- Key Takeaways
- What is PCI DSS?
- What is PCI DSS v4.0?
- PCI DSS 4.0 Implementation Timeline
- Getting Ready for Post-Quantum Cryptography (PQC) With PCI DSS 4.0
- Defined Approach by PCI DSS 4.0 for Cryptographic Cipher Suites and Protocols Requirements (12.3.3)
- Testing Procedure (12.3.3)
- Why Is Planning for Post-Quantum Cryptography (PQC) Important?
- Industry Trends
- Conclusion
- Frequently Asked Questions
Quick answer: PCI DSS 4.0 requirement 12.3.3 makes cryptographic agility a compliance obligation, not just best practice, requiring organizations to maintain an up-to-date inventory of every cryptographic cipher suite and protocol in use, actively monitor industry viability trends, and document a strategy for responding to anticipated cryptographic vulnerabilities, including the quantum threat. It matters because this requirement became mandatory on March 31, 2025, and NIST finalized ML-KEM (FIPS 203), ML-DSA (FIPS 204), and SLH-DSA (FIPS 205) on August 13, 2024, giving organizations concrete standards to build a PQC migration plan around rather than waiting for a future standardization event. The recommended action is to treat your PQC migration plan as the documented evidence PCI DSS 4.0 requires for requirement 12.3.3, built on a current cryptographic inventory and reviewed at least annually.
Key Takeaways
- PCI DSS 4.0 requirement 12.3.3 became mandatory on March 31, 2025, requiring a documented cryptographic inventory, annual review, active viability monitoring, and a documented response strategy for cryptographic vulnerabilities.
- NIST finalized ML-KEM (FIPS 203), ML-DSA (FIPS 204), and SLH-DSA (FIPS 205) on August 13, 2024, giving organizations concrete standards to plan migrations around rather than waiting for standardization to complete.
- NSM-10 directs federal agencies to develop a PQC migration plan within one year of NIST’s standards release, with milestones demonstrating completion by 2035.
- A PQC migration plan doubles as the documented evidence PCI DSS 4.0 requires for the “anticipated changes in cryptographic vulnerabilities” component of requirement 12.3.3, though other cryptographic vulnerabilities beyond quantum risk still need separate mitigation plans.
- PCI DSS 4.0 effectively operationalizes crypto-agility as a compliance requirement, not just a best practice, for any organization handling cardholder data.
What is PCI DSS?
PCI DSS stands for Payment Card Industry Data Security Standard. It’s a set of security standards to ensure that all companies that accept, process, store, or transmit credit card information maintain a secure environment. This standard was created to protect sensitive payment card data, such as credit card numbers, from theft and fraud.
The Payment Card Industry Data Security Standard (PCI DSS) is a collection of security protocols established in 2004 through collaboration between Visa, MasterCard, Discover Financial Services, JCB International, and American Express. Regulated by the Payment Card Industry Security Standards Council (PCI SSC), this compliance framework is designed to safeguard credit and debit card transactions from unauthorized access, data breaches, and fraudulent activities.
What is PCI DSS v4.0?
PCI DSS v4.0 is the next evolution of the Payment Card Industry Data Security Standard (PCI DSS). With the new iteration, below are the high-level goals outlined by the PCI Standards Security Council for PCI v4.0
- Continue to meet the security needs of the payment industry
- Promote card-holder security as a continuous process.
- Add flexibility and support of other methodologies to enhance payment security approaches.
- Enhanced validation methods and procedures to streamline the compliance process.
Additionally, the following technical areas are considered for potential adjustments within PCI DSS 4.0:
- Authentication protocols and password recommendations.
- Enhanced system monitoring criteria.
- Guidance on the implementation of multi-factor authentication measures.
Learn more about PCI DSS 4.0 requirements here
PCI DSS 4.0 Implementation Timeline
Here is what you need to get up to speed with PCI DSS 4.0.
PCI DSS 4.0 Release
PCI DSS 3.2.1 retired. Best practices requirements 4.0
PCI DSS 4.0 best practices requirements mandatory
Getting Ready for Post-Quantum Cryptography (PQC) With PCI DSS 4.0
The white house published the “National Security Memorandum on Promoting United States Leadership in Quantum Computing While Mitigating Risks to Vulnerable Cryptographic Systems,” also known as NSM-10. NSM-10 extensively discusses reducing the risks that quantum computers might bring to encryption. It outlines various steps federal agencies must follow now that the National Institute of Standards and Technology (NIST) has finalized its first three post-quantum cryptography (PQC) standards: ML-KEM (FIPS 203), ML-DSA (FIPS 204), and SLH-DSA (FIPS 205), published on August 13, 2024.
The timeline for formal adoption of NSM-10 for private sectors is not fixed by regulation. However, organizations subject to PCI DSS compliance already have the requirement spelled out in 12.3.3. That requirement, optional as a best practice since PCI DSS 4.0’s March 2022 release, became mandatory for all applicable organizations on March 31, 2025.
Defined Approach by PCI DSS 4.0 for Cryptographic Cipher Suites and Protocols Requirements (12.3.3)
Cryptographic cipher suites and protocols in use are documented and reviewed at least once every 12 months, including at least the following:
- An up-to-date inventory of all cryptographic cipher suites and protocols, including the purpose and where used.
- Active monitoring of industry trends regarding the continued viability of all cryptographic cipher suites and protocols.
- A documented strategy to respond to anticipated changes in cryptographic vulnerabilities.
Testing Procedure (12.3.3)
Examine documentation for cryptographic suites and protocols in use, interview personnel to verify the documentation, and review it to ensure that it meets all elements specified in the PCI DSS 4.0 requirement.
Why Is Planning for Post-Quantum Cryptography (PQC) Important?
Protocols and encryption strengths may quickly change or be deprecated due to identifying vulnerabilities or design flaws. To support current and future data security needs, entities need to know where cryptography is used and understand how they would be able to respond rapidly to changes impacting the strength of their cryptographic implementations.
Organizations must understand and prepare accordingly for the transition to PQC. This involves assessing their current cryptographic infrastructure, identifying potential vulnerabilities, and planning to adopt new encryption methods. By doing so, organizations can mitigate the risks associated with outdated encryption techniques and ensure the security of sensitive data, particularly cardholder information.
Moreover, aligning cryptographic strategies with PCI DSS 4.0 requirements is essential for maintaining compliance and protecting payment card data. This includes implementing robust encryption protocols, adhering to security best practices, and staying informed about regulatory updates.
NSM-10 directed agencies to develop a migration plan to transition to Post-Quantum Cryptography (PQC) within one year of NIST’s standards release. That plan should include milestones demonstrating the completion of the migration by 2035.
Such a plan will serve as evidence for the final component of requirement 12.3.3: “A documented strategy to respond to anticipated changes in cryptographic vulnerabilities.” While the PQC migration plan addresses vulnerabilities in cryptography susceptible to exploitation by quantum computers, other potential cryptographic vulnerabilities must also be analyzed. Corresponding mitigation plans must be documented to ensure full compliance with requirement 12.3.3. Implementing PQC should be part of the data protection strategy for any organization that leverages cryptography.
Industry Trends
Monitoring the key Events and requirements for Transition to Post-Quantum Cryptography (PQC) and PCI DSS 4.0 Compliance:
| Event Description | Schedule/Requirements |
|---|---|
| NIST finalizes new standards for PQC | August 13, 2024 |
| Proposal of deprecation of quantum vulnerable ciphers timeline by Secretary of Commerce | 90-days post NIST release |
| Review and adjustment of the above deprecation timeline | Annually |
| Industry monitoring of results of deprecated ciphers | Continuous monitoring required |
| Monitoring of cryptographic cipher viability | Ongoing assessment |
| Documentation of Monitoring Procedures and Results | The documented procedure with conclusions |
| Support for PCI DSS 4.0 Compliance | Required evidence for compliance |
| Action Plan for NIST Deprecations | Adds to PCI compliance evidence |
Conclusion
Implementing PCI DSS 4.0 is crucial for organizations to prepare for the shift to quantum-safe cryptography. As cybersecurity threats evolve, businesses must update their security strategies to address emerging risks effectively. By adhering to PCI DSS 4.0 guidelines and staying informed about industry developments, organizations can proactively safeguard sensitive data, even in the face of advancements in quantum computing.
This proactive approach strengthens security measures and builds trust among stakeholders in an increasingly digital landscape. Maintaining vigilance and readiness will be key to protecting against evolving threats and ensuring the ongoing security of payment card data.
In summary, the PCI DSS 4.0 requirement 12.3.3 asks organizations for:
- A documented strategy to respond to anticipated changes in cryptographic vulnerabilities.
- Yearly documentation and review of the cryptography in use.
- An up-to-date inventory of cryptography, including the purpose and where used.
- Active monitoring of the viability of cryptography in use.
Overall, PCI DSS 4.0 considers cryptography management and crypto agility best practices for responding quickly to future developments in cryptographic protocol vulnerabilities.
Frequently Asked Questions
What does PCI DSS 4.0 requirement 12.3.3 actually require?
Organizations must document and review, at least once every 12 months, an up-to-date inventory of all cryptographic cipher suites and protocols in use (including purpose and location), maintain active monitoring of industry trends regarding the continued viability of those cipher suites and protocols, and keep a documented strategy for responding to anticipated changes in cryptographic vulnerabilities.
When did PCI DSS 4.0 requirement 12.3.3 become mandatory?
PCI DSS 4.0 was released on March 31, 2022, with the older 3.2.1 version retired on March 31, 2024. Requirement 12.3.3, like other new PCI DSS 4.0 requirements, was treated as a best practice during a transition window and became mandatory for all applicable organizations on March 31, 2025.
How does a PQC migration plan help satisfy PCI DSS 4.0 requirement 12.3.3?
A PQC migration plan serves as documented evidence for the “anticipated changes in cryptographic vulnerabilities” component of 12.3.3, since it directly addresses the migration away from quantum-vulnerable algorithms. However, it doesn’t cover the full requirement on its own: other potential cryptographic vulnerabilities unrelated to quantum computing must also be analyzed and have corresponding mitigation plans documented.
Which NIST post-quantum standards should organizations reference when building this plan?
ML-KEM (FIPS 203) for key encapsulation, ML-DSA (FIPS 204) for digital signatures, and SLH-DSA (FIPS 205) as a hash-based signature alternative, all finalized by NIST on August 13, 2024. These are concrete, standardized targets rather than a moving standardization process still in progress.
What does NSM-10 direct federal agencies to do, and does it apply to private companies?
NSM-10 directs federal agencies to develop a migration plan to transition to post-quantum cryptography within one year of NIST’s standards release, with milestones demonstrating completion by 2035. It does not carry a fixed formal adoption timeline for private-sector organizations, but PCI DSS 4.0’s requirement 12.3.3 already imposes an equivalent documented-strategy obligation on any organization handling cardholder data.
What is the first step toward meeting requirement 12.3.3?
Building the up-to-date cryptographic inventory the requirement calls for: every cipher suite and protocol in use, its purpose, and where it’s deployed. This inventory is the foundation for the annual review, ongoing viability monitoring, and vulnerability response strategy that make up the rest of the requirement.
- Key Takeaways
- What is PCI DSS?
- What is PCI DSS v4.0?
- PCI DSS 4.0 Implementation Timeline
- Getting Ready for Post-Quantum Cryptography (PQC) With PCI DSS 4.0
- Defined Approach by PCI DSS 4.0 for Cryptographic Cipher Suites and Protocols Requirements (12.3.3)
- Testing Procedure (12.3.3)
- Why Is Planning for Post-Quantum Cryptography (PQC) Important?
- Industry Trends
- Conclusion
- Frequently Asked Questions
