MDR Services

Our Managed Detection and Response Services provide continuous monitoring from a team who’ll neutralise any breaches at speed...

Incident Response

Gain access to malware experts to quickly contain threats and reduce future exposure to attacks...

Gartner Recognised

Integrity360 has been recognised as a Gartner Representative Vendor.

Download our CyberFire MDR ebook

Many organisations are choosing CyberFire MDR to strengthen their defences. Discover how it can protect your business in our brochure.

The hidden human costs of a cyber attack

Cyber attacks often seem faceless, but hidden behind the headlines of financial loss and technical details there are very real human stories. 

The reality of ransomware in 2025: What you need to know

In 2025, we’re witnessing a shift in how ransomware operates, who it targets, and the consequences of falling victim.

Your guide to 2026: Trends and Predictions

Stay ahead of the latest cybersecurity industry developments, advancements and threats, and understand how you can best protect your organisation.

Cybersecurity testing services

Do you know what your company’s network vulnerabilities are? Businesses that invest in penetration testing do.

What is PCI? Your most common questions answered

If your business handles credit card data, PCI DSS compliance isn’t optional—it’s critical. From retailers and e-commerce platforms to service providers and financial institutions, securing credit card data is critical to customer trust and preventing fraud.

Weekly Threat roundups

Stay informed with the latest cybersecurity news with our weekly threat roundups.

The A-Z Glossary of cybersecurity terms

Confused about cybersecurity? Our A-Z Glossary of terms can help you navigate this complicated industry.

Read our latest blog

For many small and mid-sized businesses, cybersecurity can feel overwhelming.

Integrity360 completes SOC 2 certification to strengthen global cyber defence ecosystem

SOC 2 certification reflects Integrity360’s continued investment in strengthening cyber resilience for clients across highly regulated and high-risk industries. 

Integrity360 expands into North America with Advantus360 Acquisition

Leading Canadian cybersecurity services provider Advantus360 joins Integrity360 creating the group’s first hub in North America

Security First 2026

See the full list of our conferences across the UK, Europe, Africa & the Caribbean
Integrity360 Emergency Incident Response button Under Attack?

PCI 3DS

If you operate a 3DS Server, Directory Server or Access Control Server, the PCI 3DS Core Security Standard applies to you. The assessment runs from scoping through to your Report on Compliance.

0

SOCs in Ireland, Sweden, Bulgaria, Spain, Italy, South Africa & Canada (coming 2026)

0 +

security consultants, engineers and analysts

0 +

satisfied clients

What is PCI 3DS?

The PCI 3DS Core Security Standard sets the physical and logical security requirements for environments that perform 3-D Secure functions. It supports the EMVCo 3-D Secure protocol, which authenticates cardholders during online transactions, by defining the controls the systems running that protocol have to meet.

Who does PCI 3DS apply to?

The standard applies to entities performing one or more of the three core 3DS functions:

  • 3DS Server (3DSS): Handles the initial routing of the authentication request.

  • 3DS Directory Server (DS): Determines whether a cardholder is enrolled and routes to the right issuer.

  • 3DS Access Control Server (ACS): Authenticates the cardholder on behalf of the card issuer.

Merchants take part in 3-D Secure transactions but are not in scope for the PCI 3DS Core Security Standard. Their obligations sit under PCI DSS. The 3DS protocol versions you must support are set by the individual payment brands.

PCI 3DS compliance in three steps

Scope Analysis Review

Your PCI 3DS scope determines which systems need controls and which do not. Getting that boundary right at the start keeps the program focused, with segmentation, outsourcing and other techniques used strategically to keep the scope as lean as possible.

Gap Analysis Review

A Gap Analysis Review maps your current 3DS environment against the PCI 3DS requirements, giving you an accurate view of where you stand before formal assessment work begins. Closing gaps at this stage keeps the assessment itself cleaner and more predictable.

Formal Assessment of Compliance

The formal assessment involves on-site interviews, system configuration sampling, and document reviews conducted by a qualified 3DS Assessor. It produces the Report on Compliance and Attestation of Compliance that the payment brands recognize as evidence of your PCI 3DS standing.

Speak to an expert

Assessment against the PCI 3DS Core Security Standard has to be carried out by a qualified 3DS Assessor, and the scoping conversation shapes everything that follows. Talk to an advisor about what your environment will need and when.

The PCI family

PCI DSS

PCI P2PE

Swifts CSP Assessment

Swifts CSP Assessment

Our Certifications

  ENS Certification  

 

Access key insights

What is new in PCI DSS 4.0?

What is PCI DSS and Why Does It Matter?

How Managed Detection and Response can facilitate PCI DSS Compliance

Why Switching to Integrity360 Should Be Your Top Choice for PCI DSS Compliance This Data Privacy Week