Advisory

PCI PIN Security Assessments

Independent PCI PIN assessments for organisations that process PIN transactions or manage the keys that protect them.

Protect the PIN and the keys behind it.

The PCI PIN Security Standard sets the requirements for the secure management, processing and transmission of PINs and their associated cryptographic keys. It applies to acquiring institutions and to the agents responsible for processing PIN transactions on their behalf, at ATMs and at attended and unattended point-of-sale terminals. Vectra runs PCI PIN assessments. We help you define the scope, prepare your evidence and close gaps before the formal assessment begins, then assess your key management, PIN processing and secure devices against the requirements and report what we find. Your acquirer or the payment brands decide when and how you must validate, so we plan the engagement around their requirements.

PCI PIN Security Assessments

What the PIN Security Standard asks you to prove.

The standard covers the full life of each cryptographic key, the way PINs are protected from the terminal to the host, and the secure devices that do the work.

The requirements are detailed and technical. A good assessment starts with a clear view of where keys and PINs actually go.

  • Key management

    How keys are created, loaded, shared, stored, used, changed and destroyed, and who can reach them.

  • PIN processing

    How PINs are encrypted at entry and stay protected until they reach the host.

  • Secure devices

    How terminals and other secure devices that handle PINs and keys are approved, tracked and kept safe.

  • Key loading

    How keys are placed into terminals and other devices, including at key-injection facilities.

PIN security inside one PCI practice.

PCI work since 2006

Vectra became Australia's first certified QSA Company in 2006. Our PIN assessments sit inside the same PCI practice.

Across the PCI standards

We run assessments for PCI DSS, PCI PIN, PCI P2PE and the Software Security Framework, so we can identify where your controls overlap and plan the work together.

Testing in the same team

Our penetration testing team can test the networks and systems surrounding your PIN environment, so technical findings come from the same practice.

From scope to Attestation of Compliance.

Each step is based on evidence of the controls operating today, not controls that are only planned.

  1. Step 1: Scope

    Map where PINs and keys are handled: terminals, host systems, secure cryptographic devices, facilities, third parties and the people with key management responsibilities.

  2. Step 2: Readiness review

    Check your key inventories, procedures and device controls against the requirements, and prioritise the gaps by risk.

  3. Step 3: Fix the gaps

    Help your team rewrite procedures, tighten key duties and gather the evidence the assessment will need.

  4. Step 4: Assess

    Review documentation and records, interview key custodians, inspect secure rooms and devices, and observe key handling where required.

  5. Step 5: Report

    Prepare the assessment report and Attestation of Compliance, with clear findings for your acquirer or payment brand.

  6. Step 6: Keep it current

    Review new keys, devices, facilities and service providers as your environment changes, so the next assessment brings no surprises.

PIN security work we run.

PIN gap assessment

A review of your current state against the PIN Security Requirements, with a ranked plan to close the gaps.

Formal PCI PIN assessment

An independent assessment of your PIN environment, reported in the format your acquirer or payment brand asks for.

Key management review

A close look at how keys are created, split, stored, loaded, changed and destroyed, and who holds each part.

Key ceremony review

We review ceremony scripts, logs and dual-control records, and can observe a ceremony to confirm it runs as written.

Device and site controls

We check how secure devices are approved, tracked and protected, and how secure rooms control access.

Policy and procedure uplift

We help you write procedures that match the requirements and that your key custodians can follow.

What you have at the end.

  • A clear scope for your PIN environment, agreed before the assessment starts.

  • Key management procedures that match the requirements and how your team works.

  • An assessment report and Attestation of Compliance for your acquirer or payment brand.

  • A ranked list of any gaps, with owners and next steps.

PCI PIN questions.

Who needs a PCI PIN assessment?

The standard applies to acquiring institutions and their agents responsible for processing PIN transactions, which can include processors, ATM and terminal providers, and key-injection facilities. Your acquirer or the payment brands determine whether you must validate compliance.

How is PCI PIN different from PCI DSS?

PCI DSS protects account data wherever it is stored, processed or transmitted, while PCI PIN focuses on PINs and the cryptographic keys that protect them. Many organisations need both, and we can plan the two assessments together.

How often do we need to be assessed?

The payment brands and acquirers determine how often you validate. We confirm the requirements that apply to your organisation during scoping.

Does PCI SSC list PIN service providers?

Yes. PCI SSC introduced a voluntary listing for PIN service providers in 2025. A provider needs a validated PIN Attestation of Compliance to apply.

Can you help before a formal assessment?

Yes. Most engagements begin with a gap assessment, which identifies what to fix first and which evidence to gather.

Start with a conversation.

Speak to us about your cyber governance and compliance requirements.