News

PCI Council extends encryption deadline

Monday 28 December 2015 09:44 CET | News

The PCI Standards Council (PCI SSC), a global forum for the development of payment card security standards, has announced a change to the date that organizations who process payments must migrate to TLS 1.1 encryption or higher.

The original deadline date for migration, June 2016, was included in the most recent version of the PCI Data Security Standard, version 3.1 (PCI DSS 3.1), which was published in April of 2015. The new deadline date, June 2018, will be included in the next version of the PCI Data Security Standard, which is expected in 2016.

In addition to the migration deadline date-change, the PCI Security Standards Council has updated anew requirement date for payment service providers to begin offering more secure TLS 1.1 or higher encryption; a requirement for new implementations to be based on TLS 1.1 or higher and an exception to the deadline date for Payment Terminals, known as “POI” or Points of Interaction.

The PCI Security Standards Council is a global forum that is responsible for the development, management, education, and awareness of the PCI Data Security Standard and other standards that increase payment data security. Founded in 2006 by the major payment card brands American Express, Discover Financial Services, JCB International, MasterCard Worldwide and Visa Inc., the Council has over 700 participating organizations representing merchants, banks, processors and vendors worldwide.
 


Free Headlines in your E-mail

Every day we send out a free e-mail with the most important headlines of the last 24 hours.

Subscribe now

Keywords: The PCI Security Standards Council, encryption, payment card security standards, TLS 1.1 encryption
Categories: Fraud & Financial Crime
Companies:
Countries: World
This article is part of category

Fraud & Financial Crime






Industry Events