PCI DSS v4.0 Requirement 3.7 Readiness Checklist
Who Can Touch Your Encryption Keys, And Can You Prove It?
Too many admins can reach your keys, and an auditor will ask why
Attackers rarely break modern encryption. They target excessive administrator access, shared privileged accounts, and manual key handling with no split knowledge or dual control. When a QSA asks who can access, manage, or modify your cryptographic keys, the honest answer is often "more people than we can defend." This workbook helps you close that gap before the assessment does it for you.
Free 14-page workbook
Get instant access to the readiness checklist
- Scorecard, evidence worksheet, and 30-day plan included.
- Access control review, custodians, MFA and dual control.
- Maps directly to Requirement 3.7, not generic advice.
What is inside the workbook
Six focused reviews built around who can touch your keys and how you prove it.
What you can do once you have worked through it
Grounded in the standard, not generic security advice
Maps to Requirement 3.7
Aligns directly to PCI DSS v4.0 Requirement 3.7 and the PCI Security Standards Council framework.
Speaks the assessor's language
References the concepts assessors expect: KEKs, HSMs, split knowledge, dual control, and documented cryptoperiods.
The cryptoperiod auditor tip
Includes an auditor tip on justifying why a specific cryptoperiod was selected rather than an arbitrary timeframe.
Built around the QSA process
Structured around the QSA assessment process and the evidence expectations that support compliance validation.
Before you download
Access control is the focus, but the workbook covers the entire key lifecycle, generation, distribution, storage, rotation, replacement, and destruction, so access controls sit in their full context.
IAM, security, and IT teams doing the work, along with compliance professionals, merchants, and service providers preparing for a PCI DSS assessment.
No. It is provided for educational purposes only. You should consult your Qualified Security Assessor and the official PCI DSS documentation when determining compliance obligations.
No. It includes a 30-day action plan that breaks the work into weekly steps, from inventorying keys and custodians through an internal assessment.
PCI DSS v4.0 Requirement 3.7