PCI 3DS
If you operate a 3DS Server, Directory Server or Access Control Server, the PCI 3DS Core Security Standard applies to you. The assessment runs from scoping through to your Report on Compliance.
0
0 +
0 +
What is PCI 3DS?
The PCI 3DS Core Security Standard sets the physical and logical security requirements for environments that perform 3-D Secure functions. It supports the EMVCo 3-D Secure protocol, which authenticates cardholders during online transactions, by defining the controls the systems running that protocol have to meet.
Who does PCI 3DS apply to?
The standard applies to entities performing one or more of the three core 3DS functions:
-
3DS Server (3DSS): Handles the initial routing of the authentication request.
-
3DS Directory Server (DS): Determines whether a cardholder is enrolled and routes to the right issuer.
-
3DS Access Control Server (ACS): Authenticates the cardholder on behalf of the card issuer.
Merchants take part in 3-D Secure transactions but are not in scope for the PCI 3DS Core Security Standard. Their obligations sit under PCI DSS. The 3DS protocol versions you must support are set by the individual payment brands.
PCI 3DS compliance in three steps
Scope Analysis Review
Your PCI 3DS scope determines which systems need controls and which do not. Getting that boundary right at the start keeps the program focused, with segmentation, outsourcing and other techniques used strategically to keep the scope as lean as possible.
Gap Analysis Review
A Gap Analysis Review maps your current 3DS environment against the PCI 3DS requirements, giving you an accurate view of where you stand before formal assessment work begins. Closing gaps at this stage keeps the assessment itself cleaner and more predictable.
Formal Assessment of Compliance
The formal assessment involves on-site interviews, system configuration sampling, and document reviews conducted by a qualified 3DS Assessor. It produces the Report on Compliance and Attestation of Compliance that the payment brands recognize as evidence of your PCI 3DS standing.
Speak to an expert
Assessment against the PCI 3DS Core Security Standard has to be carried out by a qualified 3DS Assessor, and the scoping conversation shapes everything that follows. Talk to an advisor about what your environment will need and when.
Dublin: +353 01 293 4027
London: +44 20 3397 3414
Sofia: +359 2 491 0110
Cape Town: +27 08 606 25673
Johannesburg: +27 08 606 25673
