PCI DSS v4.0 Requirement 3 reference
Which Algorithms Still Pass Under PCI DSS v4.0
The accept/prohibit baseline for AES, RSA, ECC and hashes, plus the 3DES sunset and the 112-bit bar.
The problem
You need a defensible baseline before you can justify a migration
When you run a cryptographic inventory, the hard part is not finding the algorithms, it is proving which ones PCI DSS v4.0 still accepts and which you are now obliged to retire. Encryption is only as strong as the key management around it, and Requirement 3 demands documented, auditable controls that most teams cannot readily evidence. Without a clear accept/prohibit line, every migration decision and timeline is an argument you have to win from scratch.
17-page practitioner reference
Get the reference guide
- Written for practitioners, mapped to PCI DSS v4.0 clauses
- Acceptable-algorithms table with minimum key lengths
- AES mode guidance for payment contexts
Download the guide
Inside the reference
What is inside the reference
The payoff
What you can do once you have it
Standards, not opinion
Grounded in the standards, not opinion
FAQ
Questions engineers ask before downloading
The guide sets out the 3DES/TDEA position - sunset after 2023 in new implementations - alongside its 112-bit effective key length, so you can tell where existing use stands versus new deployments.
Yes. It states where CBC, GCM, ECB and CTR are acceptable in a CDE, including why ECB is prohibited and why GCM is preferred for data in transit and tokenization vaults.
No. It is an independent practitioner reference for informational and educational purposes. Commerce Security Authority is not affiliated with, endorsed by, or approved by PCI Security Standards Council, LLC.
For engineers running a cryptographic inventory or migration who need a clear accept/prohibit baseline - with the operational detail and the audit artifacts an assessor will later ask for.
PCI DSS v4.0 Requirement 3 reference