Skip to main content

PCI DSS v4.0 · Requirement 3.7

The Evidence Collection Worksheet for PCI Key Management

Inventory, rotation logs, access reviews, custodian assignments, organized and tracked.

// The gap most teams don't see until the assessment

You have the controls. Can you produce the records?

Many teams invest heavily in encryption yet scramble to demonstrate the operational controls around their cryptographic keys during an assessment. When a QSA asks for the inventory, the rotation logs, the access reviews and the custodian assignments, the answer is often a hurried search across systems and inboxes. This workbook gives you a template for exactly what documentation to keep, and who owns it, before the assessment begins.

// Contents

What is inside the workbook

An evidence collection worksheet with an owner assigned to every record
The full list of documentation to collect for Requirement 3.7
Access control evidence: IAM reports, MFA configuration, custodian assignments
Manual key handling evidence: key ceremony docs, witness logs, training records
Production key inventory fields to capture and maintain
A final readiness checklist confirming all evidence is collected

// Outcomes

What changes once you have it

You answer control by control

Every worksheet maps directly to PCI DSS v4.0 Requirement 3.7, so you respond to each control with the record it asks for.

You cover the whole lifecycle in one place

Generation, distribution, storage, rotation, replacement and destruction are all tracked in a single workbook rather than scattered across tools.

You know where you stand before the QSA does

A scored readiness assessment shows which areas are excellent, which need improvement and which require immediate remediation.

You fix the real gaps first

The workbook is built around the findings QSAs flag most often, so your remediation targets what assessments actually catch.

You start today

Abstract requirements become concrete checkboxes and evidence lists, plus a ready-to-use 30-day action plan to close gaps on a schedule.

// Why this workbook

Grounded in the standard, built for the assessment

Requirement 3.7 vocabulary

Grounded in PCI DSS v4.0 Requirement 3.7 controls and terminology: cryptoperiod, split knowledge, dual control, KEKs and HSMs.

Knows what auditors ask for

Includes an Auditor Tip and lists the specific evidence QSAs request across each control area.

Honest about its scope

Points you to the official PCI SSC documentation and your Qualified Security Assessor (QSA) for final compliance determinations.

// Before you download

Questions, answered

No. It is an educational readiness workbook. It helps you organize evidence and identify gaps, but you should consult your QSA and the official PCI DSS documentation to determine your compliance obligations.

PCI DSS v4.0 · REQUIREMENT 3.7

Assemble your audit-ready evidence

Print-ready checklists, worksheets and a 30-day plan.