Skip to main content

PCI DSS v4.0 Requirement 3.7 Readiness Checklist

Who Can Touch Your Encryption Keys, And Can You Prove It?

Least privilege, MFA, split knowledge, and dual control for the cardholder data environment.

Too many admins can reach your keys, and an auditor will ask why

Attackers rarely break modern encryption. They target excessive administrator access, shared privileged accounts, and manual key handling with no split knowledge or dual control. When a QSA asks who can access, manage, or modify your cryptographic keys, the honest answer is often "more people than we can defend." This workbook helps you close that gap before the assessment does it for you.

Free 14-page workbook

Get instant access to the readiness checklist

A requirement-by-requirement checklist for validating cryptographic key access controls against PCI DSS v4.0 Requirement 3.7.
  • Scorecard, evidence worksheet, and 30-day plan included.
  • Access control review, custodians, MFA and dual control.
  • Maps directly to Requirement 3.7, not generic advice.
Key Management Under PCI DSS v4.0

Send me the checklist

Scorecard, evidence worksheet, and 30-day plan included.

Verifying you're human...

What is inside the workbook

Six focused reviews built around who can touch your keys and how you prove it.

Access control review: least privilege, MFA, documented administrative roles, and key custodian identification
Manual key handling review: split knowledge, dual control, key ceremony and witness log documentation
Privileged activity logging checks across the cardholder data environment
Evidence to collect: access control matrix, IAM reports, MFA configuration, administrator list, custodian assignments
Common access-related assessment findings, from shared accounts to unclear ownership
Compliance readiness scorecard, evidence collection worksheet, and a 30-day action plan

What you can do once you have worked through it

Defend your access model to a QSA

Show exactly who can touch each key, under what controls, and back it with the evidence an assessor expects.

Find your access gaps before the assessor does

Name the common findings, excessive admin rights, shared accounts, missing logs, and remediate them on your own timeline.

Put a defensible least-privilege model in place

Enforce MFA, prohibit shared accounts, review service accounts, and assign accountable key custodians.

Prove manual key operations are controlled

Confirm split knowledge and dual control are implemented, documented, and independently verified for every cleartext key operation.

Grounded in the standard, not generic security advice

Maps to Requirement 3.7

Aligns directly to PCI DSS v4.0 Requirement 3.7 and the PCI Security Standards Council framework.

Speaks the assessor's language

References the concepts assessors expect: KEKs, HSMs, split knowledge, dual control, and documented cryptoperiods.

The cryptoperiod auditor tip

Includes an auditor tip on justifying why a specific cryptoperiod was selected rather than an arbitrary timeframe.

Built around the QSA process

Structured around the QSA assessment process and the evidence expectations that support compliance validation.

Before you download

Access control is the focus, but the workbook covers the entire key lifecycle, generation, distribution, storage, rotation, replacement, and destruction, so access controls sit in their full context.

PCI DSS v4.0 Requirement 3.7

Prove who can touch your keys, before the QSA asks.

Scorecard, evidence worksheet, and 30-day plan included.