Cryptographic Architecture
PCIComplianceHubLast updated
A documented description of how cryptography is used across an environment: the algorithms, protocols and cipher suites in use, the keys and certificates involved, where each is applied, and the plan for responding when an algorithm or protocol weakens. PCI DSS Requirement 12.3.3 requires all entities to document and review the cipher suites and protocols in use at least once every 12 months, so that a deprecation such as the retirement of TLS 1.0 or SHA-1 is acted on rather than discovered during an assessment. Requirement 3.6.1.1 places a fuller cryptographic architecture obligation on service providers. Requirement 12.3.3 was future-dated at publication and became mandatory on 31 March 2025.