Ciphertext
PCIComplianceHubLast updated
Data after encryption: unreadable without the key that decrypts it. Ciphertext is what PCI DSS wants stored PAN to be under 3.5.1's strong-cryptography option, and what it wants PAN to be on any public network under 4.2.1. Ciphertext is only as protected as its key, which is why Requirements 3.6 and 3.7 are about keys rather than about the encryption.