unauthorized Disclosure, Modification, or Substitution |
| CO-12 | Keys Are Used in a Manner That Prevents or Detects Their Unauthorized Usage |
| CO-13 | Keys Are Administered Throughout Their Lifecycle in a Secure Manner |
| CO-14 | Materials Used to Generate or Transport Keys Are Treated With the Same Security as the Keys They Protect |
| CO-15 | Cryptographic Keys Are Replaced With New Keys When Knowledge of Or Access to a Key Is No Longer Required |
| CO-16 | Keys No Longer Used or Replaced Are Securely Destroyed |
| CO-5 | Cryptographic Keys Are Generated Using Approved Methods |
| CO-6 | Cryptographic Keys Are Conveyed or Transmitted Securely |
| CO-7 | Key Loading Is Handled in a Secure Manner |
| CO-8 | Keys Are Used Only for Their Designated Purpose |
| CO-9 | Keys Are Administered in a Secure Manner |
Logging and Monitoring
| Code | Title |
|---|---|
| CO-18 | Logging Is in Place to Enable Audit and Investigation of Key Management Activities |
PCI PIN Security: Cybersecurity Controls
Technical cybersecurity measures (PCI PIN Security)
| Code | Title |
|---|---|
| PCI-PIN-06 | Network security and segmentation |
| PCI-PIN-07 | Endpoint protection and detection |
| PCI-PIN-08 | Application security controls |
| PCI-PIN-09 | Encryption and key management |
| PCI-PIN-10 | Secure configuration standards |
PCI PIN Security: Incident Management & Reporting
Incident handling for financial services (PCI PIN Security)
| Code | Title |
|---|---|
| PCI-PIN-21 | Incident detection and classification |
| PCI-PIN-22 | Incident response and containment |
| PCI-PIN-23 | Regulatory reporting requirements |
| PCI-PIN-24 | Customer notification procedures |
| PCI-PIN-25 | Post-incident review and improvement |
PCI PIN Security: Information Security Governance
IT governance for financial institutions (PCI PIN Security)
| Code | Title |
|---|---|
| PCI-PIN-04 | Security policy framework |
| PCI-PIN-05 | Roles and responsibilities definition |
PCI PIN Security: Operational Resilience
Business continuity and resilience (PCI PIN Security)
| Code | Title |
|---|---|
| PCI-PIN-11 | Business continuity planning and testing |
| PCI-PIN-12 | Disaster recovery procedures |
| PCI-PIN-13 | Third-party dependency management |
| PCI-PIN-14 | Critical service identification |
| PCI-PIN-15 | Communication and escalation procedures |
PCI PIN Security: Third-Party Risk Management
Managing vendor and supplier risks (PCI PIN Security)
| Code | Title |
|---|---|
| PCI-PIN-16 | Due diligence and onboarding |
| PCI-PIN-17 | Contractual security requirements |
| PCI-PIN-18 | Ongoing monitoring and assessment |
| PCI-PIN-19 | Concentration risk management |
| PCI-PIN-20 | Exit strategy and transition planning |
Physical Security
Risk Management
| Code | Title |
|---|---|
| CO-19 | Organizations Implement and Document Risk-Mitigation Practices |
Your Compliance Coverage
If you comply with PCI PIN Security, you already cover:
PSD2 SCA
40%
17 controls mapped
Compare →PCI P2PE
40%
17 controls mapped
Compare →FFIEC IT Examination Handbook
40%
17 controls mapped
Compare →+ 190 more: PCI SSF (40%), Singapore Government Instruction Manual on ICT&SS Management (IM8) (35%)
See all 193 mapped frameworks ↓Maps to 193 other frameworks
What is PCI PIN Security and who does it apply to?
PCI PIN Security is a compliance framework from International with 14 domains and 43 controls. PCI PIN Transaction Security for payment terminals It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
What does PCI PIN Security actually require?
PCI PIN Security has 43 controls organised across 14 domains. The largest domains are Key Management (11 controls), PCI PIN Security: Cybersecurity Controls (5 controls), PCI PIN Security: Incident Management & Reporting (5 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
If I already comply with another framework, how much of PCI PIN Security do I already cover?
PCI PIN Security maps to 193 other compliance frameworks. The top mapping partners are PSD2 SCA (40% coverage), PCI P2PE (40% coverage), FFIEC IT Examination Handbook (40% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I implement PCI PIN Security?
Start your PCI PIN Security compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about PCI PIN Security requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 43 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 686 frameworks.
Get Started Free →Free forever — no credit card required