Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

Qualified PIN Assessor — Qualified PIN Assessor: What a PCI PIN Assessment Involves

Qualified PIN Assessor: What a PCI PIN Assessment Involves

Qualified PIN Assessor is the qualification held by the people who assess compliance with PCI PIN Security, and it is a separate scheme from the QSA qualification used for PCI DSS. If you are preparing for your first PIN assessment on the assumption that your existing QSA relationship covers it, it does not.

This guide sets out what a Qualified PIN Assessor does on site, how the engagement differs from a DSS assessment, what gets sampled, and how the listing cycle actually works — which is the part organisations most often plan wrongly.

What this guide covers

Qualified PIN Assessor explained
A PCI PIN listing expires two years after the assessor signs the attestation — not two years from submission.

What a Qualified PIN Assessor is

A Qualified PIN Assessor is qualified and trained by PCI SSC to perform independent assessments of environments where PINs are processed, against the PIN Security Requirements and in accordance with the QPA Program Guide. The assessment is performed by a QPA employed by a QPA Company, and it produces a Report on Compliance and an Attestation of Compliance.

The entity being assessed is referred to throughout as a PIN Service Provider. That term appears on the attestation and in the programme documents, and it covers acquirers and their agents rather than merchants.

There is no self-assessment route

This is the single most important structural difference, and it catches people arriving from PCI DSS. There is no PIN equivalent of an SAQ. Validation is an onsite assessment by a Qualified PIN Assessor, for every entity, regardless of size or volume.

Checklists sold as “PIN self-assessments” are internal readiness tools. They are genuinely useful — running one before an assessor arrives is how you find your own gaps first — but they are not submissions, and treating one as a submission wastes a cycle.

How a Qualified PIN Assessor tests

The testing procedures a Qualified PIN Assessor works from sit beside each requirement in the standard, and they lean far more heavily on observation than a DSS assessment does. Expect a Qualified PIN Assessor to want:

Activity What they are testing
Scope confirmation Which activities you perform, and therefore which requirement columns apply
Documentation review That procedures exist, are current, and are approved
Interviews Custodians, supervisors, operators, technical management — awareness is itself a requirement
Observation of a live operation A key ceremony or loading session, performed the way it is normally performed
Physical inspection Storage containers, secure rooms, device samples, facilities
Records sampling Ceremony records, loading logs, custody trails, destruction certificates
Device sampling Physical devices against the inventory and the approval listings

The observation is the hard part

A Qualified PIN Assessor will want to watch a real operation. That means one has to be scheduled during the assessment window, both custodians have to be available, and the records have to be completed at the time, in front of them.

Rehearsing it is counterproductive. A session performed unusually smoothly, with paperwork that does not match the pattern of the rest of the year’s records, invites exactly the scrutiny you were hoping to avoid. The better preparation is to make the ordinary sessions correct months earlier.

Sampling reinforces that. Assessors sample across the whole period rather than only recent records, because recent records are usually the best ones. A procedure that produced no records in the first half of the year is a procedure that started when someone booked the assessment.

The two-year cycle

PCI PIN does not run on the annual rhythm most people bring from PCI DSS. A listing on PCI SSC’s List of PIN Service Providers shows as expired two years after the date the Qualified PIN Assessor signs Part 3c of the Attestation of Compliance.

Two consequences follow, and both are frequently missed:

  1. The clock starts at signature, not submission. PCI SSC does not prorate for a past-dated attestation, so an assessment completed in March and submitted in July loses those months from the listing rather than shifting it.
  2. An expired listing is visible. Once the expiry date has passed the date appears in orange on the website, and after ninety days it appears in red to show the listing was not revalidated before expiry.

Plan the renewal backwards from the expiry date: submission close behind signature, fieldwork before that, corrective actions closed before fieldwork, and the internal review far enough ahead that findings can actually be fixed.

What the Report on Compliance contains

Two documents come out of the engagement, and they do different jobs. The Report on Compliance is the detailed record: every applicable sub-requirement, what the assessor did to test it, and what they found. It is long, it is the document a payment brand asks for when it wants detail, and it is the one that takes the time.

The Attestation of Compliance is the summary declaration, completed by the assessor and signed by both parties. It records your details, the assessor company’s details, which of the five service categories were included and which were excluded with reasons, the facilities and dates reviewed, and the result.

Review the attestation carefully before signing. An attestation that overstates scope is worse than one that understates it, because you are then representing coverage you do not actually have to everyone who reads it.

Listing is optional

Being listed is not a compliance requirement. The assessment produces an attestation, which you can provide to payment brands and customers directly. Listing is an additional submission, involving a PCI SSC countersignature, for PIN Service Providers who choose to appear on the public list. There are no annual recurring PCI SSC fees associated with an accepted listing.

What a Qualified PIN Assessor finds most often

The findings that recur are rarely exotic. They cluster in a handful of places, and every one of them is visible to an internal review that bothers to test rather than read.

A procedure that produced no records. The requirement asks for procedures demonstrably in use. A correct, approved, current document with nothing behind it is a finding waiting to happen.

Dual control that is really one person and a witness. If the second party only observes, the operation completes without them, and a Qualified PIN Assessor will say so.

Separation defeated by something nobody listed. A facilities master key, a safe supplier’s override code, an administrator who can read both components, or a backup custodian appointed for both halves.

A PIN block in an application log. Usually in debug output, a database audit table, or diagnostic logging switched on for an incident and never switched off.

Device firmware ahead of the approval listing. Approvals name hardware, firmware and resident application versions; an estate that has been patched without re-checking the listing drifts out of match quietly.

A spare hardware security module outside dual control. The requirement names spare and backup devices explicitly, and they are the ones sitting in a cupboard.

Evidence retention, and whose obligation it is

QPA Companies must gather evidence supporting each Report on Compliance and retain it for a minimum of three years from the report’s completion date — case logs, audit results, workpapers, emails, interview notes and technical information.

Note whose obligation that is. It falls on the assessor’s company, not on you. Do not record it in your own retention schedule as an obligation of the assessed entity, and do not rely on the assessor’s copy as your evidence. You need your own records, retained across at least two assessment cycles, because that is the period a future assessment will sample.

Preparing for a Qualified PIN Assessor

The most useful preparation is an internal review run by somebody independent of the people who operate the controls, far enough ahead that findings can be closed. Test the controls rather than reading the procedures: attempt a loading session with one credential set, ask who else can open each container, search application logs for PIN blocks, compare check values across devices for accidental key reuse.

Where you find a gap, say so when the assessor arrives and show the corrective action record. An assessor who finds a gap you already knew about and were fixing treats it very differently from one they discover.

Two areas draw a disproportionate share of assessment time: PCI PIN key blocks, where the position differs by population, and the normative annexes — key injection facilities and remote key distribution.

Frequently asked questions

Can our QSA perform a PCI PIN assessment?

Only if they also hold the Qualified PIN Assessor qualification. QSA and QPA are separate schemes with separate training, and holding one does not confer the other.

Is there a PIN self-assessment questionnaire?

No. Every PCI PIN validation is an onsite assessment by a QPA. Internal checklists are readiness tools, not submissions.

How often do we need assessing?

The listing expires two years after the assessor’s signature on Part 3c of the attestation, so plan on a two-year cycle and work backwards from the expiry date.

Where are the programme documents?

The QPA Program Guide and QPA Qualification Requirements are both free from PCI SSC’s document library, alongside the standard, the reporting template and the attestation.

Getting the documentation together

What a Qualified PIN Assessor asks to see first is rarely a policy. It is the key inventory, the custodian appointments and separation design, the ceremony and loading records, the custody trails, and an evidence register that points every applicable requirement at the artefact that evidences it.

Our PCI PIN Security Toolkit ships all of those among its 149 templates, including a readiness guide written specifically around how a QPA engagement differs from a DSS one. See also our guides to the PCI PIN Security Requirements, PCI PIN scope and PCI PIN vs PCI DSS.

Stay Compliance-Ready

Get compliance tips, new toolkit releases, and standard updates in your inbox.

We don’t spam! Read our privacy policy for more info.