Skip to main content
The RFC No One Submitted Feedback OnPCI DSS Compliance
4 min readFor PCI DSS Compliance Teams

The RFC No One Submitted Feedback On

What Happened

Between February 13 and March 16, the PCI Security Standards Council opened a 30-day request for comments (RFC) period for draft revisions to the Card Production and Provisioning Physical and Logical Security Standards v3.0.1. These standards hadn't been updated since June 2022. Stakeholders had to sign an NDA, access documents through the PCI SSC Portal, and submit feedback within this window.

Here's the issue: most compliance teams likely didn't participate. Not because the standards don't matter, but because card production security often falls into a compliance blind spot for organizations that don't manufacture or personalize cards. If you're running a merchant environment or payment gateway, you've probably never opened these documents.

This wasn't a breach, but a missed chance to influence requirements that impact your supply chain.

Timeline

June 2022: Last update to Card Production and Provisioning standards published.

February 13, 2025: RFC period opens for v3.0.1 draft.

March 16, 2025: RFC period closes; feedback window ends.

Post-RFC: PCI SSC reviews submissions, finalizes changes, publishes updated standards.

Future enforcement: Updated requirements flow down to card manufacturers, personalizers, chip embedders, and data preparation facilities in your payment ecosystem.

Which Controls Failed or Were Missing

This isn't about a control failure in the traditional sense. It's about a structural gap in how compliance teams engage with standards affecting their environment indirectly.

Missing Stakeholder Engagement: Organizations relying on card production vendors often don't review the standards governing those vendors. You validate their PCI compliance status annually, but you probably don't read the actual Card Production and Provisioning requirements they're assessed against.

Absent Supply Chain Visibility: When you onboard a card manufacturer or personalization bureau, do you know which version of the Physical and Logical Security Standards they're certified under? Do you know what changed between v3.0 and v3.0.1? Most compliance teams can't answer that.

No Feedback Mechanism for Downstream Impact: The RFC process allows "eligible stakeholders" to comment, but eligibility typically means direct participation in card production activities. If you're a bank issuing cards or a processor managing personalization data, you have operational exposure to these standards, but you may not have formal standing to submit feedback.

Lack of Pre-RFC Awareness: The 30-day window assumes stakeholders are monitoring PCI SSC announcements and ready to review draft standards on short notice. In practice, compliance teams are deep in PCI DSS 4.0 transition work, fraud rule tuning, or AML program assessments. Card production standards don't trigger the same urgency.

What the Relevant Standard Requires

The Card Production and Provisioning Physical Security Standard addresses requirements for entities that manufacture, personalize, pre-personalize, embed chips, or fulfill card orders. This covers physical access controls, environmental protections, equipment security, and materials handling.

The Logical Security Standard governs data preparation, pre-personalization activities, card personalization processes, and PIN generation. This includes cryptographic key management, secure data transmission, access controls for personalization systems, and audit logging.

Both standards exist separately from PCI DSS but intersect with it. If you're a card issuer, your CDE ends where the personalization bureau's environment begins. You're responsible for secure transmission of cardholder data to that bureau, and they're responsible for meeting Card Production and Provisioning requirements during manufacturing.

The standards require split knowledge for cryptographic key components, physical separation of card production zones, and logging of all personalization activities. They mandate specific controls for PIN mailer handling, magnetic stripe encoding, and chip initialization.

What the standards don't explicitly require: downstream notification when requirements change. When v3.0.1 publishes, card manufacturers will need to update their processes, but there's no automatic alert to the banks and processors who depend on those manufacturers.

Lessons and Action Items for Your Team

Map Your Card Production Dependencies Now: List every vendor involved in card manufacturing, personalization, PIN generation, or fulfillment for your organization. Confirm which version of the Card Production and Provisioning standards each vendor is certified under. Ask for their assessment timeline and how they'll handle v3.0.1 updates.

Request RFC Participation Rights: If your organization issues cards or manages personalization data, contact PCI SSC to clarify your eligibility for future RFC periods. Even if you don't manufacture cards directly, you have operational risk exposure that justifies input on requirement changes.

Build an RFC Monitoring Process: Assign someone to track PCI SSC announcements specifically for Card Production and Provisioning updates. Don't rely on your QSA to flag these; they're focused on your DSS assessment, not your supply chain standards.

Review Vendor Contracts for Standards Version Language: Your agreements with card manufacturers should reference specific versions of applicable PCI standards and include update obligations. Vague language like "maintain PCI compliance" doesn't give you leverage when v3.0.1 introduces new requirements that affect cost or timeline.

Connect Card Production Security to Your Threat Model: The Physical and Logical Security Standards exist because card production facilities are high-value targets. If an attacker compromises a personalization bureau, they can inject malicious code into chip applications, intercept PINs, or exfiltrate account data for thousands of cardholders. Your incident response plan should account for supply chain compromise scenarios.

Participate in the Next RFC: When PCI SSC opens comment periods for standards updates, treat it as compliance work, not optional reading. You're not just reviewing abstract requirements; you're influencing controls that protect your cardholders and your program.

The Card Production and Provisioning standards update won't generate headlines. But the next time a personalization bureau gets breached and you're explaining to regulators why you didn't know what security controls were required at that facility, you'll wish you'd spent 30 days reading that RFC.

You Might Also Like