A PCI PIN key ceremony checklist is a step-by-step list for any event in which cryptographic keys or key components are generated, loaded, exchanged or destroyed, so that every action is performed under dual control with split knowledge and is fully recorded. Key ceremonies are among the most closely examined activities in a PCI PIN assessment.
PCI PIN Security Requirements apply to organizations that handle PIN data and the keys that protect it, such as acquirers, processors, key injection facilities and certification authorities. The requirements are maintained by the PCI Security Standards Council, and the assessor will compare what you do with the current text.
This guide describes a practical ceremony structure. It is general guidance and does not replace the PCI PIN requirements, your payment brand rules or the instructions of your assessor, so always check the current documents.
Free gap assessment
How much of PCI DSS v4 is actually in place?
Score all twelve requirements at sub-requirement level, free, including the ones that stopped being future-dated in 2025.
Run the free PCI DSS 4.0 gap assessment → or View premium report sample
Why a PCI PIN key ceremony checklist matters
Keys protect every PIN that passes through your systems. If an attacker or an insider obtains a full key in clear text, the protection fails. The defense is to ensure that no single person ever has access to a whole clear-text key. That is what dual control and split knowledge achieve in practice.
Ceremonies are also where human error creeps in. Components get read aloud, forms are signed after the fact, or a seal is broken and nobody writes down why. A written checklist makes each step deliberate and provable.
Assessors usually ask to see ceremony records, observe a live one and interview the custodians. A clear, consistent checklist and a complete set of records shorten that process.
Understand dual control and split knowledge
Dual control means at least two authorized people are required to perform a sensitive function, and no single person can complete it alone. Split knowledge means a key is divided into components so that no person has enough information to reconstruct it. Both principles must hold at once.
In practice, a key is split into at least two components, each given to a different custodian. Each custodian knows only their own component, and each component alone reveals nothing about the key. More detail is in dual control and split knowledge.
The checklist should make these principles explicit at each step, for example by stating which custodian handles which component and confirming that no one else can view it.
| Stage | Key checks | Evidence |
|---|---|---|
| Preparation | Approved request, named roles, secure room, tools verified | Request form, role list |
| Execution | Dual control and split knowledge at every step | Ceremony script, signed log |
| Custody | Components in tamper-evident packaging with serial numbers | Seal log, custody forms |
| Verification | Key check values match, devices confirmed | Check value record |
| Closure | Materials returned or destroyed, records filed | Closure record |
Prepare the PCI PIN key ceremony checklist roles
Define the roles before the day. Typical roles include the ceremony administrator who runs the script, two or more key custodians, a witness or an internal auditor, and a security officer who controls the room. Key custodians must be formally appointed and must acknowledge their responsibilities, as described in PCI PIN key custodians.
Approve the ceremony in advance with a documented request that states the purpose, the keys involved, the devices and the people. Confirm that the custodians are not in a conflict, for example that one does not report to the other in a way that undermines independence.
Prepare the room and tools: a controlled space, no unauthorized devices, verified secure cryptographic devices, tamper-evident bags with recorded serial numbers, and blank forms. Check that all materials are sealed and intact before starting.
Run the ceremony under control
Follow a written script. The administrator reads each step, the custodians perform their actions, and the witness confirms and signs. Only the people needed for each step should be in the room at that step.
Generate or load keys inside secure cryptographic devices and avoid exposing clear-text components outside them. Where a device supports key blocks, use them so keys are bound to their usage, as discussed in PCI PIN key blocks. After loading, verify using key check values, and record the result without revealing the key.
For remote distribution and injection, follow the specific controls for that method. See PCI PIN remote key distribution and PCI PIN key injection facility.
Record, seal and store
Every event needs a record: date and time, participants, devices, key identifiers, seal serial numbers, check values, deviations and signatures. Do it at the time, not afterward. Copies of the logs should go to a separate custodian of records.
Store components in tamper-evident packaging in secure containers that require dual access, such as safes with two different keys or combinations held by different people. Keep inventory logs that show each opening, who was present and why.
If a seal appears damaged or a component is missing, stop and follow the compromise procedure. The guidance in PCI PIN key destruction and compromise explains how to handle suspected compromise and how to destroy keys and materials.
Closure and review
At the end, return or destroy materials as the script states, confirm the room is clear and complete the closure record. Check that all signatures are present and that the ceremony log matches the request.
Review each ceremony within a few days. Did everything follow the script? Were there deviations? Are any follow-up actions needed, such as replacing a seal or updating the script? Feed lessons into the next version of the checklist.
Keep records for the retention period set by your policy and your assessor’s expectations. Make them easy to retrieve for the next assessment by a qualified PIN assessor.
A short PCI PIN key ceremony checklist example
A processor needs to load a new zone master key into a hardware security module. The request is approved. Three people take part: two custodians and a witness. Each custodian holds a component in a sealed bag. The administrator confirms the seal numbers match the log. Custodian one enters component one into the device, and custodian two enters component two.
After both entries, the device reports a key check value, and the custodians and the witness confirm it matches the value recorded by the partner. The components are destroyed, the log is signed and the closure record is filed. The example is invented and simplified, but it shows how a PCI PIN key ceremony checklist prompts each action and each record.
If the key check value had not matched, the team would stop, investigate and log the deviation before continuing.
Common mistakes and assessor findings
Frequent findings include custodians who are not formally appointed, forms signed in advance, shared access to safes, missing seal logs, key components emailed or read out, and no separation between custodians and administrators. Another common gap is failing to show that only necessary people were present.
Others are ceremony scripts that do not match actual practice, stale custodian lists after staff changes and incomplete evidence of destruction. Make it a habit to review the list of custodians each quarter.
The relationship with the broader payment standard is explained in PCI PIN vs PCI DSS. For scoping, see PCI PIN scope, and for the requirements overview read PCI PIN security requirements.
Training custodians for a PCI PIN key ceremony checklist
Custodians carry real responsibility, so train them properly. Cover the principles of dual control and split knowledge, the handling of components and seals, what to do if something looks wrong and the legal and disciplinary consequences of misuse. Have each custodian sign an acknowledgment and repeat the training on a schedule.
Run a dry rehearsal using test keys. Practicing with test keys lets people learn the script without risk, and it reveals unclear steps. After the rehearsal, collect feedback and improve the PCI PIN key ceremony checklist. Keep a record of attendance and of the scripts used, because assessors often ask how custodians know what to do.
Rotate roles where practical, so no one person becomes a single point of failure, and maintain a backup list of trained custodians in case of absence or departure.
Keeping the PCI PIN key ceremony checklist current
Review the checklist whenever the key hierarchy, devices, vendors or the PCI PIN requirements change, and at least once a year. Record each change with a date and approver. Compare your checklist with the latest standard text and with any guidance from your acquirer or brand, and close gaps promptly. Periodic internal reviews of completed ceremony records help ensure the checklist is being followed in practice, not just stored in a policy folder.
Using a ready-made PCI PIN key ceremony checklist
Writing the ceremony scripts, custodian forms, logs and policies from scratch is slow and easy to get wrong. A prepared set of templates helps you start from a consistent structure.
The PCI PIN Security Toolkit provides 149 templates for PCI PIN v3.1, including forms and records for key management, custodian acknowledgments, ceremony logs and destruction records. Adapt them to your devices, key hierarchy and procedures.
Whichever route you take, rehearse the ceremony before the real event and then ask an independent person to review the records against your PCI PIN key ceremony checklist. The Council publishes the standard at PCI Security Standards Council document library.
PCI PIN key ceremony checklist FAQ
What is a key ceremony?
It is a controlled event in which cryptographic keys or key components are generated, loaded, exchanged or destroyed under dual control and with full records.
What is split knowledge?
It is a method in which a key is divided into components so that no single person knows or can reconstruct the whole key.
How many custodians are needed?
At least two for dual control, each holding a different component, plus roles such as administrator and witness as your procedure requires.
What records should we keep?
Request and approval, participants, device and key identifiers, seal numbers, check values, deviations, signatures and closure records.
Who assesses PCI PIN compliance?
Qualified PIN assessors, who compare your practice and records with the current PCI PIN requirements.