PCI 3DS Core Security Standard
PCI SSC's security requirements for 3-D Secure environments (issuer/ACS, 3DS Server, and DS components) that support cardholder authentication.
v1.0 · PCI Security Standards Council — 3DS Core · published 2017-10-01
00Answer
01Standing
Authority and version facts, with a parsed public catalog when available; no tenant blueprint or executable evidence method is activated.
PCI 3DS Core Security Standard is tracked in the registry — authority, version ledger, verification — and nothing else is modelled for it yet. Import its catalog to begin.
Freely downloadable from PCI SSC; PCI SSC's terms permit identifiers and structure, not verbatim requirement text, without a separate license.
02Registry record
- Registry status
- Planned · namedTracked metadata: we name the regime and monitor its issuing authority. No control or requirement model is implemented.
- Control units
- Not on record — no catalog ingested and no authority-published count cited.
- Control families
- 3DS environment security · Cryptography and key management · Access control · Physical security
- Applies to
- payments · global
- Verification
- Secondary — corroborated across independent sources; the authority blocks automated fetch or does not state it plainly. checked 2026-09-06
- Pending change
- A v2.0 revision has been under discussion for years with no publication date announced; v1.0 remains the current, effective standard.Expected: Unannounced
03Version ledger
| v1.0 | Current edition | 2017-10-01 |
06Related frameworks
- PCI DSSv4.0.1
Also applies to payments · The cardholder-data standard every merchant and service provider that touches payment card data is measured against. v4.0 retired 2024-12-31; the 51 future-dated v4.x requirements became mandatory 2025-03-31.
Also applies to payments · PCI SSC's physical- and logical-security requirements for card production and provisioning facilities (two companion documents under one program).
Also applies to payments · PCI SSC's standard for validated point-to-point encryption solutions that can reduce a merchant's PCI DSS scope. Part of the payments family beyond bare PCI DSS.
Also applies to payments · PCI SSC's standard for accepting contactless card payments on a commercial off-the-shelf mobile device without a separate secure card reader. In its formal sunset window now, with MPoC as the designated successor.