Skip to main content
Framework library
Framework module · pci-card-production-3-0

PCI Card Production and Provisioning

PCI SSC's physical- and logical-security requirements for card production and provisioning facilities (two companion documents under one program).

v3.0 · PCI Security Standards Council — Card Production and Provisioning · published 2022-01-13

Standing today
Directory entry

00Answer

from the registry record
What is PCI Card Production and Provisioning?
PCI SSC's physical- and logical-security requirements for card production and provisioning facilities (two companion documents under one program).
Who does PCI Card Production and Provisioning apply to?
PCI Card Production and Provisioning applies to payments, card issuers, global, per PCI Security Standards Council — Card Production and Provisioning.
What is the current version of PCI Card Production and Provisioning?
The current edition is v3.0, issued by PCI Security Standards Council — Card Production and Provisioning and published 2022-01-13. Source: https://www.pcisecuritystandards.org/standards/card-production/.
What does an assessment under PCI Card Production and Provisioning require?
No control catalog has been ingested for PCI Card Production and Provisioning yet — the registry tracks it as planned (Tracked metadata: we name the regime and monitor its issuing authority. No control or requirement model is implemented), so an assessment under this framework currently requires the authority's own catalog rather than a ControlFrame-parsed one.

01Standing

Directory entry

Authority and version facts, with a parsed public catalog when available; no tenant blueprint or executable evidence method is activated.

PCI Card Production and Provisioning is tracked in the registry — authority, version ledger, verification — and nothing else is modelled for it yet. Import its catalog to begin.

Freely downloadable from PCI SSC; PCI SSC's terms permit identifiers and structure, not verbatim requirement text, without a separate license.

02Registry record

checked 2026-09-06
Registry status
Planned · namedTracked metadata: we name the regime and monitor its issuing authority. No control or requirement model is implemented.
Control units
Not on record — no catalog ingested and no authority-published count cited.
Control families
Physical security · Logical security · Personnel management · Data and key management
Applies to
payments · card issuers · global
Verification
Secondary — corroborated across independent sources; the authority blocks automated fetch or does not state it plainly. checked 2026-09-06
Pending change
A combined v3.0.1 draft was in RFC from 2026-02-13 to 2026-03-16; it has not yet been finalized or published.Expected: v3.0.1 draft not yet finalized

03Version ledger

1 edition
v3.0Current edition2022-01-13

06Related frameworks

scored from registry facts
  1. Also applies to payments · PCI SSC's security requirements for 3-D Secure environments (issuer/ACS, 3DS Server, and DS components) that support cardholder authentication.

  2. PCI DSSv4.0.1

    Also applies to payments · The cardholder-data standard every merchant and service provider that touches payment card data is measured against. v4.0 retired 2024-12-31; the 51 future-dated v4.x requirements became mandatory 2025-03-31.

  3. Also applies to payments · PCI SSC's requirements for the secure management, processing, and transmission of personal identification number (PIN) data during payment transactions.

  4. Also applies to payments · PCI SSC's standard for accepting contactless card payments on a commercial off-the-shelf mobile device without a separate secure card reader. In its formal sunset window now, with MPoC as the designated successor.

PCI Card Production and Provisioning | ControlFrame