PCI work since 2006
Vectra became Australia's first certified QSA Company in 2006. Our PIN assessments sit inside the same PCI practice.
Independent PCI PIN assessments for organisations that process PIN transactions or manage the keys that protect them.
The PCI PIN Security Standard sets the requirements for the secure management, processing and transmission of PINs and their associated cryptographic keys. It applies to acquiring institutions and to the agents responsible for processing PIN transactions on their behalf, at ATMs and at attended and unattended point-of-sale terminals. Vectra runs PCI PIN assessments. We help you define the scope, prepare your evidence and close gaps before the formal assessment begins, then assess your key management, PIN processing and secure devices against the requirements and report what we find. Your acquirer or the payment brands decide when and how you must validate, so we plan the engagement around their requirements.
The standard covers the full life of each cryptographic key, the way PINs are protected from the terminal to the host, and the secure devices that do the work.
The requirements are detailed and technical. A good assessment starts with a clear view of where keys and PINs actually go.
How keys are created, loaded, shared, stored, used, changed and destroyed, and who can reach them.
How PINs are encrypted at entry and stay protected until they reach the host.
How terminals and other secure devices that handle PINs and keys are approved, tracked and kept safe.
How keys are placed into terminals and other devices, including at key-injection facilities.
Vectra became Australia's first certified QSA Company in 2006. Our PIN assessments sit inside the same PCI practice.
We run assessments for PCI DSS, PCI PIN, PCI P2PE and the Software Security Framework, so we can identify where your controls overlap and plan the work together.
Our penetration testing team can test the networks and systems surrounding your PIN environment, so technical findings come from the same practice.
Each step is based on evidence of the controls operating today, not controls that are only planned.
Map where PINs and keys are handled: terminals, host systems, secure cryptographic devices, facilities, third parties and the people with key management responsibilities.
Check your key inventories, procedures and device controls against the requirements, and prioritise the gaps by risk.
Help your team rewrite procedures, tighten key duties and gather the evidence the assessment will need.
Review documentation and records, interview key custodians, inspect secure rooms and devices, and observe key handling where required.
Prepare the assessment report and Attestation of Compliance, with clear findings for your acquirer or payment brand.
Review new keys, devices, facilities and service providers as your environment changes, so the next assessment brings no surprises.
A review of your current state against the PIN Security Requirements, with a ranked plan to close the gaps.
An independent assessment of your PIN environment, reported in the format your acquirer or payment brand asks for.
A close look at how keys are created, split, stored, loaded, changed and destroyed, and who holds each part.
We review ceremony scripts, logs and dual-control records, and can observe a ceremony to confirm it runs as written.
We check how secure devices are approved, tracked and protected, and how secure rooms control access.
We help you write procedures that match the requirements and that your key custodians can follow.
A clear scope for your PIN environment, agreed before the assessment starts.
Key management procedures that match the requirements and how your team works.
An assessment report and Attestation of Compliance for your acquirer or payment brand.
A ranked list of any gaps, with owners and next steps.
The standard applies to acquiring institutions and their agents responsible for processing PIN transactions, which can include processors, ATM and terminal providers, and key-injection facilities. Your acquirer or the payment brands determine whether you must validate compliance.
PCI DSS protects account data wherever it is stored, processed or transmitted, while PCI PIN focuses on PINs and the cryptographic keys that protect them. Many organisations need both, and we can plan the two assessments together.
The payment brands and acquirers determine how often you validate. We confirm the requirements that apply to your organisation during scoping.
Yes. PCI SSC introduced a voluntary listing for PIN service providers in 2025. A provider needs a validated PIN Attestation of Compliance to apply.
Yes. Most engagements begin with a gap assessment, which identifies what to fix first and which evidence to gather.
Speak to us about your cyber governance and compliance requirements.