PCI Card Production and Provisioning
PCI SSC's physical- and logical-security requirements for card production and provisioning facilities (two companion documents under one program).
v3.0 · PCI Security Standards Council — Card Production and Provisioning · published 2022-01-13
00Answer
01Standing
Authority and version facts, with a parsed public catalog when available; no tenant blueprint or executable evidence method is activated.
PCI Card Production and Provisioning is tracked in the registry — authority, version ledger, verification — and nothing else is modelled for it yet. Import its catalog to begin.
Freely downloadable from PCI SSC; PCI SSC's terms permit identifiers and structure, not verbatim requirement text, without a separate license.
02Registry record
- Registry status
- Planned · namedTracked metadata: we name the regime and monitor its issuing authority. No control or requirement model is implemented.
- Control units
- Not on record — no catalog ingested and no authority-published count cited.
- Control families
- Physical security · Logical security · Personnel management · Data and key management
- Applies to
- payments · card issuers · global
- Verification
- Secondary — corroborated across independent sources; the authority blocks automated fetch or does not state it plainly. checked 2026-09-06
- Pending change
- A combined v3.0.1 draft was in RFC from 2026-02-13 to 2026-03-16; it has not yet been finalized or published.Expected: v3.0.1 draft not yet finalized
03Version ledger
| v3.0 | Current edition | 2022-01-13 |
06Related frameworks
Also applies to payments · PCI SSC's security requirements for 3-D Secure environments (issuer/ACS, 3DS Server, and DS components) that support cardholder authentication.
- PCI DSSv4.0.1
Also applies to payments · The cardholder-data standard every merchant and service provider that touches payment card data is measured against. v4.0 retired 2024-12-31; the 51 future-dated v4.x requirements became mandatory 2025-03-31.
Also applies to payments · PCI SSC's requirements for the secure management, processing, and transmission of personal identification number (PIN) data during payment transactions.
Also applies to payments · PCI SSC's standard for accepting contactless card payments on a commercial off-the-shelf mobile device without a separate secure card reader. In its formal sunset window now, with MPoC as the designated successor.