Skip to content

Certificate Pinning

What is Certificate Pinning?

A security technique that associates a host with its expected public key or certificate, preventing man-in-the-middle attacks by rejecting certificates that do not match the pinned values.

Information Security

Each of these is named in at least one of the same controls as certificate pinning. The number is how many controls name both.

What the standards actually require on certificate pinning

Requirements naming certificate pinning across 4 standards, quoted from the control text.

GLI-33 geolocation + mobile + internet wagering security. GEOLOCATION VERIFICATION: in regulated jurisdictions (US states + provinces) wager acceptance must be CONTINUOUSLY GEO-VERIFIED to ensure player is physically within authorized boundary;

GLI33-Geolocation-Mobile-Internet-Wagering · GLI-33 Geolocation Verification, Mobile and Internet Wagering Security, Session Management

GS1 DATA SECURITY + INTEGRITY in supply chain data exchange. KEY PRINCIPLES: (1) DATA INTEGRITY - master data + EPCIS events + GDSN exchanges must be ACCURATE + COMPLETE + TIMELY + reflect true state of supply chain;

GS1-DataSecurity-Integrity-AccessControl · GS1 Data Security and Integrity in Exchange, Access Control and Tamper Evidence

HL7 FHIR Transport Security. TRANSPORT LAYER SECURITY (TLS) - all FHIR APIs MUST use TLS 1.2+ for production + TLS 1.3 recommended; certificate validation + trust chain + certificate pinning where appropriate + HSTS + secure session establishment + cipher suit...

HL7-FHIR-Transport-TLS-Communication · HL7 FHIR Transport Security - TLS 1.2+, Communication Security, Time Keeping, Server CapabilityStatement
OWASP MASVS1 control

Per OWASP MASVS v2 MASVS-NETWORK: secure network communication for mobile apps. Requirements include (a) use TLS 1.2 or later with strong cipher suites for all sensitive network communications + (b) implement certificate pinning where appropriate + with secure...

OWASPMASVS-4 · MASVS-NETWORK: Network Communication

Questions people ask about certificate pinning

What is Certificate Pinning?
A security technique that associates a host with its expected public key or certificate, preventing man-in-the-middle attacks by rejecting certificates that do not match the pinned values.
Why is Certificate Pinning important for compliance?
Certificate Pinning is a key concept in Information Security. Understanding certificate pinning helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Certificate Pinning?
Certificate Pinning appears in the requirement text of GLI-33 - Gaming Laboratories International Event Wagering Systems, GS1 Global Standards - Supply Chain Traceability and Data Security, HL7 FHIR Security Framework, OWASP MASVS. Across these standards we have identified 4 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Certificate Pinning?
Explore our compliance framework pages to see how certificate pinning applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Certificate Pinning applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.