Description
About the PCI PIN Security Toolkit
PCI PIN Security is the standard for how a cardholder’s PIN, and every cryptographic key that protects it, is generated, moved, loaded, used, administered and destroyed. It applies to acquirers and their agents — processors, key-injection facilities and certificate processors — rather than to every merchant, and it is assessed onsite by a Qualified PIN Assessor, a different qualification from the QSA scheme used for PCI DSS.
What the standard does not come with is the documentation an assessment asks for.
The PCI PIN Security Toolkit is 149 editable templates written against PCI PIN Security Requirements and Testing Procedures v3.1, March 2021, and it covers all 145 sub-requirements across all four of the standard’s scope columns.
First, the thing our competitors will not tell you
There is no PCI PIN deadline, because PCI SSC does not set one. The standard says in as many words that the individual payment brands set the effective date for compliance. Anyone selling you a pack against a single industry-wide date is selling you something that does not exist. Contact the payment brands you work with.
What the standard does set is a phase-in for particular requirements — and as of today every one of those dates has passed:
| Date | Requirement | What changed |
|---|---|---|
| 1 June 2019 | 18-3 Phase 1 | Key blocks for internal connections and key storage in service provider environments |
| 1 January 2021 | 13-9 (Annex B) | Entities key-loading on behalf of others could no longer use PC-based key-loading platforms exposing clear-text material |
| 1 January 2023 | 18-3 Phase 2 | Key blocks for external connections to associations and networks |
| 1 January 2023 | 2-2 | Fixed key for TDEA PIN encryption disallowed in POI devices and host-to-host connections |
| 1 January 2023 | 13-9 (Annex B) | The PC-based key-loading restriction extended to entities loading only for their own processing |
| 1 January 2024 | 32-9 (Annex B) | Clear-text key injection disallowed for entities injecting on behalf of others |
| 1 January 2025 | 18-3 Phase 3 | Key blocks extended to merchant hosts, POS devices and ATMs |
| 1 January 2026 | 32-9 (Annex B) | The clear-text injection restriction extended to entities injecting for their own processing |
There is no remaining grace period on anything.
Four things most PIN material gets wrong
These are the reasons to buy this pack rather than a cheaper one. Each is a limit on a requirement that reads much broader than it is, and each is sourced from the standard or from PCI SSC’s own technical FAQs.
| The common claim | What the standard and the FAQs actually say |
|---|---|
| “All POS devices and ATMs had to convert to key blocks by January 2025” | No. POI deployments that existed before that date are not required to convert, though they may choose to. New deployments must |
| “Clear-text key injection is banned” | Only for the more recent POI device generations. Injection into earlier generations remains acceptable past both the 2024 and 2026 dates, until a payment brand mandates those devices out of service |
| “Fixed key is no longer allowed” | The prohibition is on fixed key with TDEA. Fixed key with AES is unaffected |
| “You must support ISO Format 4 PIN blocks by [date]” | Those sunrise dates were suspended in v3.1 and PCI SSC is re-evaluating them. They were dates for supporting the format, not for using it. No replacement date has been published |
A toolkit that gets these wrong sends you to rip out working estates. The relevant documents in the PCI PIN Security Toolkit carry each limit on their face, with a register to record which population each of your connections and device estates actually falls into.
This is a two-year cycle, not an annual one
Buyers arrive from PCI DSS expecting to repeat this every year. A PCI PIN listing shows as expired two years after the date the assessor signs Part 3c of the Attestation of Compliance — not two years from submission, and PCI SSC does not prorate for a past-dated attestation. Submit late and you shorten the listing rather than moving it.
The PCI PIN Security Toolkit plans backwards from that: the programme charter, the governance procedure and the listing guide all work to the two-year clock, and the listing guide sets out the milestone dates to work back from.
Scope is decided by what you do, not by how much you do
There is no transaction threshold below which these requirements stop applying. The standard divides into transaction processing operations, symmetric key distribution using asymmetric techniques, and key-injection facilities — and an organisation is subject to the requirements of every activity it performs.
| Scope column | Sub-requirements |
|---|---|
| Transaction Processing Operations (main body) | 96 |
| Normative Annex A — remote key distribution operations | 85 |
| Normative Annex A — certification and registration authority operations | 105 |
| Normative Annex B — key-injection facilities | 94 |
Those four figures overlap heavily and must not be added together. The standard contains 145 distinct sub-requirement identifiers in total, across 33 numbered Requirements in 7 Control Objectives. An entity subject to more than one column satisfies the union of them, not the sum. The PCI PIN Security Toolkit ships an applicability matrix seeded with all 145 rows against all four columns, so you filter rather than guess.
Both normative annexes are covered in full
Most PIN material stops at the main body. The PCI PIN Security Toolkit does not:
- Normative Annex A gets its own 28-document section covering both sub-annexes —
remote key distribution, and certification and registration authority operations, including a certificate policy, a certification practice statement, CA hardening, audit trail integrity and the three tiers of physical barrier around an authority facility.
- Normative Annex B gets a 12-document section for key-injection facilities, covering
the secure injection room, the caged-environment case, device serial number tracking and reconciliation against a pre-authorised device inventory.
If you do not perform those activities, the sections tell you to record that determination rather than delete them — an assessor asks why a section is absent, and a recorded decision answers faster than a missing folder.
The documents paraphrase the standard. Here is why, and what you get instead
PCI SSC owns the copyright in PIN Security v3.1, and the licence under which it is distributed conveys no right to create a derivative work of it. So unlike toolkits built on US Government publications, the PCI PIN Security Toolkit does not reproduce PCI’s requirement text — and you should be sceptical of any pack that does.
What each document carries instead is a Requirements addressed table naming the identifier, the requirement topic and what the document is evidence for, in our own words, with the paraphrase labelled as a paraphrase on every page it appears. You will need your own licensed copy of the standard, which is free to download from PCI SSC’s document library after accepting their licence.
That is a limitation, and we would rather you knew it before buying than after.
What is in the 149 documents
| Section | Documents | Coverage |
|---|---|---|
| Programme Foundation | 11 | Programme mechanics |
| PIN Processing and Devices | 10 | 11 sub-requirements |
| Key Generation | 9 | 9 sub-requirements |
| Key Conveyance | 11 | 13 sub-requirements |
| Key Loading | 18 | 25 sub-requirements |
| Key Usage | 11 | 13 sub-requirements |
| Key Administration | 14 | 15 sub-requirements |
| Equipment Management | 12 | 10 sub-requirements |
| Annex A Remote Key Distribution | 28 | 38 sub-requirements |
| Annex B Key-Injection Facilities | 12 | 11 sub-requirements |
| Assessment and Listing | 13 | Programme mechanics |
Built so the coverage claim is true
The register that defines this pack fails the build if any of the 145 sub-requirements is unclaimed, and fails separately if a document filed in a transaction processing section cites a requirement the standard scopes to an annex only. That second check is what stops the pack telling an acquirer it has to satisfy a key-injection-facility requirement.
The four seeded workbooks — the applicability matrix, the self-assessment checklist, the gap analysis tool and the evidence register — each assert they wrote exactly 145 rows before saving.
What you get
- 149 templates — 118 Word documents and 31 Excel workbooks, in Microsoft
Office format, fully editable and rebrandable.
- Eleven sections following the standard’s own organisation.
- Coverage of all 145 sub-requirements across all four scope columns.
- Instant download after purchase, free updates and free support.
- A perpetual single-organisation licence.
Frequently asked questions
Does this make us PCI PIN compliant? No toolkit can. Compliance is assessed onsite by a Qualified PIN Assessor against the testing procedures in the standard. The PCI PIN Security Toolkit is the documentation and the records that assessment asks to see.
Is there a self-assessment questionnaire for PCI PIN? No. Unlike PCI DSS, there is no self-assessment route. Validation is an onsite assessment by a QPA. The self-assessment checklist in the PCI PIN Security Toolkit is for your own internal readiness review, not a submission.
When is our deadline? The payment brands set it, not PCI SSC. Contact the brands you work with. The phase-in dates for individual requirements listed above have all passed.
Do we need Annex A and Annex B? Only if you perform those activities. The scope statement in section 00 works that out, and the applicability matrix then filters the 145 requirements down to the ones that apply to you.
Does the pack include the standard itself? No, and it cannot — PCI SSC’s licence does not permit redistribution. The standard is free to download directly from PCI SSC after accepting their licence agreement.
How often do we have to be assessed? The listing expires two years after the assessor signs the attestation. Plan the renewal backwards from that date; the listing guide in section 10 sets out the milestones.
List of all documents
Programme Foundation
- Toolkit Guide and Document Index (Word)
- PCI PIN Scope and Applicability Statement (Word)
- PIN Security Programme Charter (Word)
- PCI PIN Implementation Roadmap (Word)
- PIN Security Terms and Definitions (Word)
- Requirement Applicability Matrix (Excel)
- Cryptographic Key Management Policy (Word)
- Key Custodian Roles and Dual Control Matrix (Excel)
- Key Custodian Appointment and Acknowledgement Form (Word)
- Cryptographic Key Inventory (Excel)
- Key Management Governance and Review Procedure (Word)
PIN Processing and Devices
- Secure Cryptographic Device Policy (Word)
- POI Device Inventory and Approval Register (Excel)
- HSM Inventory and Certification Register (Excel)
- Device Approval Verification Procedure (Word)
- PIN Handling and Cardholder Confidentiality Procedure (Word)
- Online PIN Translation Standard (Word)
- PIN Encryption Algorithm and Key Size Standard (Word)
- Offline PIN and EMV Chip Processing Procedure (Word)
- PIN Block Format Standard (Word)
- PIN Storage and Store-and-Forward Procedure (Word)
Key Generation
- Cryptographic Key Generation Policy (Word)
- Key Generation Ceremony Procedure (Word)
- Key Generation Ceremony Script and Attendance Record (Word)
- Key Generation Environment Standard (Word)
- Key Component Printing and Packaging Procedure (Word)
- Key Generation Residue Destruction Procedure (Word)
- Asymmetric Key Pair Generation Procedure (Word)
- Clear-Text Key Channel Prohibition Standard (Word)
- Key Generation Log (Excel)
Key Conveyance
- Key Conveyance and Transmission Policy (Word)
- Key Conveyance Method Register (Excel)
- Split Knowledge and Component Separation Standard (Word)
- Key Conveyance Channel Standard (Word)
- Public Key Conveyance Procedure (Word)
- Key Component Transit Custody Procedure (Word)
- Tamper-Evident Packaging Inspection Procedure (Word)
- Tamper-Evident Packaging Register (Excel)
- Multiple Key Dispatch Separation Procedure (Word)
- Key-Encryption Key Strength Standard (Word)
- Key Conveyance and Receipt Log (Excel)
Key Loading
- Key Loading Policy (Word)
- Dual Control and Split Knowledge Procedure (Word)
- Key Component Combination Standard (Word)
- HSM Master File Key Standard (Word)
- Initial TMK and DUKPT Key Loading Procedure (Word)
- Public-Key Key-Establishment Standard (Word)
- Clear-Text Key Loading Environment Procedure (Word)
- Electronic Media Key Loading Procedure (Word)
- Key Transfer to Key-Loading Device Procedure (Word)
- Printed Key Component Handling Procedure (Word)
- Component Custodian Separation Control (Word)
- Key-Loading Equipment Control Procedure (Word)
- Cable and Connection Inspection Checklist (Excel)
- Key Loading Activity Log (Excel)
- Key-Loading Credential Management Procedure (Word)
- Key Check Value Validation Procedure (Word)
- Public Key Authenticity Verification Procedure (Word)
- Key Loading Procedures by Device Type (Word)
Key Usage
- Key Usage Policy (Word)
- Unique Link Key Standard (Word)
- Synchronisation Error Monitoring Procedure (Word)
- Tamper Evidence Response Procedure (Word)
- Key Block Implementation Standard (Word)
- Key Block Migration Plan and Status Register (Excel)
- Asymmetric Key Usage Standard (Word)
- Production and Test Separation Policy (Word)
- POI Device Key Uniqueness Standard (Word)
- DUKPT Derivation and Segmentation Standard (Word)
- Base Derivation Key Register (Excel)
Key Administration
- Key Administration Policy (Word)
- Key Administration Awareness Record (Word)
- Key Form and Storage Standard (Word)
- Key Component Storage Register (Excel)
- Key Compromise Response Procedure (Word)
- Failed Key Load Response Procedure (Word)
- Reversible Key Transformation Standard (Word)
- Key Destruction Procedure (Word)
- Key Destruction Certificate (Word)
- Key Destruction Log (Excel)
- Key Custodian Access Control Procedure (Word)
- Key Material Movement and Loading Log (Excel)
- Key Backup Policy (Word)
- Key Backup Register (Excel)
Equipment Management
- Equipment Security Policy (Word)
- Device Receipt and Pre-Service Assurance Procedure (Word)
- Chain of Custody Procedure (Word)
- Device Chain of Custody Record (Excel)
- Device Transport and Storage Protection Standard (Word)
- HSM Dual Control and Spares Procedure (Word)
- POI Device Lifecycle Management Procedure (Word)
- Deployed Device Inventory and Inspection Register (Excel)
- Device Return and Replacement Procedure (Word)
- SCD Decommissioning and Destruction Procedure (Word)
- SCD Key Encryption Misuse Prevention Standard (Word)
- Equipment Inspection and Test Record (Excel)
Annex A Remote Key Distribution
- Annex A Scope and Applicability Statement (Word)
- Remote Key Distribution Policy (Word)
- Key Distribution Host Authorisation Procedure (Word)
- Key Establishment Design Assurance Statement (Word)
- External Key Pair Transfer Procedure (Word)
- POI Certificate Communication Standard (Word)
- Host and POI Private Key Separation Standard (Word)
- Certificate Renewal Key Pair Procedure (Word)
- Certificate-Signing Key Protection Standard (Word)
- CA and RA Key Strength Standard (Word)
- CA Key Purpose Control Procedure (Word)
- CA Private Key Sharing Standard (Word)
- CA Hierarchy and Risk Segmentation Design (Word)
- CA Compromise Response Plan (Word)
- Certificate Policy (Word)
- Certification Practice Statement (Word)
- Certificate Requestor Identity Validation Procedure (Word)
- CA Operations Separation Standard (Word)
- CA Access Control and Separation of Duties Procedure (Word)
- CA System Hardening Standard (Word)
- CA Audit Trail and Log Integrity Standard (Word)
- CA User Authentication Procedure (Word)
- Time Synchronisation Standard (Word)
- CA Facility Physical Barrier Standard (Word)
- CA Intrusion Detection and Alarm Procedure (Word)
- CA Facility Access Logbook (Excel)
- CA Facility Power Resilience Standard (Word)
- CA Alarm Event Log (Excel)
Annex B Key-Injection Facilities
- Key-Injection Facility Scope and Architecture Statement (Word)
- KIF Injection Equipment Standard (Word)
- KIF Dual Control and Split Knowledge Procedure (Word)
- PC-Based Key-Loading Platform Control Standard (Word)
- KIF Key Substitution Prevention Procedure (Word)
- Device Serial Number Tracking Log (Excel)
- Base Derivation Key Separation Standard (Word)
- KIF Remote Key Establishment Procedure (Word)
- Pre-Authorised Device Inventory and Reconciliation (Excel)
- KIF Internal Channel Authentication Standard (Word)
- Secure Key Injection Room Specification (Word)
- Secure Room Inspection Checklist (Excel)
Assessment and Listing
- PCI PIN Self-Assessment Checklist (Excel)
- PCI PIN Gap Analysis Tool (Excel)
- PCI PIN Evidence Register (Excel)
- QPA Assessment Readiness Guide (Word)
- Assessment Scope Definition Worksheet (Excel)
- Sampling and Location Schedule (Excel)
- Internal Review Procedure (Word)
- Internal Review Report Template (Word)
- Nonconformity and Corrective Action Procedure (Word)
- Corrective Action Log (Excel)
- Management Review Meeting Pack (Word)
- Evidence Retention Procedure (Word)
- PCI PIN Listing and AOC Submission Guide (Word)
PCI PIN Security Toolkit – 149 Templates for PIN v3.1
ISO 27001 Assessment Tool – Premium Quality 




































Reviews
There are no reviews yet