Cardholder Data Encryption Playbook
AES or ECC? The PCI-Defensible Answer for Every Workload
Key lengths, curves, and cipher modes mapped to data at rest, in transit, and storage under PCI DSS v4.0.
GCM, CBC, or XTS? AES-128 or AES-256? ECC or RSA, and if ECC, which curve? Each choice carries a different acceptability outcome under PCI DSS v4.0, and the wrong pairing surfaces as a finding at assessment time.
“Strong cryptography” is a specific, evidence-driven definition covering algorithm, key length, mode of operation, and key management, not simply the fact that you encrypt. Teams implement encryption once, leave it unchanged through multiple compliance cycles, and produce the same recurring findings as a result.
The 37-page playbook
Get instant access to the playbook
This 37-page operational playbook takes the questions engineers actually type into a search bar, ECC vs RSA, AES-128 vs AES-256, which curve for TLS, GCM vs CBC, and turns them into decisions you can defend. Every recommendation is tied to the workload it applies to, data at rest, data in transit, and storage volumes, and back to the requirement that governs it. It shows practitioners how to move from control intent to deployed, auditable encryption.
No. The playbook is intended solely for educational and informational purposes. It is not legal, regulatory, audit, or compliance advice. Consult qualified legal counsel, a Qualified Security Assessor, and your security professionals regarding your specific PCI DSS obligations.
Encryption being present is not the same as encryption being defensible. The playbook addresses the layers assessors test beyond the fact of encryption: correct mode for the workload, key separation, and the key-management lifecycle that makes the control auditable.
Both. It is written for crypto and platform engineers designing or upgrading a cardholder data environment, and structured so internal compliance teams and QSAs can walk cryptographic controls against Requirement 3 sub-requirement by sub-requirement.
Yes. It addresses HSM-backed KEK storage, software key store risks, and cloud key management services with dedicated HSM backing, alongside centralized, distributed, and federated operating models.
Cardholder Data Encryption Playbook