Payment transactions depend on the secure handling of sensitive cardholder payment data. This data moves through a complex ecosystem of merchants, payment processors, acquirers, issuers, service providers, and payment devices. Each participant has security responsibilities to protect highly sensitive payment account data from breaches, fraud and transaction modification.
Compliance provides a common and mandatory framework for managing these responsibilities and protecting payment account data. At the center of payment compliance is the PCI Security Standards Council (PCI SSC), the global industry body responsible for setting industry-wide security standards.
The Council was established in 2006 by American Express, Discover, JCB International, MasterCard, and Visa Inc. The founding members share ownership, governance, and responsibility for the Council’s activities. Each founding member incorporates the PCI Data Security Standard (PCI DSS) into the technical requirements of its respective payment security compliance programs.
The Council’s primary mission is to enhance the security of payment account data worldwide by developing security standards and supporting programs that promote education, awareness, and effective implementation across the payment ecosystem.
To understand how the PCI SSC supports payment security in practice, it is important to look at the key security standards it develops and maintains, each of which addresses a specific aspect of the payment ecosystem.
PCI Security Standards
The Council maintains a range of payment security standards, each addressing a specific area of the payment ecosystem. These include the PCI Data Security Standard (PCI DSS), PCI PIN Security, PCI PTS, and PCI Point-to-Point Encryption (P2PE).
PCI DSS
Establishes a broad set of technical and operational requirements for protecting payment cardholder data. It applies to entities that store, process, or transmit cardholder data or sensitive authentication data, as well as entities that can impact the security of the cardholder data environment. The standard addresses the security of the broader payment environment through requirements covering areas such as access control, vulnerability management, security monitoring, data protection, and cryptographic controls.
PCI PIN Security
Focuses specifically on protecting personal identification numbers (PINs) during payment transaction processing. The standard is primarily aimed at entities responsible for PIN transaction processing, including acquiring institutions and relevant service providers. It applies to PIN-based transactions using online and offline payment card transaction processing at ATMs and point-of-sale (POS) terminals.
PCI Point-to-Point Encryption (P2PE)
The objective of the P2PE Standard is to support the development, validation, acceptance, listing, and deployment of P2PE Solutions that protect account data throughout its transmission. Under a P2PE Solution, account data is encrypted at the Point of Interaction (POI) within the merchant encryption environment, where the data is captured. The data remains encrypted as it moves through the payment environment and is decrypted only within a secure decryption environment. This approach eliminates the presence of cleartext account data between the POI and the decryption environment.
PCI PTS HSM
Defines security requirements for Payment HSMs used in payment environments, covering their design, security characteristics, and management throughout the Payment HSM lifecycle. The standard is intended to protect the confidentiality and integrity of sensitive payment data and cryptographic keys involved in activities such as PIN processing, card verification, payment card personalization, and key management. It also covers areas such as remote administration and, in the current standard, multi-tenant HSM environments used by cloud providers.
These standards are complementary rather than hierarchical: PCI DSS provides the broad security baseline, while the other standards address specific payment technologies, processes, and security components.
How Payment HSMs Support PCI Compliance
Although these standards address different parts of the payment ecosystem, cryptographic key protection and cryptographic processing are recurring security requirements across several of them. This is where Payment HSMs become relevant.
Payment HSMs play a critical role in protecting sensitive payment data throughout the transaction lifecycle. Payment HSMs can support PCI DSS Requirements 3 and 4 by securely protecting cryptographic keys and performing encryption-related operations. PCI DSS allows cryptographic keys used to protect stored cardholder data to be stored in a secure cryptographic device such as an HSM. Payment HSMs can support the key management and cryptographic operations used to protect cardholder data during transmission over open, public networks.
Payment HSMs help to secure payment transactions by protecting the lifecycle of cryptographic keys and performing encryption and decryption operations. In PIN processing, the PIN is encrypted using different keys at different stages of the transaction, requiring strict controls over how those keys are generated, managed, rotated, and destroyed. PCI PIN Security therefore places particular emphasis on secure cryptographic key handling as well as the detection and management of security events, including compromised keys, supported by documented procedures, defined responsibilities, audit records, and regular reviews.
Within a validated P2PE solution, Payment HSMs can support cryptographic functions such as key management, key loading, encryption/decryption operations, and protection of cryptographic keys.
How Can Payment HSMs Be Deployed to Achieve PCI Compliance?
Payment HSM infrastructure can be deployed in different operational models, including on-premises and cloud-based environments. The appropriate approach depends on factors such as the desired level of control, the organization's infrastructure strategy, operational maturity, and scalability requirements.
Organizations can deploy this infrastructure on-premises, owning and physically controlling their HSMs directly, or in the cloud, where a specialized provider hosts PCI-validated Payment HSMs on their behalf.
PCI For Secure Payments
PCI standards play an important role in securing the global payment industry, with PCI DSS, PCI PIN Security, and PCI P2PE addressing key areas of payment security. Secure payment technologies such as Payment HSMs can support the cryptographic and key-management controls required within these frameworks. A Payment HSM does not by itself make an organization PCI compliant, but it can be an important security component within a broader compliant environment, whether deployed on-premises or through a suitable cloud model.
Utimaco’s Secure Payments Solutions
Utimaco’s Payment HSM portfolio includes the Atalla AT1000 Payment HSM and the CryptoSec Payment HSM, both designed to secure critical payment operations such as key management, PIN processing, and transaction authentication across issuing and acquiring environments. The Atalla AT1000 is recognized as one of the fastest Payment HSMs, delivering up to 10,000 TPS, while the CryptoSec Payment HSM enables easier migration with a strong price-to-performance ratio for modern payment infrastructures. Both solutions are fully PCI compliant.
Utimaco’s fully hosted Payment HSM as a Service offering is an attractive option for organisations that need the flexibility and scalability of the cloud. It also provides one of the fastest and simplest way to comply with the global payment regulations.
Sind Sie bereit, Ihre digitale Zukunft zu sichern?
Schließen Sie sich den über 500 globalen Unternehmen und Regierungsinstitutionen an, die Utimaco für ihre kritische Sicherheitsinfrastruktur vertrauen.
Kontakt VertriebYour download request(s):

Your download request(s):

About Utimaco's Downloads
Visit our Downloads section and select from resources such as brochures, data sheets, white papers and much more. You can view and save almost all of them directly (by clicking the download button).
For some documents, your e-mail address needs to be verified. The button contains an e-mail icon.
A click on such a button opens an online form which we kindly ask you to fill and submit. You can collect several downloads of this type and receive the links via e-mail by simply submitting one form for all of them. Your current collection is empty.