Knowledge
·
February 2, 2021

PCI 3DS Assessment and Certification

3DS 2.0 changes who must validate. This guide sets out which 3DSS, ACS, cloud and HSM providers need a PCI 3DS assessment, and the seven steps to certification.

Article cover image

The 3DS 2.0 New Era

3D Secure (3DS) is a solution designed to enhance the security of online payment-by-card transactions by authenticating that the payer is the rightful owner of the card. All major global card schemes have adopted the common 3DS standards and specification managed by EMVCo. Global card schemes have set liability shift timelines for migration to 3DS transactions, while the revised European Payment Services Directive (PSD2) requires Strong Customer Authentication (SCA) for online payments.

The newest EMV® 3-D Secure Protocol and Core Functions Specification for the certification of ACS, DS, and 3DSS products is version 2.2.0, while the PCI SSC released the PCI 3DS Core Security Standard v1.0 in December 2017. The global payment cards industry has entered a new 3DS 2.0 era.

3DS Product Certification

3DS product providers and software vendors need certification of compliance to EMVCo's 3DS specification as well as card schemes' secure programs in order to integrate with the card schemes' Directory Server. Visit EMVCo's website for more information on 3DS product specifications, and the Visa Technology Partner website for the Visa Secure program and Visa's EMV 3DS Product Testing.

Who needs PCI 3DS validation?

Below is a summary of relevant certification requirements based on Visa's Certification Guide and Checklist for the ACS and 3DSS, as well as our suggestions.

(1) 3DSS Services

If you are a 3DS Server (3DSS) Hosting Services provider or an Acquirer Processor, you need to pass the validation of PCI DSS for the 3DE (3DS Data Environment). If you are a Merchant running your own 3DSS for your operations, you have to pass PCI DSS assessment too.

(2) ACS Services

For ACS services, if you are an ACS Hosting Services Provider or Issuer Processor, you are required to pass both PCI DSS and PCI 3DS assessments for your 3DE (or to pass both Part 1 and Part 2 of PCI 3DS). But if you are an Issuer — whether you buy an ACS solution or build your own ACS system — you can choose whether to get these assessments; both standards are not mandated for an Issuer using ACS.

(3) Cloud Service and Cloud Service Vendor

For companies who would like to utilize cloud technologies for their 3DS operations or ACS services, it is very important to verify that the cloud service vendor has been validated by the PCI 3DS Standard; both PCI 3DS AOC and ROC should be submitted to the card scheme before registering as a 3DS services vendor.

(4) HSM (Hardware Security Module)

The PCI 3DS Standard requires a high-level HSM for cryptographic management. For ACS and DS, all key management activity for specified cryptographic keys (as defined in the PCI 3DS Data Matrix) must be performed using an HSM that is either FIPS 140-2 Level 3 (overall) or higher certified, or PCI PTS HSM approved. If you are planning ACS services, get the right model and level of HSM — some cloud Key Management Services are only FIPS 140-2 Level 2 (overall) and will not meet PCI 3DS requirements.

How to get PCI 3DS Certification

(1) Check your PCI DSS compliance

There are two parts to the PCI 3DS Core Security Standard: Part 1 Baseline Security Requirements and Part 2 3DS Security Requirements. Part 1 is the equivalent of PCI DSS — if you have passed PCI DSS validation for the PCI 3DS environment, you don't need Part 1 again. Since VISA requires ACS Hosting and Issuing Processors to have PCI DSS validation, PCI DSS should be seen as a must.

(2) Confirm products (ACS, DS, 3DSS) have been approved by EMVCo

Check whether the software systems you use have been certified by EMVCo and the card scheme. If you build it yourself, you have to get the LOA yourself; if from vendors, have them confirm they have the LOA.

(3) Establish a PCI 3DS environment based on the PCI 3DS Security Standard

Set up your systems, applications, databases, networks and security components based on PCI DSS requirements or PCI 3DS Part 1. If using a cloud service, check that your vendor has been validated by PCI 3DS before you use it.

(4) Ensure the security of your 3DS data

Based on the PCI 3DS Data Matrix, all sensitive data should be encrypted in your 3DS environment. Most 3DS transaction data is transferred by API between DS, 3DSS, and ACS — TLS protection and the relevant certificates issued by card schemes should be in place.

(5) Prepare and implement related procedures and management assignments

The PCI 3DS standard requires many accompanying management policies, procedures and risk management strategies, plus execution records to prove your compliance.

(6) Technical testing of compliance requirements

Most technical tests are required by PCI DSS or PCI 3DS Part 1, but application/development security, code review and testing of the API interfaces should be done before your systems can be validated.

(7) PCI 3DS Assessment

Engage a PCI 3DS QSA company to do the assessment. Based on card scheme requirements, you have to inform your card schemes before you conduct the PCI 3DS Assessment. Assessment takes 3-5 days of onsite checking and evidence review — following the QSA company's guidance to get the environment ready and keep enough compliance evidence helps you pass validation more smoothly and quickly.

Contact Us Today for Expert PCI Compliance Support

👉 Contact Us