Visa recently announced the sunset of its PIN Security compliance program, set to take effect from October 1st, 2023.Traditionally, Visa ensured entities' systems, devices, and processes complied with PCI PIN standards, crucial for maintaining transaction security and preventing fraud.

However, with the new changes, the Visa PIN Security Program will no longer validate Payment Card Industry (PCI) PIN security requirements. While the program becomes inactive, clients, processors, and service providers must continue adhering to PCI PIN security standards.

It's important to note that Visa's decision to enhance its compliance program should not be misconstrued as a decreased emphasis on the PCI PIN standard. Acquirers, Third Party Agents, and Processors are still required to comply with PCI PIN Security requirements, emphasizing the need for industry standards to maintain a secure payment ecosystem.

Effects of Visa Sunset:

  • The Visa sunset will impact the "Visa Global Registry of Service Providers," with PCI PIN validation types no longer listed once previous ones expire.
  • PTS devices Expired with Approvals from production can remain deployed but are recommended for replacement once added to the PCI’s PIN Transaction Security Devices with Expired Approvals list.
  • Scheduled submissions of compliance with PCI PIN Security Requirements are no longer required by Visa. However, those managing PINs for Visa or handling key management and PIN devices must still follow those requirements.
  • The sunset of the compliance program has not waived or altered any fees or obligations associated with a compromise resulting from a violation of the Visa Rules leading to the loss of Visa Account data with PIN.

New changes to PCI SLA:

SLA (Service Level Agreement) 30 calendar-day submission timelines for AQM (Assessor Quality Management) are moving to a 30 business-day SLA. As declared by the PCI SSC (PCI Security Standard Council), the updated submission timelines for AQM took effect on September 27th, 2023.

This change impacts submission review times and response preparations by the AQM, considering weekends, holidays, and office closures applicable to the United States of America. For example, if the submission occurred on December 1st, 2023, the PCI SSC's response would happen approximately on January 17th, 2024 (47 calendar days), excluding 14 weekend days and 3 holidays.

Need more information? Our expert team is available to answer your questions about the Visa PIN Security Program. Contact us today.

Column Header Text Column Header Text Column Header Text

Their work should have not stopped there because achieving compliance is an occasional result that doesn't ensure a continual protection.

Their work should have not stopped there because achieving compliance is an occasional result that doesn't ensure a continual protection.

  • Their work should have not stopped there because achieving
  • Their work should have not stopped there because achieving
  • Their work should have not stopped there because achieving
  • Their work should have not stopped there because achieving

Their work should have not stopped there because achieving compliance is an occasional result that doesn't ensure a continual protection.

Their work should have not stopped there because achieving compliance is an occasional result that doesn't ensure a continual protection.

Their work should have not stopped there because achieving compliance is an occasional result that doesn't ensure a continual protection.

Performing a review of the media inventories at least annually

Performing a review of the media inventories at least annually

Performing a review of the media inventories at least annually

Row Header Text

Lorem ipsum dolor sit

Lorem ipsum dolor sit

23

Row Header Text

Lorem ipsum dolor sit

Lorem ipsum dolor sit

23

Row Header Text

Lorem ipsum dolor sit

Lorem ipsum dolor sit

23

Row Header Text

Lorem ipsum dolor sit

Lorem ipsum dolor sit

23

Row Header Text

Lorem ipsum dolor sit

Lorem ipsum dolor sit

23

Row Header Text

Lorem ipsum dolor sit

Lorem ipsum dolor sit

23

Row Header Text

Lorem ipsum dolor sit

Lorem ipsum dolor sit

23

Row Header Text

Lorem ipsum dolor sit

Lorem ipsum dolor sit

23

Discover More

Advantio_Blog_DNS_Diagram_V1 Image caption goes here. This is HTML text.

Established in 2009, Advantio offers a comprehensive portfolio of professional, managed, advisory, and security testing services. Our subject matter expertise and services focus on cybersecurity, data protection, risk, and compliance with a distinct specialization in the ‘Payment Card Industry.’ We believe that for your organization to compete and grow in a rapidly evolving environment, investing in the right partner and technology is crucial to help you focus better on your core business. Our team works tirelessly to help you achieve, maintain, and demonstrate compliance against the most demanding cybersecurity standards and regulatory frameworks on time and on budget. With a strong presence across Europe and global reach on four continents, we have become the partner of choice for many large corporates and international enterprises. Our clients span a diverse range of fintech suppliers and fintech consumers in verticals such as travel, hospitality, telecommunication, financial, healthcare, education, entertainment, government, non-profit and more.

Schedule a call with an expert