Reference

Payment Certification Levels

A practical guide to EMVCo L1 / L2 / L3 terminal certifications, PCI DSS merchant compliance tiers, and the standards that govern every card-present transaction.

PCI PTS & Software Security Framework

PCI PTS and PCI SSF govern the hardware and software side of the payment security stack independently from merchant compliance tiers.

PCI PTS

PIN Transaction Security

Governs all devices that enter, process, or transmit PINs and sensitive authentication data. Applies to POS terminals, PIN pads, and unattended payment terminals.

Device classes

  • POI — Point of Interaction (POS terminals, PIN pads)
  • HSM — Hardware Security Modules
  • PED — PIN Entry Devices (tested under POI since PTS 5.x)

Security levels (POI)

  • Open protocolsNo additional tamper resistance
  • EnhancedExtra logical and physical security
  • Open + screenedModules with screened components

Key requirements

  • Tamper-evident / tamper-responsive enclosure
  • Secure key loading and key management
  • Isolated cryptographic module for PIN encryption
  • All PINs encrypted immediately upon entry (DUKPT or Master/Session)
  • Display and keypad integrity verification

PCI SSF

Software Security Framework

Replaced PA-DSS (Payment Application Data Security Standard) in 2022. Covers software security for payment applications across two programmes.

Two standards

  • Secure Software Standard (S3) — for payment software running on commercial off-the-shelf environments (COTS). Covers secure development lifecycle, vulnerability management, and sensitive data handling.
  • Secure Software Lifecycle Standard (Secure SLC) — for vendors who want to demonstrate a mature, repeatable security development process. Provides a vendor-level certification rather than a per-product one.

Key differences from PA-DSS

  • Broader scope: covers SaaS and cloud payment apps (PA-DSS was limited to COTS)
  • Lifecycle focus: secure design, not just point-in-time assessment
  • Modular: S3 and Secure SLC can be used independently

PCI P2PE

Point-to-Point Encryption

A validated P2PE solution encrypts cardholder data from the point of swipe/dip/tap all the way to the decryption environment, keeping the merchant's POS system out of PCI DSS scope.

  • Merchants using a validated P2PE solution can use SAQ P2PE (~35 questions)
  • Decryption must occur in a PCI-compliant HSM
  • Key management must follow PCI PTS HSM requirements
  • Solution providers are listed on the PCI SSC P2PE Solutions List

PCI 3DS

3-D Secure Core Security Standard

Governs security requirements for entities that provide 3DS services: Access Control Servers (ACS), 3DS Servers, and Directory Servers.

  • Applies to: ACS vendors, 3DS service providers, DS operators
  • Covers: Cardholder data protection, cryptographic key management, audit logging
  • Assessment: Annual assessment by a PCI 3DS Assessor

Related Tools

Use these tools to work with the cryptographic primitives that underpin terminal and card security.