PCI DSS
CompliancePayment Card Industry Data Security Standard -- a set of security requirements for organizations that store, process, or transmit payment card data, governing systems that interact with smart card transactions.
What Is PCI DSS?
PCI DSSPCI DSSComplianceSecurity standard for payment card data environments.Click to view → (Payment Card Industry Data Security Standard) is a comprehensive set of security requirements for any organization that stores, processes, or transmits payment card data. Maintained by the PCI Security Standards Council (founded by Visa, Mastercard, American Express, Discover, and JCB), PCI DSS governs the security posture of the entire ecosystem surrounding smart card payment transactions -- from the EMV terminal at point-of- sale through the acquiring bank's processing infrastructure.
While PCI DSS does not directly specify smart card chip requirements (that is EMVCo's domain), it defines the security controls for every system that touches the cardholder data after it leaves the card.
Scope Relevant to Smart Cards
PCI DSS applies to systems that interact with smart card transaction data:
| System | PCI DSS Relevance |
|---|---|
| POS terminals | Card reader, PIN pad, terminal software |
| Payment gateway | Transaction routing, tokenization |
| Card personalization bureauCard personalization bureauManufacturingCertified facility for large-scale smart card personalization.Click to view → | Cardholder data handling during electrical personalization |
| HSM infrastructure | Key management for PIN translation, card verification |
| Card issuance platform | PAN, CVV generation, PIN mailing |
Key Requirements
PCI DSS v4.0 (current) defines 12 requirement categories:
- Install and maintain network security controls
- Apply secure configurations to all system components
- Protect stored account data (encryption, key management)
- Protect cardholder data with strong cryptography during transmission
- Protect all systems against malware
- Develop and maintain secure systems and software
- Restrict access by business need-to-know
- Identify users and authenticate access
- Restrict physical access to cardholder data
- Log and monitor all access to network resources and cardholder data
- Test security of systems and networks regularly
- Support information security with organizational policies
Relationship to Smart Card Standards
PCI DSS works alongside other smart card industry standards:
- PCI PTS -- security requirements for the physical terminals and PIN entry devices that read smart cards.
- EMVCo Type Approval -- certification of the smart card chip and payment application themselves.
- PCI PIN Security -- requirements for PIN processing, including HSM key management and PIN block encryption.
- PCI P2PE -- point-to-point encryption from the card reader to the acquirer, reducing the merchant's PCI DSS scope.
Impact on Card Personalization
Card personalization bureaus must maintain PCI DSS compliance because they handle PANs, CVVs, and cryptographic keys during the pre-personalization and personalization phases. This requires physical security zones, dual-control procedures, and auditable key management using certified HSMs.
Related Content
PCI PTS for Smart Card Terminals
Compliance…timelines for older hardware. Relationship to EMV and PCI DSS PTS approval certifies the device ; it does not replace…
Card Personalization Systems
Developer Tools…certifications for personalisation bureaux: Standard Scope PCI DSS Cardholder data environment PCI Card Production (PCI CP)…
Perguntas frequentes
The smart card glossary is a comprehensive reference of technical terms, acronyms, and concepts used in smart card technology. It covers protocols (APDU, T=0, T=1), security (Common Criteria, EAL, HSM), hardware (SE, EEPROM, contact pad), and applications (EMV, ePassport, eSIM). It serves developers, product managers, and engineers.
Yes. SmartCardFYI provides glossary definitions in 15 languages including English, Korean, Japanese, Chinese, Spanish, Portuguese, Hindi, Arabic, French, Russian, German, Turkish, Vietnamese, Indonesian, and Thai.