PCI CPP
The security of every payment card starts in production. PCI CPP compliance is how your organization demonstrates that your environment is built to the right standard.
0
0 +
0 +
What is PCI Card Production and Provisioning?
PCI Card Production and Provisioning (CPP) sets the security requirements for organizations that manufacture, personalize, provision and fulfil payment cards and payment credentials. It covers the physical security of the facilities where that work happens and the logical security of the systems, data and cryptographic keys involved.
Compliance is assessed by Card Production Security Assessors qualified by the PCI Security Standards Council. As with the other PCI standards, whether your organization is required to validate is determined by the payment brands.
Who needs to comply with PCI CPP?
The requirements apply to organizations performing card production and provisioning activities, including:
-
Card manufacturers and personalizers
-
Chip embedders and pre-personalizers
-
Data preparation and fulfilment operations
-
PIN generation and printing
-
Cloud-based and secure element provisioning service providers
-
Organizations managing over-the-air personalization and the cryptographic key lifecycle
Physical and logical: two sets of requirements
-
Physical Security Requirements cover the facilities themselves: access control, secure areas, materials handling, storage, movement of card stock and the operational controls around production activity.
-
Logical Security Requirements cover the systems and processes: cryptographic key management, EMV data preparation, pre-personalization, magnetic stripe and IC personalization, PIN generation and printing, and fulfilment data.
The two are assessed separately by assessors qualified separately in each. Most organizations are in scope for both, and getting the boundary right between them is where the scoping work earns its keep.
PCI CPP compliance services
Scope Assessment Review (SAR)
Identifying which systems, facilities and business processes fall within scope for the physical and logical requirements is where the work starts. SAR establishes and validates that boundary, so remediation and assessment effort go where the requirements apply.
Gap Analysis Review (GAR)
Comparing your current environment against the physical and logical requirements surfaces what needs to change. You get a clear picture of where the gaps sit, what closing them involves, and which solutions will get you there.
Formal Assessment of Compliance (FAC)
Where your organization is required to demonstrate compliance, the FAC assesses and reports on the security of your environment against the applicable requirements. Knowledge is transferred to your team throughout, so maintaining compliance between assessments sits with people who understand why each control is there.
Trusted Advisor Service (TAS)
Running alongside the above, TAS gives you a dedicated point of contact through planning, implementation and maintenance, with direct access to solution experts for questions on evolving controls and developments in the standard.
Speak to an expert
Card production environments differ enormously in what falls inside the boundary, and that boundary determines the cost of everything that follows. Talk to an advisor about scoping yours.
Dublin: +353 01 293 4027
London: +44 20 3397 3414
Sofia: +359 2 491 0110
Cape Town: +27 08 606 25673
Johannesburg: +27 08 606 25673
