PCI TSP
Your token data environment falls under two sets of requirements: PCI DSS and the additional TSP requirements layered on top. An assessment covers both.
0
0 +
0 +
What are the PCI TSP Security Requirements?
The Additional Security Requirements and Assessment Procedures for Token Service Providers (EMV Payment Tokens) set the security requirements for entities that generate and issue EMV payment tokens, as defined under the EMV Payment Tokenisation Specification Technical Framework.
The requirements build on PCI DSS rather than replacing it. Both apply to your token data environment, and the TSP requirements add cryptographic key management, physical security and logical access controls that go further than PCI DSS asks for.
Most of that work starts with scope. We help you identify which systems belong inside your TSP boundary and what your options are for keeping it contained.
Who do the PCI TSP requirements apply to?
The requirements apply to organizations registered with EMVCo as Token Service Providers that generate and issue EMV payment tokens. If you are EMVCo-registered, your compliance and validation requirements are set by the applicable payment brands rather than by the Council.
Assessment against the TSP requirements can only be performed by a QSA (P2PE) assessor who has completed TSP training, reflecting the cryptographic key management and physical security expertise the standard demands.
PCI TSP compliance in three steps
Scope analysis review
Identifying the people, processes and technologies that interact with EMV payment tokens, or that could affect their security, establishes the boundary before any further compliance work. Because PCI DSS and the TSP requirements both apply within that boundary, getting it right sets the shape of both assessments.
Preliminary gap analysis review
Ahead of committing to a formal assessment, comparing your current security environment against the TSP requirements gives you a clear picture of what needs addressing. The gap analysis defines a plan to close the distance, with the effort quantified before you commit.
Formal assessment of compliance
The formal assessment is an independent review of your EMV payment tokenization environment. Through testing and evidence evaluation, it determines whether your systems protect token data, maintain its integrity and meet the TSP requirements.
Speak to an expert
Two standards apply inside your token data environment, and one boundary determines the scope of both. Talk to an advisor about establishing it.
Dublin: +353 01 293 4027
London: +44 20 3397 3414
Sofia: +359 2 491 0110
Cape Town: +27 08 606 25673
Johannesburg: +27 08 606 25673
