MDR Services

Our Managed Detection and Response Services provide continuous monitoring from a team who’ll neutralise any breaches at speed...

Incident Response

Gain access to malware experts to quickly contain threats and reduce future exposure to attacks...

Gartner Recognised

Integrity360 has been recognised as a Gartner Representative Vendor.

Download our CyberFire MDR ebook

Many organisations are choosing CyberFire MDR to strengthen their defences. Discover how it can protect your business in our brochure.

The hidden human costs of a cyber attack

Cyber attacks often seem faceless, but hidden behind the headlines of financial loss and technical details there are very real human stories. 

The reality of ransomware in 2025: What you need to know

In 2025, we’re witnessing a shift in how ransomware operates, who it targets, and the consequences of falling victim.

Your guide to 2026: Trends and Predictions

Stay ahead of the latest cybersecurity industry developments, advancements and threats, and understand how you can best protect your organisation.

Cybersecurity testing services

Do you know what your company’s network vulnerabilities are? Businesses that invest in penetration testing do.

What is PCI? Your most common questions answered

If your business handles credit card data, PCI DSS compliance isn’t optional—it’s critical. From retailers and e-commerce platforms to service providers and financial institutions, securing credit card data is critical to customer trust and preventing fraud.

Weekly Threat roundups

Stay informed with the latest cybersecurity news with our weekly threat roundups.

The A-Z Glossary of cybersecurity terms

Confused about cybersecurity? Our A-Z Glossary of terms can help you navigate this complicated industry.

Read our latest blog

For many small and mid-sized businesses, cybersecurity can feel overwhelming.

Integrity360 completes SOC 2 certification to strengthen global cyber defence ecosystem

SOC 2 certification reflects Integrity360’s continued investment in strengthening cyber resilience for clients across highly regulated and high-risk industries. 

Integrity360 expands into North America with Advantus360 Acquisition

Leading Canadian cybersecurity services provider Advantus360 joins Integrity360 creating the group’s first hub in North America

Security First 2026

See the full list of our conferences across the UK, Europe, Africa & the Caribbean
Integrity360 Emergency Incident Response button Under Attack?

PCI TSP

Your token data environment falls under two sets of requirements: PCI DSS and the additional TSP requirements layered on top. An assessment covers both.

0  

SOCs in Ireland, Sweden, Bulgaria, Spain, Italy, South Africa & Canada (coming 2026)

0 +

security consultants, engineers and analysts

0 +

satisfied clients

What are the PCI TSP Security Requirements?

The Additional Security Requirements and Assessment Procedures for Token Service Providers (EMV Payment Tokens) set the security requirements for entities that generate and issue EMV payment tokens, as defined under the EMV Payment Tokenisation Specification Technical Framework.

The requirements build on PCI DSS rather than replacing it. Both apply to your token data environment, and the TSP requirements add cryptographic key management, physical security and logical access controls that go further than PCI DSS asks for.

Most of that work starts with scope. We help you identify which systems belong inside your TSP boundary and what your options are for keeping it contained.

Who do the PCI TSP requirements apply to?

The requirements apply to organizations registered with EMVCo as Token Service Providers that generate and issue EMV payment tokens. If you are EMVCo-registered, your compliance and validation requirements are set by the applicable payment brands rather than by the Council.

Assessment against the TSP requirements can only be performed by a QSA (P2PE) assessor who has completed TSP training, reflecting the cryptographic key management and physical security expertise the standard demands.

PCI TSP compliance in three steps

Scope analysis review

Identifying the people, processes and technologies that interact with EMV payment tokens, or that could affect their security, establishes the boundary before any further compliance work. Because PCI DSS and the TSP requirements both apply within that boundary, getting it right sets the shape of both assessments.

Preliminary gap analysis review

Ahead of committing to a formal assessment, comparing your current security environment against the TSP requirements gives you a clear picture of what needs addressing. The gap analysis defines a plan to close the distance, with the effort quantified before you commit.

Formal assessment of compliance

The formal assessment is an independent review of your EMV payment tokenization environment. Through testing and evidence evaluation, it determines whether your systems protect token data, maintain its integrity and meet the TSP requirements.

Speak to an expert

Two standards apply inside your token data environment, and one boundary determines the scope of both. Talk to an advisor about establishing it.

PCI 3DS

PCI SSF/PA DS

PCI SSF/PA DS

PCI DSS

PCI P2PE

PCI CPP

Swift CSP Assessment

Swift CSP Assessment

PCI ASV

PCI PIN

Our Certifications

  distintivo_ens_certificacion_ALTA_RD311-2022  

 

Access key insights

What is new in PCI DSS 4.0?

What is PCI DSS and Why Does It Matter?

How Managed Detection and Response can facilitate PCI DSS Compliance

Why Switching to Integrity360 Should Be Your Top Choice for PCI DSS Compliance This Data Privacy Week