PCI DSS 3.7.9 (service providers): Where a service provider shares cryptographic keys with its customers for transmission
PCI DSS v4.0.1 control 3.7.9: the requirement in full, the 1 testing procedure an assessor uses to verify it, and the related controls in section 3.7.
Requirement 3: Protect Stored Account Data › Section 3.7
Additional requirement for service providers only: Where a service provider shares cryptographic keys with its customers for transmission or storage of account data, guidance on secure transmission, storage and updating of such keys is documented and distributed to the service provider’s customers.
Summary
Service providers only: if you share keys with customers, give them written guidance on transmitting, storing and updating those keys.
What the assessor will examine
These are the testing procedures the standard defines for this control. They tell you what evidence to have ready.
| Procedure | |
|---|---|
| 3.7.9 | Additional testing procedure for service provider assessments only: If the service provider shares cryptographic keys with its customers for transmission or storage of account data, examine the documentation that the service provider provides to its customers to verify it includes guidance on how to securely transmit, store, and update customers’ keys in accordance with all elements specified in Requirements 3.7.1 through 3.7.8 above. |
Read the procedure, not the control text, before scoping this. The text asks for guidance on secure transmission, storage and updating. The procedure asks that the guidance be verified "in accordance with all elements specified in Requirements 3.7.1 through 3.7.8 above", which is a materially heavier obligation: the customer-facing document has to carry the substance of the whole section, generation, distribution, storage, cryptoperiods, retirement, dual control, substitution and custodian acknowledgement. Entities scope this as a short note on key handling and are assessed against eight controls. It applies only where you actually share keys with customers, so the first question is whether you do, and the cleanest answer for many providers is to stop, since a key the customer never holds is a control that does not apply. Merchants are on the receiving end: this document is a reasonable thing to ask for during the due diligence in 12.8.3.
What to prepare
- The customer-facing guidance, mapped against 3.7.1 to 3.7.8 element by element.
- The list of customers you share keys with, and which keys.
- Evidence the guidance reaches them, and which version they hold.
How to implement it
1. Map it to 3.7.1 through 3.7.8 before writing. Doing that first shows how much is missing from the short version, and the mapping is also the evidence that makes the assessment quick.
2. Ask whether you need to share keys at all. Provider-held keys, tokenisation, or keys generated in the customer's own environment all remove the sharing that triggers this control.
3. Cover updating properly. It is a named element and the one most often reduced to a sentence, though it carries the cryptoperiod and retirement obligations from 3.7.4 and 3.7.5.
4. Version it and record distribution. Guidance the customer cannot be shown to have received does not meet "documented and distributed".
Where this commonly fails
- Scoped from the control text as a short handling note, then assessed against eight controls.
- Guidance written once at product launch and never updated with the key management practice it describes.
- Distributed to the contract signatory rather than to the people who handle the keys.
- A merchant applying this to itself, when it is a service provider requirement.
Related controls
Others in section 3.7:
| Control | What it requires |
|---|---|
| 3.7.1 | Key-management policies and procedures are implemented to include generation of strong… |
| 3.7.2 | Key-management policies and procedures are implemented to include secure distribution… |
| 3.7.3 | Key-management policies and procedures are implemented to include secure storage… |
| 3.7.4 | Key management policies and procedures are implemented for cryptographic key changes for keys… |
| 3.7.5 | Key management policies procedures are implemented to include the retirement, replacement… |
| 3.7.6 | Where manual cleartext cryptographic key-management operations are performed by personnel… |
| 3.7.7 | Key management policies and procedures are implemented to include the prevention… |
| 3.7.8 | Key management policies and procedures are implemented to include that cryptographic key… |
← 3.7.8 · All controls · 4.1.1 →
Source
The requirement text and testing procedures above are reproduced from PCI DSS v4.0.1 (June 2024), ©2006-2024 PCI Security Standards Council, LLC. All rights reserved. The commentary is our own.
The official standard is authoritative and also contains the Customized Approach Objective, applicability notes and guidance for this control. Download it from the PCI Security Standards Council document library. PCI DSS is a registered standard of the PCI Security Standards Council, LLC, which does not endorse this site. Nothing here is a substitute for advice from a Qualified Security Assessor.