The PCI PIN Standard consists of requirements for the secure management, processing and transmission of PIN data during online and offline payment card transaction processing at ATMs and attended/unattended POS terminals. The purpose of a PCI PIN Assessment is to confirm organizations are securely managing this data.
The requirements must be met by all organizations or supporting 3rd parties that accept or process transactions from ATMs or POS terminals on the acquiring side — in particular banks, payment providers and network operators. Key Injection Facilities and Certification Authorities are subject to an SAQ or QPA assessment.
Organizations are required to have an on-site assessment conducted by a Qualified PIN Assessor (QPA) every 2 years.
A PCI PIN Assessment covers encryption and key management of PIN transactions and the secure management of processing equipment. POS devices and the HSM used to decrypt the PIN and manage keys are key parts of the assessment.
Kickoff and Planning — including the critical PIN scoping workshop. Formal validation — on-site interviews, configuration sampling, technical tests and document reviews. Reporting — within 3 weeks of successful completion. Deliverables: RoC and AoC. Continual Support after certification.
Reference: PCI SSC Document Library.