Independent research & analysis on payment security Search
paymentsecuritypros.com Payment Security Insights
Regulations & Standards

Beyond PCI DSS: A Map of the PCI Standards Family (PTS, P2PE, SSF, PIN, MPoC)

Say “PCI compliance” and nearly everyone hears “PCI DSS.” Understandable — the Data Security Standard is the one merchants are contractually measured against. But the PCI Security Standards Council maintains a whole family of PCI standards, each securing a different link in the payment chain: the terminal hardware, the encryption pipeline, the payment software, the PIN, and the phone that now doubles as a card reader. Knowing which standard binds whom saves real money — merchants routinely try to solve problems the ecosystem has already solved for them, and vendors routinely wave the wrong certificate as proof of the wrong thing.

Quick answer: PCI DSS secures the environments that store, process, or transmit cardholder data. Around it sit sibling standards: PTS (terminal hardware), P2PE (encryption solutions), the Secure Software Framework (payment applications), PIN Security (PIN handling), MPoC (phones as terminals), and 3DS Core (authentication infrastructure). Merchants comply with DSS; most other standards bind vendors and providers — but merchants must verify their vendors hold them.

Who is the PCI Security Standards Council?

The PCI SSC was founded in 2006 by the major card brands to unify their separate security programs. The Council writes and maintains the standards, trains and qualifies assessors, and publishes lists of validated devices, software, and solutions. It does not enforce anything: enforcement flows through the card brands and acquirers via contract. That division explains a common confusion — the Council can tell you what “good” looks like, but your acquirer decides what happens if you fall short.

What are the main PCI standards and who do they apply to?

PCI DSS — the environment standard

The one this site covers most: 12 requirement families applying to any entity that stores, processes, or transmits cardholder data, or could affect its security. Merchants, processors, gateways, and service providers all live here. If you are still getting oriented, start with our overview of what PCI DSS 4.0 means for your business.

PCI PTS — the terminal hardware standard

PIN Transaction Security covers the physical devices that accept cards: PIN pads, countertop terminals, unattended readers. PTS approval means the device resists tampering, protects keys in dedicated secure hardware, and — under the SRED module — can encrypt account data at the moment of capture. Who it binds: device manufacturers. What merchants do: buy devices that appear on the PTS approved list, and check the exact model and firmware version, because approvals expire and are version-specific.

PCI P2PE — the encryption solution standard

P2PE assesses an entire encryption pipeline — PTS/SRED terminals, key injection, chain of custody, and the provider’s decryption environment — as a single validated solution. Its payoff is dramatic merchant scope reduction, which we cover in depth in our guide to point-to-point encryption and PCI scope. Who it binds: solution providers. What merchants do: choose a listed solution and follow its instruction manual.

PCI Secure Software Framework (SSF) — the software standard

The SSF replaced the old PA-DSS program, which formally retired in 2022. It has two parts: the Secure Software Standard, which validates payment software itself, and the Secure SLC Standard, which validates a vendor’s software lifecycle — its ability to develop and maintain secure software continuously rather than freeze one assessed version. This shift mirrors the industry’s move from point-in-time certification toward continuous assurance. Who it binds: software vendors. What merchants do: prefer validated software, and treat a vendor’s Secure SLC qualification as a strong signal of engineering maturity.

PCI PIN Security — the PIN standard

A dedicated standard for how PINs are encrypted, translated between network zones, and managed — including the key ceremonies and hardware security modules behind them. It applies to entities that process PINs: acquirers, processors, and key-injection facilities, not typical merchants. The cardholder-facing consequences are covered in our companion piece on how PIN security works end to end.

PCI MPoC — the phone-as-terminal standard

Mobile Payments on COTS (commercial off-the-shelf) governs SoftPOS: accepting contactless payments on ordinary smartphones. It consolidated the earlier SPoC and CPoC pilots into one standard covering software-based capture, optional PIN entry on the phone’s own screen, attestation, and continuous back-end monitoring. It is the reason a merchant’s unmodified phone can now legitimately do a job that once required tamper-resistant hardware. Who it binds: MPoC solution vendors. What merchants do: use listed solutions — more in our dedicated article on SoftPOS security.

PCI 3DS Core — the authentication infrastructure standard

Separate from the EMV 3-D Secure protocol itself (an EMVCo specification), PCI 3DS Core secures the server components that run it — access control servers, directory servers, and 3DS server environments. Who it binds: 3DS infrastructure operators. Merchants meet 3-D Secure as a product feature; our guide to implementing 3-D Secure 2 without killing conversions covers that side.

Supporting programs

Two adjacent pieces complete the picture: the Token Service Provider security requirements for entities issuing EMV payment tokens, and the Card Production standards for facilities that physically manufacture and personalize cards. Both operate far upstream of merchants but explain who guards the parts of the system merchants never see.

Which PCI standards apply to me?

If you are a… You are directly bound by You should verify vendors against
Merchant (any size) PCI DSS PTS (terminals), P2PE (encryption solution), SSF (payment software), MPoC (SoftPOS app)
E-commerce-only merchant PCI DSS (often via SAQ) Your gateway/PSP’s DSS attestation; their 3DS provider’s PCI 3DS compliance
Payment software vendor Secure Software Standard / Secure SLC Component and library provenance
Processor / acquirer PCI DSS, PIN Security, often 3DS Core PTS, key-injection facilities, TSPs
SoftPOS provider MPoC, PCI DSS Attestation and monitoring components

Why the map matters in practice

  • Vendor claims become checkable. “We’re PCI certified” is meaningless until you ask which standard, which listing, which version. Every validated device, solution, and application appears on a public PCI SSC list — verifying takes minutes.
  • Responsibilities stop overlapping — or gaping. The terminal maker secures the hardware (PTS); the solution provider secures the pipeline (P2PE); you secure your environment (DSS). Breaches happen in the seams, which is why your DSS obligations include managing those third parties — a topic big enough that we cover third-party service provider risk in its own guide.
  • You stop over-building. Merchants have attempted to design their own PIN-handling controls or software vetting schemes for problems PTS and the SSF already solve. Buy validated; verify the listing; spend your effort on the parts only you can secure.

Frequently asked questions

Is PA-DSS still valid?

No. PA-DSS was retired in October 2022 and replaced by the Secure Software Framework. Software still marketed on a PA-DSS certificate alone is running on an expired credential.

Does using PTS-approved terminals make me PCI DSS compliant?

No. Approved hardware satisfies one slice of your obligations. Your environment, processes, and people remain assessed under PCI DSS.

Where do I check whether a device or solution is really validated?

The PCI SSC website maintains searchable public listings for approved PTS devices, validated P2PE solutions, validated payment software, and MPoC solutions. Match the exact model, version, and expiry.

Is EMV a PCI standard?

No — EMV specifications come from EMVCo, a separate body owned by the card brands. The two families interlock (PCI 3DS Core secures EMV 3DS infrastructure, for example) but are governed independently. Our explainer on how EMV chip cards stop counterfeit fraud covers the EMV side.

Do these standards apply outside the US?

Yes. PCI standards are global, applying wherever the participating card brands’ cards are accepted.

The pattern across the whole family is consistent: push each security problem to the party best equipped to solve it, validate their work publicly, and leave merchants a shorter list. The rest of this site is largely about executing that shorter list well.

A

abhilash@spacemen.in

Writes about payment security, compliance, and fraud prevention for Payment Security Pros.

Leave a Reply

Your email address will not be published. Required fields are marked *