PCI DSS: Requirement 3 – Explained

PCI DSS (Payment Card Industry Data Security Standard) is a set of security standards designed to ensure that all companies that process, store, or transmit credit card information maintain a secure environment. This article focuses on Requirement 3 of PCI DSS v4.0.1, covering what it entails, how it has evolved from v3.2.1, and what your organisation needs to do to stay compliant. 

For more on PCI DSS, see our Ultimate Guide. 

What is PCI DSS Requirement 3?

Requirement 3: Protect Stored Account Data 

Requirement 3 focuses on protecting stored account data by limiting data retention and applying strong safeguards where storage is necessary. Organisations must only store cardholder data when absolutely required for legal, regulatory, or business reasons, and must render it unreadable using strong encryption or masking. Access to this data must be tightly controlled, and encryption keys must be securely managed. Crucially, sensitive authentication data – such as CVV codes, full track data, or PINs – must never be stored after authorisation, even if encrypted. 

By enforcing strict controls around data storage, organisations can reduce the impact of a potential breach and limit the value of any data compromised. 

Why is Requirement 3 Important?

Requirement 3 is essential because stored cardholder data is a high-value target for attackers. If data is retained unnecessarily, stored insecurely, or left accessible to unauthorised users, it increases the likelihood and potential impact of a breach. Even with other protections in place, failing to properly secure stored data can undermine the entire security posture. This requirement ensures that sensitive information is minimised, protected, and tightly controlled throughout its lifecycle. 

Key Changes in PCI DSS v4.0.1 for Requirement 3

PCI DSS v4.0.1 introduces several updates to enhance data protection: 

  1. Targeted Risk Analysis for Pre-Authorisation SAD Storage
    Organisations must perform a formal risk analysis to justify the storage of SAD before authorisation.
  2. Quarterly Reviews of Stored Data
    Entities are now required to conduct quarterly reviews of all stored cardholder data to verify the necessity of its retention.
  3. Remote Access Controls (Requirement 3.4.2)
    Technical controls must be in place to prevent the copying or relocation of PAN during remote access sessions, unless explicitly authorised for a defined business need.
  4. Keyed Cryptographic Hashing (Requirement 3.5.1.1)
    When hashing is used to render PAN unreadable, it must be a keyed cryptographic hash (e.g., HMAC).
  5. Limitations on Disk-Level Encryption (Requirement 3.5.1.2)
    Disk-level or partition-level encryption is acceptable only for removable media. For non-removable media, additional mechanisms like truncation or tokenisation must be employed to render PAN unreadable.
  6. Detailed Cryptographic Architecture Documentation (Requirement 3.6.1.1)
    Service providers must document their cryptographic architecture, including key lengths, key rotation, algorithm types, and separation of environments.

A Breakdown of Requirement 3

3.1 – Processes and mechanisms for protecting stored account data are defined and understood.

Organisations must define and document the processes and mechanisms used to protect stored account data. This includes assigning roles and responsibilities, understanding where and how account data is stored, and establishing the safeguards that protect that data. These processes must be communicated and consistently followed to maintain compliance and reduce the risk of data compromise. 

3.2 – Storage of account data is kept to a minimum.

Cardholder data must only be stored when absolutely necessary and for the shortest time possible. Organisations must implement policies and processes to ensure storage is limited to essential data, retained only as long as needed for legal, regulatory, or business requirements. Secure deletion methods must be used to remove data that is no longer required. 

3.3 – Sensitive authentication data (SAD) is not stored after authorisation.

Sensitive authentication data, including full track data, CVV/CVC, and PINs or PIN blocks, must not be stored after authorisation, even if encrypted. This applies across all environments including logs and backups. Any temporary storage must be strictly justified, limited in duration, and appropriately protected. Storing SAD post-authorisation is strictly prohibited and considered a serious violation. 

3.4 – Access to displays of full PAN and ability to copy PAN are restricted.

Access to full Primary Account Numbers (PANs) must be limited to only those with a documented and legitimate business need. Where PANs are displayed, they must be masked so only the minimum necessary digits are visible, typically the first six and last four. Controls must also prevent copying, storing, or sending full PANs unless specifically authorised. 

3.5 – Primary account number (PAN) is secured wherever it is stored.

Stored PANs must be rendered unreadable using strong cryptography, such as encryption, truncation, tokenisation, or keyed cryptographic hashing. The chosen method must meet defined criteria for effectiveness. Disk-level encryption is not sufficient unless used on removable media. These measures help ensure data remains protected even if accessed without authorisation. 

3.6 – Cryptographic keys used to protect stored account data are secured.

Cryptographic keys must be securely stored and protected to maintain the integrity of encrypted data. This involves using secure storage mechanisms such as HSMs, key encryption keys, or equivalent methods, and implementing strict access controls. Keys must never be stored in plaintext and must be protected against unauthorised substitution or disclosure. 

3.7 – Where cryptography is used to protect stored account data, key management processes and procedures covering all aspects of the key lifecycle are defined and implemented.

Effective key management is essential to the security of encrypted data. Organisations must define and implement policies and procedures that cover the full lifecycle of cryptographic keys, from creation through to retirement or destruction. Keys must be protected against disclosure and misuse, securely changed when compromised, and retired at the end of their defined cryptoperiod. Any keys that are no longer needed, or have been weakened or compromised, must be securely archived or destroyed. 

Manual key-management operations, where performed, must use dual control and split knowledge to prevent a single person from having full access to a cleartext key. Controls must also prevent the unauthorised substitution of cryptographic keys. All key custodians must acknowledge their responsibilities formally, and service providers that share cryptographic keys with customers must provide secure handling guidance. These requirements help ensure cryptographic systems remain trustworthy and effective throughout their use. 

Common Challenges with Requirement 3

While the principles of Requirement 3 may seem straightforward, organisations often encounter challenges such as: 

  • Legacy Systems & Shadow Data: Older systems or poorly mapped networks may retain cardholder data unnecessarily, leading to undetected ‘shadow’ storage.
  • Ineffective Encryption or Hashes: Using outdated encryption algorithms or non-keyed hashes can result in non-compliance, even if the data appears protected.
  • Excessive PAN Access: Unmasked PAN access is often not adequately monitored or controlled, especially in organisations with dispersed teams.
  • Poor Key Management Practices: Inadequate key rotation, improper storage of encryption keys, and insufficient documentation can jeopardise compliance.
  • Lack of Data Review & Retention Schedules: Failing to perform and document quarterly reviews of stored data is a common oversight, particularly in data-intensive businesses. 

How Securious Can Help

Securious has been a PCI QSAC since 2016, with a team of qualified, highly experienced PCI DSS QSA and 3DS assessors ready to assist you in achieving and maintaining compliance with the latest PCI DSS standards. 

Based in Exeter, Devon, we undertake PCI QSA work both nationally and internationally. We are the only PCI DSS QSA company in our region, so organisations in Devon, Cornwall, or Somerset can benefit from cost efficiencies with on-site assessments. 

Our mission is to build cyber security confidence. When it comes to PCI DSS compliance, we collaborate with you to make the process as efficient as possible, helping you understand what needs to be done and why. 

We offer three options to assist our clients with PCI DSS compliance: 

  1. PCI DSS QSA Gap Analysis & Assessment (one-off fee)
    Read more about our PCI DSS QSA Gap Analysis & Assessment by clicking here.
  1. Managed PCI DSS Compliance Service (fixed monthly fee)
    Read more about our Managed PCI DSS Compliance Service by clicking here.
  1. Assisted PCI DSS SAQ Compliance Service (one-off fee)
    Read more about our Assisted PCI DSS SAQ Compliance Service by clicking here. 

Get in Touch to Get Started 

To learn more, visit our PCI services page, call us on 01392 247 110, email info@securious.co.uk, or send us a message using the form below. 

Find out whether you’re ready for PCI DSS v4.0.1 in minutes.