PCI 3DS Core readiness and gap assessment for 3-D Secure environments.
Card brands and partners expect PCI 3DS Core evidence from anyone operating an ACS, Directory Server, or 3DS Server. This readiness and gap assessment confirms which functions you actually perform, defines the 3DS Environment boundary, and shows what has to be fixed before a qualified 3DS Assessor arrives.
- Confirmed applicability and function scoping across ACS, DS, and 3DSS roles.
- Architecture and data-flow review with a defensible 3DS Environment boundary.
- A Core control and evidence gap register with prioritized remediation.
Prefer to talk first? Book a readiness call.
Who this is for
- Issuers and issuer processors operating or supporting an Access Control Server.
- Organizations operating Directory Server functions for a payment network.
- Acquirers, gateways, and merchants operating a 3DS Server.
- Technology providers hosting 3DS components on behalf of clients.
- Teams whose 3DS Environment boundary has never been formally documented.
- Organizations facing a first PCI 3DS Core assessment or a brand deadline.
What you receive
- Applicability and function scoping
- A written determination of which 3DS functions you perform (ACS, DS, 3DSS) and which PCI 3DS Core requirements follow from them.
- Architecture and data-flow review
- Documented 3DS message flows, component inventory, hosting and segmentation review, and a defensible 3DS Environment boundary.
- Core control and evidence gap register
- Findings against applicable PCI 3DS Core Security Standard requirements, including cryptography, key management, logging, and access control, with the evidence each one needs.
- Prioritized remediation plan
- Sequenced by risk, brand pressure, and engineering effort rather than requirement number.
- Testing and evidence plan
- Identify the testing and evidence required for readiness. When included in scope, ControlSolid can perform supporting application, API, and security control testing, document the results for assessor review, and identify any testing that must be performed or independently validated by a qualified 3DS assessor.
- Qualified assessor handoff
- An organized scope and evidence package for handoff to a qualified 3DS assessor.
How the engagement runs
- 01Scope
Confirm the 3DS functions performed, the components in the environment, and the third parties involved.
- 02Assess
Control and evidence review against the applicable PCI 3DS Core requirements.
- 03Plan and hand off
Prioritized remediation, an evidence plan, and coordination with a qualified 3DS Assessor when required.
Who you work with
Senior-led payment authentication readiness informed by prior QSA and PCI PIN Security Assessor experience. Every engagement is delivered by a principal consultant, not staffed out to junior reviewers.
- Prior principal-level payment-security consulting at Trustwave.
- Prior application-security work at Amazon Web Services.
- Focused on the PCI 3DS Core Security Standard and the environments it governs.
- Scope and boundary resolved before remediation spend.
ControlSolid provides readiness, gap assessment, remediation support, and evidence preparation. ControlSolid does not perform the formal PCI 3DS assessment. Formal independent assessment is performed by a PCI SSC-qualified 3DS Assessor. We can coordinate qualified partners while maintaining the independence those assessments require. Prior QSA and PCI PIN Security Assessor experience refers to previous professional roles and does not represent currently active assessor credentials.
Common questions
Which PCI 3DS standard does this cover?
The PCI 3DS Core Security Standard, which applies to environments performing ACS, Directory Server, or 3DS Server functions. The separate 3DS SDK standard is in its sunset period and is not part of this offer.
Does PCI 3DS Core apply to us?
It depends on the 3DS functions your organization performs and what the payment brands require of you. Confirming that, in writing, is the first step of the engagement.
Can ControlSolid perform the assessment?
No. Formal independent assessment is performed by a PCI SSC-qualified 3DS Assessor. We prepare scope, controls, and evidence, and can coordinate a handoff to a qualified partner while maintaining the required independence.
We use a third-party 3DS provider. Are we still in scope?
Sometimes. Outsourcing a function does not always remove responsibility, and the split has to be documented. The scoping work makes that explicit before an assessor questions it.
How long does readiness take?
Most engagements run a few weeks, driven by the number of 3DS functions, hosting arrangements, and how much evidence already exists.
Start with a PCI 3DS Core readiness and gap assessment.
Send the details and we'll reply within one business day, or book a readiness call.