All posts by David Acosta

Qualified Security Assessor (QSA) for PCI DSS, PCI PIN, PCI 3DS, P2PE and PCI TSP. CISSP, CISA, CISM, CRISC, C|EH, C|HFI.

Compensatory checks and personalised approach: What are they and when are they used?

Unlike other security standards, the PCI DSS standard allows for some flexibility in the implementation of your controls. If there are technical or administrative restrictions that prevent the implementation of a control "as is" as requested in the standard, the...

/ June 18, 2026

Changes in PCI PTS HSM v5.0: Who do they affect and what does it mean for the future of payments?

On May 18, 2026, the PCI SSC released version 5.0 of the PCI PTS HSM standard (or simply PCI HSM). This standard includes numerous changes that may affect, directly or indirectly, compliance with other PCI standards.

/ May 20, 2026

DNS: The blind spot of PCI DSS

If you thought that, by implementing all PCI DSS controls, you were going to be invulnerable against cyberattacks, you may need to review your strategy. There are certain technical areas that are not covered by that standard and that need to be reviewed...

/ May 7, 2026

What is known about PCI DSS v5.0?

Version 4.0 of PCI DSS was released in March 2022. The PCI Security Standards Council is already actively working on version 5.0. What is known about this new version? Ray Kurzweil's Law of Accelerated Yields...

/ April 7, 2026

Two-year extension for PCI PTS HSM v3

After having us on edge for a few months, the PCI Security Standards Council (PCI SSC) has extended the expiration periods of devices validated in PCI HSM as follows: Extends the period of device validation in...

/ March 9, 2026

What is PCI 3DS?

This article presents a brief description of the PCI 3DS standard, aimed at protecting card-not-present e-commerce transactions through robust cardholder authentication. Introduction The Payment Card Industry Standard...

/ February 26, 2026

Transparent Data Encryption (TDE): ‘compliance’ vs. ‘security’

Transparent Data Encryption (TDE) is a technology that protects sensitive data in databases during storage (data-at-rest). However, its use must be restricted to very specific scenarios, outside of which the level of protection that...

/ February 19, 2026

The expiration date of PCI HSM version 3.x is approaching (30 April 2026), what will happen to the affected devices?

April 30, 2026 is the stipulated date for the expiration of cryptographic devices validated according to PCI HSM version 3.x. If you do not have defined your migration strategy, this article interests you. NOTE: The PCI SSC has...

/ February 12, 2026

What is PCI SSF/PCI Secure SLC/PCI S3?

This new article presents a brief introduction to the Payment Card Industry Software Security Framework (PCI SSF), which replaced the PA-DSS (Payment Applications Data Security Standard) standard in October 2022. Introduction One...

/ January 27, 2026

PCI SSC Standards Ecosystem (updated January 2026)

The PCI Security Standards Council (PCI SSC) has developed multiple security standards that define specific security requirements oriented towards the protection of each of the areas related to the security of payment card data,...

/ January 26, 2026

Do you process card data and don't want to get complicated with PCI DSS compliance reports? So you can get an exemption

The security of payment card data is not the same as it was 10 or 15 years ago. The massification of EMV chips and contactless transactions, the use of tokenization, the implementation of P2PE controls and...

/ December 18, 2025

The Importance of Encryption Modes in Cryptography

When using encryption, a robust algorithm and an acceptable key length is not enough. There are two other very important parameters that are often forgotten: Encryption mode and initialization vector parameterization (Initialization Vector, IV). These...

/ December 11, 2025

Differences between Vulnerability Scans and Penetration Tests in PCI DSS

As part of regular security status monitoring activities, the PCI DSS standard requires a series of technical assessments to identify potential security issues in compliance and compliance assets early.

/ December 4, 2025

Visa's AIS program no longer includes level 4 for merchants

Visa's Account Information Security (AIS) program has undergone major changes, modifying merchant classification criteria to report compliance with the PCI DSS standard. This program defines the applicable requirements based on the...

/ November 27, 2025

Guide to understanding the types of tokens and their use

One of the key controls of the PCI DSS v4.0 standard is requirement 3.5. It lists a number of techniques for protecting the PAN (Primary Account Number) when it should be stored, if there is any business justification.  The...

/ November 20, 2025