PCI PIN key custodians are the named individuals who hold the components or shares of cryptographic keys that protect PINs, and their role is central to how the PCI PIN Security Requirements achieve dual control and split knowledge. The idea is simple: no one person should ever be able to see, use or rebuild a sensitive key alone. Getting the people side right is often harder than getting the hardware right, because it depends on procedures, discipline and records that hold up in an audit.
This guide explains what key custodians do, how dual control and split knowledge apply to them, what a key ceremony should record, how to appoint and manage custodians, and the mistakes that lead to findings. It refers to PCI PIN Security Requirements v3.1, and you should confirm requirement wording and numbering in the current document you are assessed against.
Free gap assessment
How much of PCI DSS v4 is actually in place?
Score all twelve requirements at sub-requirement level, free, including the ones that stopped being future-dated in 2025.
Run the free PCI DSS 4.0 gap assessment → or View premium report sample
What PCI PIN key custodians do
When a cryptographic key is generated, loaded or transferred in a form where people could see it, the standard requires it to be split into components or shares, with each one held by a different assigned person. Those people are the custodians. They receive, hold, load and protect the components they are responsible for, and they sign records showing what they did. Custodians are used in key generation, key loading into secure cryptographic devices, key transport and key injection facilities. Our guides to the key injection facility and to remote key distribution show where the role appears in practice.
Because the standard is about the whole environment, not just the equipment, custodians are part of the assessed control set. Assessors observe, interview and read logs to check that the people follow the documented procedure. For the wider structure of the standard, see our overview of the PCI PIN Security Requirements.
Dual control and split knowledge in PCI PIN key custodians’ work
The two ideas work together, and they are easy to confuse.
| Principle | Plain meaning | Example in practice |
|---|---|---|
| Dual control | Two or more people must act together for a sensitive operation | Two custodians are present when a key is generated in a secure room |
| Split knowledge | No one person holds enough information to recreate the key | Each custodian holds a different component, and one component reveals nothing about the key |
The v3.1 requirements express these ideas in several places. In the numbering used by the reporting template, requirement 6-1.1 says any clear-text output of the key generation process must be managed under dual control, and that only the assigned custodian can have direct access to the clear text of a key component or share, limited to the component or share assigned to that custodian. Requirement 8-2 says a person with access to one component or share of a secret or private key must not have access to other components or shares that are sufficient to form the threshold needed to derive the key. You can read the reporting template on the PCI Security Standards Council listings site.
Appointing and managing PCI PIN key custodians
- Choose people deliberately. Select individuals who are trusted, trained and not otherwise able to reach the other components. Avoid picking people from the same reporting line who could collude easily.
- Formally designate them. Keep a register of custodians by key and component, with dates and management approval.
- Get written acknowledgment. Each custodian should sign a form that states their responsibilities, including protecting components, not sharing them and reporting loss or suspected compromise.
- Train and test. Train custodians before their first ceremony and repeat periodically. Include what to do when something goes wrong.
- Appoint backups. Plan for absence, but keep the same separation rules for backups.
- Review regularly. Check the register when staff move, leave or change roles, and remove access promptly.
The requirements also cover conveying keys. Procedures must designate who is permitted to convey or receive keys, and awareness that custodians cannot access enough components to reconstruct a key on their own. Treat that designation as a controlled list, not an informal habit.
Key ceremonies and the records they leave
A key ceremony is a scripted, witnessed event in which keys are generated, loaded or destroyed. Its records are the evidence of dual control. The v3.1 template describes checks that logs verify documented procedures were followed and that at least two individuals performed the key generation process, and that logs exist for the generation of higher-level keys, including the names and signatures of the individuals involved. Secure rooms used for key printing also need electronic access control that enforces dual-access entry.
What a good ceremony record contains
- Date, time, location and purpose of the ceremony.
- The keys involved, identified by a name or reference and not by value.
- Names and signatures of every participant, and their role.
- Device identifiers and tamper-evident bag or envelope numbers.
- Confirmation that each step of the script was performed, with any deviations noted.
- Time in and out of the secure room.
- The disposition of components after the ceremony, including storage location.
Storing components held by PCI PIN key custodians
Components must be stored so that one person cannot reach more than their own. Common practice is tamper-evident, pre-numbered envelopes or bags, each in its own safe or locked container, with access limited to the assigned custodian and a controlled process for a backup. Log every access to the container. Never store components together, and never write them in an email, ticket or shared document. If an envelope shows signs of tampering, treat the component as compromised, follow your incident procedure and replace the key.
A worked example
The following is a hypothetical illustration. A processor plans to generate a new key for its host security module and split it into three components. It designates three custodians from three different teams, and each signs an acknowledgment form. On the day of the ceremony, an auditor and a security officer witness the process in a secure room with dual-access badge entry. The custodians load their components one at a time, and each seals his or her printed component in a numbered tamper-evident envelope. The log records participants, envelope numbers, times and device serial numbers, and everyone signs. Each envelope goes into a different safe, held by a different person. Six months later, one custodian moves to another department. The register is updated, the component is transferred under the documented procedure with a new custodian’s acknowledgment, and the change is logged. At the annual assessment, the assessor selects a ceremony, compares the log with the procedure and interviews two custodians, who describe their responsibilities accurately.
Common findings for PCI PIN key custodians
- Custodians with access to more than one component. Often caused by shared safes or administrator privileges.
- Missing acknowledgments. No signed form for one or more custodians.
- Incomplete ceremony logs. Missing signatures, times or envelope numbers.
- Stale registers. Departed staff still listed, or new custodians who were never formally designated.
- Untrained custodians. People who cannot describe their duties when interviewed.
- Improvised deviations. Steps skipped during the ceremony without being recorded.
- Weak storage. Components in unlocked drawers or in one shared safe.
Reducing dependence on people
The more keys are handled in clear by people, the more risk there is. Many organizations reduce manual handling through key blocks, secure remote key distribution and injection using approved devices and facilities. Our notes on PCI PIN key blocks and PCI PIN scope explain how those choices change what is in scope. The comparison of PCI PIN and PCI DSS shows how the two standards divide the work. Even so, some manual ceremonies usually remain, and custodians should be treated as an important control.
Documenting your PCI PIN key custodians program
Assessors expect a key management policy, a custodian register, designation and acknowledgment forms, ceremony scripts and logs, storage procedures, an incident procedure for suspected compromise and a training record. The PCI PIN Security Toolkit provides templates for these that you can adapt to your environment. Keep your own procedures aligned with the version of the requirements you are assessed against.
PCI PIN key custodians FAQ
How many key custodians do we need?
Enough that no one person can reconstruct a key and that at least two people take part in key generation. The number of components depends on your design, and backups need the same separation.
What is the difference between dual control and split knowledge?
Dual control means two or more people must act together for a sensitive operation. Split knowledge means no one person holds enough information to recreate the key.
Can one person hold two components?
No, not in a way that gives them sufficient components to derive the key. The requirements state that a person with access to one component must not have access to others that reach the threshold.
Do custodians need to sign anything?
They should sign ceremony logs and, as good practice, an acknowledgment of their responsibilities. Check the wording of the requirements you are assessed against.
What happens if a component envelope is tampered with?
Treat the component as compromised, follow your incident procedure, and replace the affected key according to your key management policy.