PCI PIN key destruction is the part of key management that ends a key’s life safely, and the compromise procedures that decide what happens when a key may be exposed. Assessors pay close attention to both because a key that is never properly retired, or a compromise handled informally, undermines everything else in your key hierarchy. This guide explains what the PCI PIN Security Requirements expect for destroying keys, keeping logs and backups, and responding to a suspected compromise.
The detail below follows the requirement wording in version 2.0 of the PCI PIN Security Requirements published by the PCI Security Standards Council. Numbering and wording changed in later versions, so map each point to the version in your scope before you use it in a procedure. For the wider standard, see our guides to PCI PIN security requirements and PCI PIN scope.
Free gap assessment
How much of PCI DSS v4 is actually in place?
Score all twelve requirements at sub-requirement level, free, including the ones that stopped being future-dated in 2025.
Run the free PCI DSS 4.0 gap assessment → or View premium report sample
What PCI PIN key destruction covers
The requirement is short: secret and private keys, and their components, that are no longer used or have been replaced must be securely destroyed. The supporting tests add detail, summarised in the table.
| Topic | What the requirement text expects |
|---|---|
| When | Destroy keys and components when no longer used or replaced |
| How | Documented procedures that make keys unrecoverable, for example cross-cut shredding, pulping or burning, and not strip-shredding |
| Storage media | Destroy keys on media following ISO 9564 and ISO 11568 procedures |
| Witness | A third party who is not a custodian witnesses and signs a destruction affidavit |
| After loading | Destroy components after successful loading and confirmation, except where they are held for HSM storage |
Two points catch organizations out. First, destruction applies to every instance, including copies in backups and printed components. Second, the witness must be independent of the custodians, so the people who held the components cannot also witness their destruction.
Building a PCI PIN key destruction procedure
- Trigger. Define when destruction is required: key replaced, key expired, device decommissioned, or component loaded and confirmed.
- Inventory. List every instance of the key or component, including backup copies and printed forms.
- Method. Specify the method for each medium: shred, burn or pulp paper, and wipe or physically destroy electronic media following the referenced standards.
- Dual control. Perform the destruction under dual control, following the principles in our guide to dual control and split knowledge.
- Witness. Have an independent witness observe and sign an affidavit that lists what was destroyed.
- Record. File the affidavit and update the key inventory and log.
Include the custodians in the design. Our page on PCI PIN key custodians explains how custodians are designated with signed forms, and the same people usually deliver the destruction steps.
Key logs and retention
Requirement text in version 2.0 asks for logs whenever keys, components or related materials are removed from storage or loaded to a secure cryptographic device. The test procedures describe an archive of at least two years, with entries showing the date and time in and out, the component identifier, the reason for access, the custodian’s name and signature and the tamper-evident package number. Confirm the current retention period in the version you follow.
Logs are only useful if they match reality. Assessors often sample a destruction event and then trace it to the log, the affidavit and the inventory. A missing package number or a signature by an unauthorised person is a finding on its own.
Backups of secret and private keys
Backups are permitted only to restore accidentally destroyed or inaccessible keys, and they must be held in one of the permitted forms: as separate shares or components, encrypted under a key of equal or greater strength, or inside a secure cryptographic device. Creating a backup requires at least two authorised individuals, and the same controls apply to the backup as to the original. When you destroy a key, plan the destruction of its backups at the same time, because forgotten backups are a common weakness.
Responding to a suspected compromise
The compromise requirement asks for procedures to replace known or suspected compromised keys with a value that is not feasibly related to the original. The test text lists elements that a sound procedure includes.
- Components are never reloaded for a suspected compromise.
- A new key is not installed until the device has been inspected.
- The compromised key is replaced immediately.
- All keys encrypted or derived from the compromised key are also replaced.
- An escalation process and organizational notification are defined.
- Specific compromise events are identified in advance, such as a tamper-evident bag found open or a custodian leaving without handover.
Write these as a playbook with named roles and contact details. The point of the identified events is that staff should not be deciding in the moment whether an open package is serious. Run a tabletop exercise at least annually and record the results.
Replacing derived and dependent keys
The most commonly missed step is replacing dependent keys. If a key-encrypting key is compromised, every working key it protects is exposed. Your key hierarchy diagram should therefore show dependencies so the impact of a compromise can be read directly. See our explanation of PCI PIN key blocks for how binding key usage to the key reduces misuse when a key must be replaced.
Roles and training for key destruction
Name a key management owner who approves destruction events, and make sure at least two trained custodians plus an independent witness are available at any time. Train each of them on the procedure, the risks of key residue on printers and media, and the steps for recording the event. Record attendance, and retrain when the procedure changes. Rotate the witness role among internal audit or compliance staff so that no single person becomes a bottleneck, and confirm each witness understands the difference between observing a destruction and taking part in it.
Retiring equipment
Destruction also applies when devices leave service. Requirements on device removal say that key material must be rendered irrecoverable through zeroization, or the device physically destroyed, under dual control. Devices should then be tested or inspected, affected parties notified, returns tracked and records kept for at least one year. Include this in your decommissioning checklist so it is not treated as an IT clean-up task.
Preparing evidence for PCI PIN key destruction reviews
Assessors work from evidence, so assemble a pack before the assessment. For PCI PIN key destruction, that pack should hold the written procedure, a sample of completed affidavits, the matching log entries, the current key inventory and a list of custodians with their signed forms. Add records of training, because the requirements expect procedures to be known to the people affected. Keep the pack in one place with an index, so the assessor can trace any key from generation to destruction without searching several systems.
Test the trail yourself first. Choose three keys at random, follow each one through the inventory, the log and the affidavits, and note any gap. Fixing a missing signature before the assessor finds it is far easier than explaining it afterwards. Repeat the exercise after every major key ceremony, and after any change in custodians, so that key compromise procedures and destruction records stay in step with how the team actually works.
A hypothetical example
A hypothetical acquirer replaces its zone master key. Two custodians retrieve the old components from separate safes and log the removal. After the new key is loaded and confirmed, they destroy the paper components by cross-cut shredding, and an internal auditor who was never a custodian witnesses the process and signs the affidavit. The key inventory is updated, and the affidavit, log entries and package numbers are filed together. During the next assessment the assessor samples the event and finds a complete trail. The example is invented for illustration.
Common findings about PCI PIN key destruction
- Components destroyed without an independent witness.
- Strip shredding used instead of cross-cut shredding.
- Backups of retired keys left in a safe or vault.
- Logs missing package numbers or custodian signatures.
- No defined list of compromise events, so escalation is ad hoc.
- Dependent keys not replaced after a compromise.
Confirm the wording against the PCI PIN Security Requirements and your assessor’s guidance. Assessments are carried out by a Qualified PIN Assessor, so involve yours early.
Templates for PCI PIN key destruction
To avoid writing destruction affidavits, key logs and compromise playbooks from scratch, the PCI PIN Security Toolkit provides documents you can adapt. Have your assessor confirm they match the version you are assessed against.
PCI PIN key destruction FAQ
Who can witness key destruction?
Version 2.0 text says a third party who is not a key custodian should witness it and sign an affidavit. Check your version and assessor’s interpretation.
Is strip shredding acceptable?
The requirement text names cross-cut shredding, pulping or burning, and states that strip shredding is not sufficient.
How long should key logs be kept?
The version 2.0 test procedures describe a minimum two-year archive. Confirm the period in your current version.
Can we keep backups of keys we have retired?
Backups exist only to restore lost keys, so retired keys and their backups should be destroyed together, under the same controls.
What counts as a compromise event?
Define these in advance, for example opened tamper-evident packaging, an unaccounted-for component or a custodian breach. The procedure should not rely on judgment in the moment.