PCI PIN is the standard for how a cardholder PIN, and every cryptographic key that protects it, is generated, moved, loaded, used, administered and destroyed. It applies to acquirers and their agents rather than to every merchant, and this PIN security documentation set is written for the assessment a Qualified PIN Assessor actually runs.
On this page:
- There is no PCI PIN deadline, and four things most PIN material gets wrong
- What is inside the PIN security documentation pack
- The documents paraphrase the standard, and here is what you get instead
- Who the PIN security documentation pack is written for
- What the PIN security documentation pack does not do
- Frequently asked questions
- Related toolkits
There is no PCI PIN deadline, and four things most PIN material gets wrong
PCI SSC does not set an effective date. The standard says in as many words that the individual payment brands do. Anyone selling a pack against a single industry-wide date is selling something that does not exist – contact the brands you work with. What the standard does set is a phase-in for particular requirements, and every one of those dates has now passed, so there is no remaining grace period on anything.
Four claims circulate widely and all four are wrong. That all POS devices and ATMs had to convert to key blocks by January 2025: no, deployments existing before that date are not required to convert, though they may. That clear-text key injection is banned: only for the more recent POI device generations, and injection into earlier generations remains acceptable past both the 2024 and 2026 dates until a brand mandates those devices out of service. That fixed key is no longer allowed: the prohibition is on fixed key with TDEA, and fixed key with AES is unaffected. That ISO Format 4 PIN blocks must be supported by a given date: those sunrise dates were suspended in v3.1 and PCI SSC is re-evaluating them.
Each of those limits is sourced from the standard itself or from PCI SSC technical FAQs, and each is stated in this PIN security documentation where it matters rather than in a footnote. Scoping a programme against a rumour is expensive in both directions.
What is inside the PIN security documentation pack
149 editable templates covering all 145 sub-requirements across the four scope columns, with both normative annexes covered in full. Scope is decided by what you do, not by how much of it you do, and the pack is organised that way.
- Control objectives 1 to 7 – one section per objective, following the structure a Qualified PIN Assessor works through.
- Key management procedures – generation, conveyance, loading, usage, administration, storage and destruction, each as a separate procedure rather than one long policy.
- Key custodian documents – appointment, acknowledgement, dual control and split knowledge records, and the custodian change process.
- HSM and device management – configuration standards, inspection records, chain of custody and decommissioning.
- Annex A – symmetric key distribution using asymmetric techniques, covered in full.
- Annex B – key-injection facility requirements, covered in full, including the platform restrictions and their dates.
- Scope determination – the documents that decide which of the four columns apply to you before anything else is written.
- Evidence registers – sub-requirement coverage, key inventory, custodian register, device inventory and inspection log.
- Assessment preparation – the pack an assessor asks for, assembled rather than hunted for.

The documents paraphrase the standard, and here is what you get instead
PCI SSC requirement wording is copyright, so this PIN security documentation paraphrases it rather than reprinting it. That is a real constraint and it is stated openly rather than worked around.
What you get in exchange is a coverage claim that can be checked. Every document carries a Requirements-addressed table naming the sub-requirements it answers in the citation form a reader searching the standard will use, and the coverage register lists all 145 sub-requirements against the document that answers each. A gap shows as a blank cell. You can hold the standard open beside the pack and verify the claim in an afternoon, which is not true of a pack that simply asserts full coverage.
This is a two-year assessment cycle rather than an annual one, and the pack is built for that rhythm – the evidence that has to be kept continuously is marked separately from the evidence assembled for the assessment itself.
Who the PIN security documentation pack is written for
- Acquirers, and the processors and agents that act for them.
- Key injection facilities and certificate processors.
- Organisations preparing for a Qualified PIN Assessor onsite assessment, or for a TR-39 review.
- Payment service providers whose brand agreements require PIN compliance evidence.
What the PIN security documentation pack does not do
It is not an assessment and it does not produce a compliance status. Only a Qualified PIN Assessor can do that.
It does not reprint the standard. You need your own copy from PCI SSC to verify the mappings, and it is free to download.
It is not PCI DSS. Different standard, different scope, different assessor qualification. If you need cardholder data environment documentation, that is the PCI DSS pack.
Frequently asked questions
When is our PCI PIN deadline?
PCI SSC does not set one; the payment brands do. Ask the brands you work with. What the standard sets is a phase-in for specific requirements, and all of those dates have passed.
Does it cover both annexes?
Yes, Annex A and Annex B in full, including the key injection facility requirements and the platform restrictions with their effective dates.
Is this the same as PCI DSS?
No. PCI DSS covers the cardholder data environment and is assessed by a QSA. PCI PIN covers PIN and key management and is assessed by a QPA.
What formats are the files in?
Native Microsoft Word and Excel, fully editable, with organisation-specific values marked as placeholders.
Related toolkits
Most acquirers run this beside the PCI DSS toolkit, and add the ISO 27001 toolkit where a certificate is required contractually. Banks in the SWIFT network also use the SWIFT CSP toolkit. The standard is published free by PCI SSC.
Implementing for clients? The Consultant Package licenses all 86 toolkits and assessment tools on this site for unlimited client engagements, under one firm-wide licence. One payment of $1,399, no subscription and no per-client fee.
Delivery, format and licence
The PIN security documentation pack downloads immediately after checkout as native Microsoft Word and Excel files. Nothing is locked, nothing is a PDF you cannot edit, and no add-on or portal login is needed to open it. Every organisation-specific value is marked as a placeholder so you can see what still has to be decided.
One payment, no subscription and no annual renewal. The source files behind the PIN security documentation pack are yours to adapt for your own organisation for as long as you need them, including future revisions of your own documents.




Reviews
There are no reviews yet.