Document Comparison

PCI_Card_Production_SR_FAQs_v3_October_2025.pdf PCI_CP_SR_FAQs_v3_Feb_2026.pdf
96% similar
43 → 44 Pages
16680 → 17448 Words
2 Content Changes

Content Changes

2 content changes. 30 administrative changes (dates, page numbers) hidden.

Added p. 18
a) The PIN distribution system must not communicate with any other system where associated cardholder data is stored or processed.

b) The PIN distribution system must run on a dedicated computer and be isolated from any other network by a dedicated firewall.

c) The PIN distribution system must perform no other function than PIN distribution, and any sessions established during the distribution - e.g., a telephone call, an e-mail, or a SMS message•must be terminated once the PIN has been sent.

d) During transmission to and storage in the PIN distribution system, all PIN and authentication values must be encrypted using key algorithms and sizes as stated in Normative Annex A.

e) Communication of the PIN to the cardholder must only take place after verification of the identification value and associated authentication value.

f) The identification and authentication values must not disclose the account number.

g) The authentication value must be different than the identification value …
Modified p. 18
Section 9

• PIN Distribution via Electronic Methods No FAQ in this section

• Reserved
for future use.
Section 9

• PIN Distribution via Electronic Methods The following requirements apply for the distribution of PINs via electronic methods.