Payment Card Industry (PCI) PIN Security Compliance Assessment Checklist Form
Use this checklist to assess your organization's compliance with PCI PIN security requirements. All checklist items are designed to help you evaluate adherence to established PCI PIN security controls. Do not enter sensitive personal or financial information.
Are PIN entry devices (PEDs) physically secured against tampering and unauthorized access?
*
Compliant
Non-Compliant
Not Applicable
Are cryptographic keys used for PIN protection managed and stored securely according to PCI standards?
*
Compliant
Non-Compliant
Not Applicable
Is dual control and split knowledge enforced for all PIN cryptographic key components?
*
Compliant
Non-Compliant
Not Applicable
Are PINs encrypted immediately upon entry and during all transmission and storage processes?
*
Compliant
Non-Compliant
Not Applicable
Are procedures in place for regular inspection and detection of device tampering or substitution?
*
Compliant
Non-Compliant
Not Applicable
Is access to PIN processing and key management systems restricted to authorized personnel only?
*
Compliant
Non-Compliant
Not Applicable
Are audit logs maintained and regularly reviewed for all PIN-related activities?
*
Compliant
Non-Compliant
Not Applicable
Are PINs never displayed in plain text or stored unencrypted at any point?
*
Compliant
Non-Compliant
Not Applicable
Are all personnel handling PIN security trained on PCI PIN security requirements?
*
Compliant
Non-Compliant
Not Applicable
Is there a documented incident response plan for PIN security breaches?
*
Compliant
Non-Compliant
Not Applicable
Submit Assessment
Should be Empty: