Skip to main content

Cardholder Data Encryption Playbook

AES or ECC? The PCI-Defensible Answer for Every Workload

Key lengths, curves, and cipher modes mapped to data at rest, in transit, and storage under PCI DSS v4.0.

AES-128 vs AES-256//ECC vs RSA//P-256 vs P-384//GCM vs CBC//Triple DES deprecated//112-bit threshold//Which curve for TLS//FIPS 186-5//AES-128 vs AES-256//ECC vs RSA//P-256 vs P-384//GCM vs CBC//Triple DES deprecated//112-bit threshold//Which curve for TLS//FIPS 186-5//

GCM, CBC, or XTS? AES-128 or AES-256? ECC or RSA, and if ECC, which curve? Each choice carries a different acceptability outcome under PCI DSS v4.0, and the wrong pairing surfaces as a finding at assessment time.

“Strong cryptography” is a specific, evidence-driven definition covering algorithm, key length, mode of operation, and key management, not simply the fact that you encrypt. Teams implement encryption once, leave it unchanged through multiple compliance cycles, and produce the same recurring findings as a result.

112 bits
Minimum security strength the PCI DSS v4.0 glossary requires for strong cryptography.
128 bits
AES-128 security strength; AES-256 doubles it and is preferred for new CDE deployments.
2048-bit
Minimum RSA key length; RSA-1024 is explicitly disallowed and 3DES is deprecated.
P-256
The 128-bit ECC baseline for most TLS and P2PE deployments, matching RSA-3072.

The 37-page playbook

Get instant access to the playbook

Mapped to specific PCI DSS v4.0 sub-requirements. Delivered straight to your inbox.

This 37-page operational playbook takes the questions engineers actually type into a search bar, ECC vs RSA, AES-128 vs AES-256, which curve for TLS, GCM vs CBC, and turns them into decisions you can defend. Every recommendation is tied to the workload it applies to, data at rest, data in transit, and storage volumes, and back to the requirement that governs it. It shows practitioners how to move from control intent to deployed, auditable encryption.

Table of contents
AES-128 vs AES-256 compared on security strength, performance overhead, and quantum posture
ECC vs RSA by use case, with equivalent security strengths for TLS handshakes, P2PE key exchange, long-term signing, and tokenization
Approved NIST curves (P-256, P-384, P-521) and the curves to avoid (secp256k1, Brainpool, Curve25519 / X25519)
Cipher mode selection: GCM for authenticated encryption, CBC caveats and padding-oracle risk, XTS for storage and full-disk encryption
The algorithm acceptability table, showing what meets the 112-bit threshold and what is disallowed
KEK hierarchies, key separation, dual control, split knowledge, cryptoperiods by key type, and rotation without downtime
An assessment-readiness checklist, a QSA evidence bundle, and a three-tier remediation priority list

Pick algorithms without guessing

Choose AES-128 vs 256, ECC vs RSA, and the correct mode for each workload knowing in advance what a QSA will accept.

Defend every choice on paper

Document key-length rationale, mode selection, and enforcement points so assessors can trace each data store to a justified configuration.

Catch the findings before the assessor does

Recognise the recurring algorithm, key-management, and documentation gaps that delay Report on Compliance issuance, and close them first.

Plan the next migration as routine

Sequence AES and ECC upgrades without transaction outages and lay the groundwork for the post-quantum transition ahead of any mandate.

PCI DSS v4.0 requirements

Definitions and thresholds cited to the PCI DSS v4.0 glossary and Requirements 3.5, 3.6, 3.7, 4.2.1, and 12.3.3.

NIST key-management references

NIST SP 800-57 Part 1 Rev. 5 as the governing key-management reference, with SP 800-131A Rev. 2 for deprecation timelines.

FIPS validation standards

FIPS 140-3 (CMVP), FIPS 197 for AES, and FIPS 186-5 / SP 800-186 for approved curves.

2024 post-quantum standards

The 2024 post-quantum standards FIPS 203, 204, and 205 referenced for forward planning.

Concrete decision tables

Algorithm acceptability, security-strength, and cryptoperiod tables with specific key lengths and bit-strengths.

No. The playbook is intended solely for educational and informational purposes. It is not legal, regulatory, audit, or compliance advice. Consult qualified legal counsel, a Qualified Security Assessor, and your security professionals regarding your specific PCI DSS obligations.

Cardholder Data Encryption Playbook

Get the PCI-defensible answer for every workload

Mapped to specific PCI DSS v4.0 sub-requirements. 37 pages, delivered to your inbox.