PCI DSS v4.0 Requirement 3, Key Management
Know Exactly What Your QSA Will Ask For
The key management evidence PCI DSS v4.0 Requirement 3 expects, dual control, split knowledge, custodian records, named before your assessment starts.
Contents
What's inside the 17 pages
The six audit artifacts assessors request to prove dual control, from ceremony scripts to HSM co-authentication logs
A controls-to-scope matrix tying each control to Req. 3.5.1, 3.7.1, 3.7.2 or 3.7.6 and the system components in scope
Three recurring findings, weak algorithms, missing dual control evidence, undocumented key inventories, each with a remediation checklist
Crypto-period guidelines by key type: DEK, KEK, PIN encryption, TLS session and signing keys
Acceptable algorithms and minimum key lengths table, with PCI DSS status for AES, 3DES, RSA, ECC, SHA-2/3, MD5 and SHA-1
AES mode guidance for payment contexts: where CBC, GCM and CTR apply and why ECB is not acceptable
Key hierarchy design separating DEKs, KEKs and master keys, with storage location and rotation trigger for each
Key storage methods rated acceptable, conditional or prohibited, HSM, software key store, cloud KMS, application config
Custodian acknowledgment, tamper-evident envelope custody chain and M-of-N ceremony quorum requirements
Entropy and key generation standards referencing FIPS 140-2/140-3, NIST SP 800-90A, SP 800-186 and RFC 3394 key wrap
A six-step suspected key compromise response sequence, from key suspension to notification
Vendor baseline criteria, CDE integration checklist and proof-of-concept questions for KMS and HSM selection
Encryption and Key Management Reference
Send me the reference
Instant access to the full 17-page reference