Requirement 12.3.3 makes a yearly-reviewed inventory of cipher suites and protocols mandatory since 31 March 2025.
At a glance
| Type | Industry standard |
|---|---|
| Jurisdiction | international |
| Who it applies to | Any organization that stores, processes or transmits payment card data (merchants, PSPs, SaaS in the payment flow). |
Cryptography requirements
| Reference | Requirement | What a scan and inventory can evidence |
|---|---|---|
| 12.3.3 | Cryptographic cipher suites and protocols in use are documented and reviewed at least every 12 months: up-to-date inventory (purpose, where used), monitoring of their continued viability, and a documented strategy to respond to anticipated changes in cryptographic vulnerabilities. |
|
Key dates
- Requirement 12.3.3 becomes mandatory (was a best practice before).
Sources
- PCI DSS v4.0.1 · PCI Security Standards Council
Catalog version 2026-09-28. Every position links to its primary source; draft documents are labelled as such.