Skip to content

Evidence request lists

PCI PIN Security

Evidence request list. 43 controls, 43 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Access Control

CO-17
Access to Secret and Private Cryptographic Keys and Key Material Is Restricted

Access to secret and private cryptographic keys and key material must be restricted to a small number of designated key custodians on a need-to-know basis with enforced dual control.

Artefacts an auditor will ask for
  • Designated custodian lists with signed acknowledgments
  • Access control configuration for HSM management
  • Dual-control evidence for key operations
  • Access review records
Where this commonly fails
  • Too many designated custodians beyond need-to-know
  • Single-person access to clear-text components
  • Access lists not reviewed periodically

Device Approval

CO-1
PINs Used for Cardholder Authentication Are Processed in Approved Devices

PINs entered for cardholder authentication must be processed only in PCI PTS approved devices (POI, HSM) that meet current security requirements and remain in approved status.

Artefacts an auditor will ask for
  • PCI PTS approval listings for each device model in use
  • Device inventory mapping serial numbers, firmware, and approval status
  • Process for monitoring device approval expirations
  • Decommissioning records for devices removed from approval
Where this commonly fails
  • Devices in service past PTS approval expiry
  • Inventory not aligned with approved firmware versions
  • No monitoring of PTS listings on the PCI SSC website
CO-2
Devices Approved Under PCI PTS POI Have SRED Functionality

Where POI devices are used in account data acceptance, devices must implement Secure Reading and Exchange of Data (SRED) functionality to protect account data within the secure boundary.

Artefacts an auditor will ask for
  • Vendor documentation confirming SRED functionality
  • Configuration verification at provisioning showing SRED enabled
  • Sample device inspection records
  • Process for verifying SRED across the device fleet
Where this commonly fails
  • SRED disabled or not configured at provisioning
  • No periodic verification that SRED remains enabled
  • Documentation does not specify SRED status per device model

Equipment Management

CO-10
Equipment Used to Process PINs and Keys Is Managed in a Secure Manner

Equipment used to process PINs and cryptographic keys, including HSMs and POI devices, must be inventoried, secured, monitored, and disposed of in a manner that prevents disclosure of sensitive data.

Artefacts an auditor will ask for
  • Equipment inventory with serial numbers and locations
  • Monitoring records for equipment status
  • Secure disposal procedures and certificates
  • Records of zeroization before disposal
Where this commonly fails
  • Equipment inventory incomplete or not reconciled
  • Disposal without zeroization evidence
  • No process for handling defective equipment containing keys

Key Distribution

CO-Annex-A
Symmetric Key Distribution Using Asymmetric Techniques

Symmetric key distribution using asymmetric techniques (remote key loading) must follow defined operational and technical requirements including device authentication, certificate management, and audit logging.

Artefacts an auditor will ask for
  • Remote key loading architecture documentation
  • Certificate authority procedures
  • Device authentication records
  • Audit logs for each remote loading session
Where this commonly fails
  • Certificate revocation not validated
  • Device authentication not mutual
  • Loading sessions without audit logging

Key Injection

CO-Annex-B
Key-Injection Facility Requirements

Key-injection facilities must operate under approved physical, logical, and procedural controls, including certified TRSMs, controlled access rooms, and documented operational procedures.

Artefacts an auditor will ask for
  • KIF certification by approved assessor
  • Physical security documentation
  • Operator role definitions enforcing dual control
  • Injection logs for each device
Where this commonly fails
  • KIF operating outside certified physical envelope
  • Operator roles not enforcing separation
  • Injection logs lack operator identification

Key Management

CO-11
Secret and Private Keys and Key Components Are Generated, Conveyed, and Used in a Manner That Prevents or Detects Their Unauthorized Disclosure, Modification, or Substitution

End-to-end controls must ensure secret and private keys and their components are protected throughout their lifecycle, with mechanisms to detect any unauthorized disclosure, modification, or substitution.

Artefacts an auditor will ask for
  • Cryptographic boundary documentation
  • Key check value (KCV) verification records
  • Detection mechanisms for key modification
  • Lifecycle traceability records
Where this commonly fails
  • Key check values not verified at each transfer
  • Cryptographic boundary undefined or poorly documented
  • No alerting on unexpected key changes
CO-12
Keys Are Used in a Manner That Prevents or Detects Their Unauthorized Usage

Mechanisms must be in place to prevent or detect unauthorized usage of cryptographic keys, including monitoring of key usage patterns, anomaly detection, and audit log review.

Artefacts an auditor will ask for
  • Key usage monitoring configuration
  • Anomaly detection thresholds and alerts
  • Audit log review records
  • Investigation records for detected anomalies
Where this commonly fails
  • No baseline of normal key usage for anomaly comparison
  • Audit log review performed without documented cadence
  • Alerts triggered but not investigated
CO-13
Keys Are Administered Throughout Their Lifecycle in a Secure Manner

Key administration procedures must cover the entire key lifecycle from generation through destruction, with appropriate controls at each stage to prevent compromise.

Artefacts an auditor will ask for
  • Documented key lifecycle policy
  • Procedures for each lifecycle stage
  • Stage transition approval records
  • Lifecycle audit trail
Where this commonly fails
  • Lifecycle stages not clearly defined
  • Transition between stages performed without authorization
  • Audit trail does not span the complete lifecycle
CO-14
Materials Used to Generate or Transport Keys Are Treated With the Same Security as the Keys They Protect

Smart cards, paper components, and other materials used to generate or transport cryptographic keys must be treated with the same security controls as the keys themselves, including dual control and secure storage.

Artefacts an auditor will ask for
  • Material handling procedures aligned to key sensitivity
  • Secure storage records (safe inventory, custodian logs)
  • Dual-control procedures for material access
  • Material destruction records
Where this commonly fails
  • Smart cards stored in unsecured locations
  • Material destruction not witnessed
  • Inventory of materials not reconciled with key inventory
CO-15
Cryptographic Keys Are Replaced With New Keys When Knowledge of Or Access to a Key Is No Longer Required

Cryptographic keys must be replaced when there is suspected or known compromise, when custodians leave their roles, or when the cryptoperiod expires. Replacement must use approved methods.

Artefacts an auditor will ask for
  • Defined cryptoperiods for each key type
  • Key replacement procedures
  • Records of replacements due to custodian changes
  • Compromise response and replacement procedures
Where this commonly fails
  • Cryptoperiods exceeded without replacement
  • Custodian departures not triggering key replacement
  • Compromise response procedures untested
CO-16
Keys No Longer Used or Replaced Are Securely Destroyed

Cryptographic keys that are no longer required or have been replaced must be securely destroyed in a manner that ensures the keys and any associated material cannot be recovered.

Artefacts an auditor will ask for
  • Documented key destruction procedures
  • Destruction certificates with witness signatures
  • HSM zeroization logs
  • Inventory updates reflecting destroyed keys
Where this commonly fails
  • Destruction without witnesses
  • Destruction certificates incomplete
  • Inventory not updated post-destruction
CO-5
Cryptographic Keys Are Generated Using Approved Methods

All cryptographic keys must be generated within PCI-approved cryptographic devices using approved random number generation, ensuring keys are unique, unpredictable, and of sufficient strength.

Artefacts an auditor will ask for
  • Key generation ceremony scripts
  • RNG source documentation (FIPS 140-2/3 validated)
  • Ceremony witness records
  • Key strength verification documentation
Where this commonly fails
  • Keys generated outside approved cryptographic devices
  • Ceremony witnesses not independent of custodians
  • RNG source unverified
CO-6
Cryptographic Keys Are Conveyed or Transmitted Securely

Cryptographic keys must be conveyed or transmitted between locations and devices using approved methods, including encrypted transport, dual control, split knowledge, and authenticated channels.

Artefacts an auditor will ask for
  • Key transport procedures with dual control
  • Records of split-knowledge component handling
  • Secure courier or encrypted channel documentation
  • Acknowledgment of receipt by destination custodians
Where this commonly fails
  • Clear-text key components transported by single custodian
  • Split components shipped together breaching split knowledge
  • Receipt acknowledgments missing or unsigned
CO-7
Key Loading Is Handled in a Secure Manner

Keys must be loaded into POI devices and HSMs in a secure manner that prevents disclosure or substitution, with appropriate dual control, witness verification, and detailed logging.

Artefacts an auditor will ask for
  • Key loading procedures with dual control
  • Key loading logs identifying operators and devices
  • Witness signatures on each loading event
  • Procedures for verifying successful key loading
Where this commonly fails
  • Loading performed by single operator without witness
  • Logs missing operator IDs or timestamps
  • No verification step that the loaded key matches the intended key
CO-8
Keys Are Used Only for Their Designated Purpose

Cryptographic keys must be used only for the specific purpose for which they were generated and distributed. Cross-use of keys between different cryptographic functions must be prohibited.

Artefacts an auditor will ask for
  • Key inventory specifying purpose for each key
  • Technical controls preventing cross-use (key attributes, HSM configuration)
  • Audit logs showing key usage by purpose
  • Procedures defining allowed key purposes
Where this commonly fails
  • Same key used for PIN encryption and MAC generation
  • Key purpose attributes not enforced by HSM configuration
  • Audit logs do not capture key usage purpose
CO-9
Keys Are Administered in a Secure Manner

Key administration including activation, deactivation, replacement, and destruction must be performed under documented procedures with appropriate authorization, dual control, and audit logging.

Artefacts an auditor will ask for
  • Key administration procedures
  • Authorization records for key changes
  • Dual-control records for administrative operations
  • Audit logs of all administrative actions
Where this commonly fails
  • Administrative actions performed without dual control
  • Authorization records missing for key changes
  • Audit logs not retained for required duration

Logging and Monitoring

CO-18
Logging Is in Place to Enable Audit and Investigation of Key Management Activities

Comprehensive logging must be implemented for all key management activities, with logs protected from tampering and retained for sufficient time to support audit and investigation.

Artefacts an auditor will ask for
  • Logging configuration for HSMs and key management systems
  • Log retention policy
  • Tamper protection measures for logs
  • Log review procedures
Where this commonly fails
  • HSM logs not forwarded to SIEM
  • Log retention shorter than audit cycle
  • No defined process for log review

PCI PIN Security: Cybersecurity Controls

PCI-PIN-06
Network security and segmentation

Network security and segmentation. Control from PCI PIN Security framework, domain: PCI PIN Security: Cybersecurity Controls.

Artefacts an auditor will ask for
  • network diagram
  • encryption inventory
  • key management procedure
  • secure config standards
Where this commonly fails
  • scope creep
  • weak key rotation
  • default credentials
  • unmanaged endpoints
PCI-PIN-07
Endpoint protection and detection

Endpoint protection and detection. Control from PCI PIN Security framework, domain: PCI PIN Security: Cybersecurity Controls.

Artefacts an auditor will ask for
  • network diagram
  • encryption inventory
  • key management procedure
  • secure config standards
Where this commonly fails
  • scope creep
  • weak key rotation
  • default credentials
  • unmanaged endpoints
PCI-PIN-08
Application security controls

Application security controls. Control from PCI PIN Security framework, domain: PCI PIN Security: Cybersecurity Controls.

Artefacts an auditor will ask for
  • network diagram
  • encryption inventory
  • key management procedure
  • secure config standards
Where this commonly fails
  • scope creep
  • weak key rotation
  • default credentials
  • unmanaged endpoints
PCI-PIN-09
Encryption and key management

Encryption and key management. Control from PCI PIN Security framework, domain: PCI PIN Security: Cybersecurity Controls.

Artefacts an auditor will ask for
  • network diagram
  • encryption inventory
  • key management procedure
  • secure config standards
Where this commonly fails
  • scope creep
  • weak key rotation
  • default credentials
  • unmanaged endpoints
PCI-PIN-10
Secure configuration standards

Secure configuration standards. Control from PCI PIN Security framework, domain: PCI PIN Security: Cybersecurity Controls.

Artefacts an auditor will ask for
  • network diagram
  • encryption inventory
  • key management procedure
  • secure config standards
Where this commonly fails
  • scope creep
  • weak key rotation
  • default credentials
  • unmanaged endpoints

PCI PIN Security: Incident Management & Reporting

PCI-PIN-21
Incident detection and classification

Incident detection and classification. Control from PCI PIN Security framework, domain: PCI PIN Security: Incident Management & Reporting.

Artefacts an auditor will ask for
  • incident response plan
  • forensic readiness procedure
  • card brand notification template
  • post-incident review
Where this commonly fails
  • no card brand contact
  • untested IR
  • weak forensic preservation
  • late notifications
PCI-PIN-22
Incident response and containment

Incident response and containment. Control from PCI PIN Security framework, domain: PCI PIN Security: Incident Management & Reporting.

Artefacts an auditor will ask for
  • incident response plan
  • forensic readiness procedure
  • card brand notification template
  • post-incident review
Where this commonly fails
  • no card brand contact
  • untested IR
  • weak forensic preservation
  • late notifications
PCI-PIN-23
Regulatory reporting requirements

Regulatory reporting requirements. Control from PCI PIN Security framework, domain: PCI PIN Security: Incident Management & Reporting.

Artefacts an auditor will ask for
  • incident response plan
  • forensic readiness procedure
  • card brand notification template
  • post-incident review
Where this commonly fails
  • no card brand contact
  • untested IR
  • weak forensic preservation
  • late notifications
PCI-PIN-24
Customer notification procedures

Customer notification procedures. Control from PCI PIN Security framework, domain: PCI PIN Security: Incident Management & Reporting.

Artefacts an auditor will ask for
  • incident response plan
  • forensic readiness procedure
  • card brand notification template
  • post-incident review
Where this commonly fails
  • no card brand contact
  • untested IR
  • weak forensic preservation
  • late notifications
PCI-PIN-25
Post-incident review and improvement

Post-incident review and improvement. Control from PCI PIN Security framework, domain: PCI PIN Security: Incident Management & Reporting.

Artefacts an auditor will ask for
  • incident response plan
  • forensic readiness procedure
  • card brand notification template
  • post-incident review
Where this commonly fails
  • no card brand contact
  • untested IR
  • weak forensic preservation
  • late notifications

PCI PIN Security: Information Security Governance

PCI-PIN-04
Security policy framework

Security policy framework. Control from PCI PIN Security framework, domain: PCI PIN Security: Information Security Governance.

Artefacts an auditor will ask for
  • security charter
  • board reporting pack
  • risk register
  • policy library
Where this commonly fails
  • no executive sponsor
  • stale policies
  • undefined accountability
  • missing risk appetite
PCI-PIN-05
Roles and responsibilities definition

Roles and responsibilities definition. Control from PCI PIN Security framework, domain: PCI PIN Security: Information Security Governance.

Artefacts an auditor will ask for
  • security charter
  • board reporting pack
  • risk register
  • policy library
Where this commonly fails
  • no executive sponsor
  • stale policies
  • undefined accountability
  • missing risk appetite

PCI PIN Security: Operational Resilience

PCI-PIN-11
Business continuity planning and testing

Business continuity planning and testing. Control from PCI PIN Security framework, domain: PCI PIN Security: Operational Resilience.

Artefacts an auditor will ask for
  • BCP plan
  • DR test results
  • vendor dependency map
  • critical service list
Where this commonly fails
  • untested DR
  • single vendor dependency
  • no exit plan
  • missing comms tree
PCI-PIN-12
Disaster recovery procedures

Disaster recovery procedures. Control from PCI PIN Security framework, domain: PCI PIN Security: Operational Resilience.

Artefacts an auditor will ask for
  • BCP plan
  • DR test results
  • vendor dependency map
  • critical service list
Where this commonly fails
  • untested DR
  • single vendor dependency
  • no exit plan
  • missing comms tree
PCI-PIN-13
Third-party dependency management

Third-party dependency management. Control from PCI PIN Security framework, domain: PCI PIN Security: Operational Resilience.

Artefacts an auditor will ask for
  • BCP plan
  • DR test results
  • vendor dependency map
  • critical service list
Where this commonly fails
  • untested DR
  • single vendor dependency
  • no exit plan
  • missing comms tree
PCI-PIN-14
Critical service identification

Critical service identification. Control from PCI PIN Security framework, domain: PCI PIN Security: Operational Resilience.

Artefacts an auditor will ask for
  • BCP plan
  • DR test results
  • vendor dependency map
  • critical service list
Where this commonly fails
  • untested DR
  • single vendor dependency
  • no exit plan
  • missing comms tree
PCI-PIN-15
Communication and escalation procedures

Communication and escalation procedures. Control from PCI PIN Security framework, domain: PCI PIN Security: Operational Resilience.

Artefacts an auditor will ask for
  • BCP plan
  • DR test results
  • vendor dependency map
  • critical service list
Where this commonly fails
  • untested DR
  • single vendor dependency
  • no exit plan
  • missing comms tree

PCI PIN Security: Third-Party Risk Management

PCI-PIN-16
Due diligence and onboarding

Due diligence and onboarding. Control from PCI PIN Security framework, domain: PCI PIN Security: Third-Party Risk Management.

Artefacts an auditor will ask for
  • TPSP register
  • AOC collection log
  • contractual responsibility matrix
  • monitoring cadence
Where this commonly fails
  • missing AOCs
  • weak responsibility matrix
  • no ongoing monitoring
  • expired attestations
PCI-PIN-17
Contractual security requirements

Contractual security requirements. Control from PCI PIN Security framework, domain: PCI PIN Security: Third-Party Risk Management.

Artefacts an auditor will ask for
  • TPSP register
  • AOC collection log
  • contractual responsibility matrix
  • monitoring cadence
Where this commonly fails
  • missing AOCs
  • weak responsibility matrix
  • no ongoing monitoring
  • expired attestations
PCI-PIN-18
Ongoing monitoring and assessment

Ongoing monitoring and assessment. Control from PCI PIN Security framework, domain: PCI PIN Security: Third-Party Risk Management.

Artefacts an auditor will ask for
  • TPSP register
  • AOC collection log
  • contractual responsibility matrix
  • monitoring cadence
Where this commonly fails
  • missing AOCs
  • weak responsibility matrix
  • no ongoing monitoring
  • expired attestations
PCI-PIN-19
Concentration risk management

Concentration risk management. Control from PCI PIN Security framework, domain: PCI PIN Security: Third-Party Risk Management.

Artefacts an auditor will ask for
  • TPSP register
  • AOC collection log
  • contractual responsibility matrix
  • monitoring cadence
Where this commonly fails
  • missing AOCs
  • weak responsibility matrix
  • no ongoing monitoring
  • expired attestations
PCI-PIN-20
Exit strategy and transition planning

Exit strategy and transition planning. Control from PCI PIN Security framework, domain: PCI PIN Security: Third-Party Risk Management.

Artefacts an auditor will ask for
  • TPSP register
  • AOC collection log
  • contractual responsibility matrix
  • monitoring cadence
Where this commonly fails
  • missing AOCs
  • weak responsibility matrix
  • no ongoing monitoring
  • expired attestations

Physical Security

CO-3
POIs and HSMs Are Protected From Unauthorized Access

POI devices and HSMs must be physically protected from unauthorized access throughout their lifecycle, including during storage, transit, deployment, and active operation.

Artefacts an auditor will ask for
  • Documented secure storage procedures
  • Chain-of-custody records for devices in transit
  • Tamper-evident packaging procedures
  • Inspection records for deployed devices
Where this commonly fails
  • Devices stored in unlocked areas before deployment
  • Chain of custody missing intermediate handlers
  • Tamper-evident seals applied inconsistently
CO-4
Procedures Exist to Protect Devices From Tampering and Substitution

Documented procedures must exist to protect POI devices and HSMs from substitution and tampering during deployment and operation, including periodic inspection and incident response.

Artefacts an auditor will ask for
  • Periodic device inspection procedures and records
  • Photographic baselines of authorized device appearance
  • Substitution detection mechanisms (serial number verification)
  • Tamper response and incident escalation procedures
Where this commonly fails
  • Inspection cadence not defined for unattended terminals
  • No baseline images for staff to compare against
  • Incident response unclear on isolating suspect devices

Risk Management

CO-19
Organizations Implement and Document Risk-Mitigation Practices

Organizations must implement and document risk-mitigation practices appropriate for their PIN and key processing environment, including risk assessments, security policies, and incident response plans.

Artefacts an auditor will ask for
  • Documented risk assessments specific to PIN and key processing
  • Approved information security policies
  • Incident response plans with PIN compromise scenarios
  • Records of plan testing and updates
Where this commonly fails
  • Risk assessments not refreshed annually
  • Policies generic and not specific to PIN environment
  • Incident response plans not tested through tabletop exercises
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the PCI PIN Security framework page.