Framework Information Security & Privacy
QPA
QPA stands for Qualified PIN Assessor, the PCI SSC qualification for companies that assess organizations against the PCI PIN Security Requirements.
The PIN standard governs how PINs and the cryptographic keys that protect them are managed, processed and transmitted at ATMs, point-of-sale terminals and in back-end processing: key generation, injection, storage, distribution and destruction, use of approved hardware security modules and PIN entry devices, and the physical and logical security of the facilities involved.
The current published version referenced on attestations is PCI PIN v3.1 (2021); verify in the PCI SSC document library.
Organizations in scope, typically acquirers, PIN processors, key injection facilities, certification and registration authorities and ATM operators, must keep in writing a key management policy, documented key ceremonies with dual control and split knowledge records, key custodian appointments and agreements, HSM and device inventories, secure room access procedures, and the Report on Compliance and Attestation of Compliance from the QPA assessment.
Compliance programs and deadlines are set by the payment brands.
help
Who has to comply
Entities that process PIN transactions or manage PIN encryption keys on behalf of acquirers: PIN processors, key injection facilities, certification and registration authorities, ATM deployers and acquirer operations, as required by the relevant brand program or acquirer contract.
What the assessor asks to see
Key management policy and procedures; key inventory and lifecycle records; key ceremony logs with dual control and split knowledge evidence; key custodian agreements; HSM and PIN entry device inventories with approval numbers; physical security and secure room access records; logical access controls; key injection facility procedures; incident and key compromise procedures; prior ROC and AOC.
Assessors
Who assesses QPA
A PCI SSC qualified QPA company with qualified QPA employees, performing the on-site assessment per the QPA Program Guide. Accredited by PCI Security Standards Council qualification.
Public register of assessors: https://www.pcisecuritystandards.org/assessors_and_solutions/qpa_assessors/
No firm has claimed a QPA assessor listing yet. Claim yours →
Consultants
Who helps with QPA
A niche ecosystem of QPA companies and key management consultants that prepare organizations through gap assessments, key ceremony design, HSM configuration reviews and documentation.
Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.
No firm has claimed a QPA consultant listing yet. Claim yours →
Software
Tools for QPA
Tools that name this framework in their own material.
No firm has claimed a QPA tool listing yet. Claim yours →
Related reading
- Navigating PCI PIN security requirementsA hardware security module maker explains the key management and HSM approval rules a PIN assessment turns on.Utimaco
- PCI PIN assessment FAQsAnswers the practical questions: who needs an assessment, how often, and what an assessor reviews on site.SecurityMetrics
Independent third-party explainers, chosen by hand. Not affiliated with this site and not paid placements. All links are nofollow.
Need a hand implementing it?
Find a Consultant for QPA
Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.
Not sure where to start?
Get Help with QPA
Tell us what you are trying to put in place. We will point you to the right tool, a consultant who can implement it, or both.