Tokenization

PCIComplianceHubLast updated

Replacing a PAN with a surrogate value, the token, that has no value to an attacker and that only the tokenisation system can map back to the PAN. A card network's payment tokens and a merchant vault's index tokens are both tokenisation; the difference is who holds the mapping.

Applies to. Merchants and service providers that need a reference to a card after the transaction, for refunds, recurring billing or reporting, without holding the PAN themselves.
Example. A subscription business stores a provider token against each customer and charges it monthly. Its own systems hold no PAN, so its stored-data scope shrinks to the systems that see the card during entry.
Limits. Tokenisation moves the PAN, it does not remove it: the system that maps tokens to PANs is in scope, and if the entity operates that system itself, so is everything that can reach it. A token that can be used to make a payment is a credential in its own right and needs protecting as one. 3.5.1 accepts index tokens as a way of rendering stored PAN unreadable; a value the entity can reverse without the vault is not one.
In PCI DSS v4.0.1. 3.5.1