In this article
Share
The Payment Card Industry Security Standards Council (PCI SSC) published PCI PIN Transaction Security Version 7.0 (PCI PTS v7) in May 2025. PCI SSC describes the standard as “a major revision” to PCI PTS v6.2, with 59 requirement changes and 23 additions to guidance. Key changes address physical tampering and malware attacks in addition to guidance for biometric interfaces, third-party applications, stronger cryptography, and accessible PIN entry.
PCI SSC developed the changes after two Request for Comment (RFC) periods in 2024. Device manufacturers, payment service providers (PSPs), application developers, merchants, and other payment stakeholders contributed feedback on testing, implementation, and current security needs. Feedback from merchants also helped to shape the new standard by providing a frontline view of the biggest security threats they face.
Who Is Most Affected by the Transition to PCI PTS v7?
Changes impact device manufacturers, payment service providers (PSPs), and application developers, and, subsequently, payment estate managers. However, the publication of PCI PTS v7 has the most immediate impact on payment device manufacturers because new products must be designed, tested, and approved against the updated requirements. Manufacturers may need to update application signing, cryptographic key management, device authentication, physical security, and application isolation controls. PCI SSC’s RFC periods in 2024 gave stakeholders insight into the changes that were coming and the opportunity to prepare before publication.
Payment device estate managers will also have to make changes to their payment environments to fully benefit from PCI PTS v7. For example, estate managers that upgrade from legacy devices can transition to stronger secure transport protocols such as Transport Layer Security (TLS) v1.3. PCI PTS v7 also lays the groundwork for post-quantum cryptography (PQC) with cryptographic agility and stronger key protection. PQC is currently an area of development in the payments industry, and Ingenico is working to ensure it is available in advance of “Q-Day,” when quantum computers become powerful enough to break public-key encryption.
PCI listings include optional post-quantum support for version 7 and later devices, so buyers should review each device listing and security policy rather than assume that all version 7 devices provide the same capabilities. Organizations should also assess application isolation, biometric interfaces, remote management, and connected peripheral security as part of the wider deployment design.
How Does PCI PTS 7 Compare to PCI PTS 6?
Since PCI published PCI PTS v6 in 2020, the payments industry, merchant demands, and threat landscape have continued to evolve. In addition to enabling new, stronger cryptography options, PCI PTS v7 addresses additional areas of potential risk.
|
Security Area |
PCI PTS 6 |
PCI PTS 7 |
|---|---|---|
| Biometric interfaces | No support options for biometric interfaces | New biometric physical and logical security requirements |
| Third-party applications not signed with vendor tools | Not supported | Optional support if the device provides an isolated execution environment |
| Cryptographic keys | Top-level keys must have an effective bit-strength of 112 bits or stronger | Top-level keys must have an effective bitstrength of 128 bits or stronger |
| Accessible PIN entry | No support options for accessible PIN entry functions. | Optional accessible PIN entry that may be enabled for an individual transaction |
Version 7 introduces explicit support for third-party applications. This support is optionally available on devices approved and listed on the PCI List of Approved PTS Devices with the relevant feature notation. The difference from PCI PTS v6 is that in v7 it is permissible to have an isolated operating environment for these applications that is restricted from permitting access to cardholder data. These applications must still be signed. However, signing of Third-Party Applications can be done with non-manufacturer tools (e.g., Android Studio, DocuSeal, etc.) with less stringent controls like single-control signing using software-based cryptographic processing, and credentials which are not necessarily issued by the terminal vendor. This provision in v7 enables support for functions such as loyalty, inventory, employee management, or customer engagement without giving those applications access to sensitive payment information.
A Look Back at the Evolving Legacy Standards and PCI PTS v7 Timeline
To keep up with changing industry demands and threats to payment data, standards typically sunset and updated guidance takes their place. At any given time, devices with legacy PTS standards are operating compliantly since device approval lifecycles last about 10-12 years. Furthermore, due to the global pandemic, supply chain disruptions, and other factors, PCI PTS v5 device approval was extended for one year to April 30, 2027, and PCI PTS v6 security requirements for new approvals run until June 30, 2026, and device approvals will not expire until April 2032.
So even if a device is running on an older version, this should not be interpreted as a security weakness. Current standards protect from current threats, and PCI PTS v7, with support for PQC, is forward-looking. At the same time, PCI is considering a move away from a fixed cadence of standards updates to a more agile model in which they publish changes in response to the payments environment rather than evolving to a fixed 3-year schedule. PCI may decide to update PCI PTS v7 with a series of minor releases rather than proceed to a wholesale change in 2028.
PCI PTS is just one element of the PCI standards ecosystem. While PCI PTS secures the “point of interaction” hardware layer, the PCI Data Security Standard (PCI DSS) governs the broader payment processing environment. Historically, these two standards have been applied in isolation from each other and sometimes in contradiction of each other. Now we are starting to see the introduction of a new set of supportive PCI Standards that pull common best practices into new single reference standards that can be referred to by PCI PTS and PCI DSS to ensure consistency throughout the industry. Standards such as the PCI Secure Software Standard and the soon-to-be-published PCI Key Management and Operations (PCI KMO) Standard lead the way in filling this role.
Which PCI PTS Version-Approved Device Do You Put on the Counter?
Payment estate managers, as well as the vendors and PSPs who provide solutions and services to them, must decide when to upgrade to PCI PTS v7-approved devices and when to continue operating with PCI PTS v6-approved devices. For new deployments, version 7 generally offers the longest approval horizon and access to the latest security options. Merchants with version 6 estates or earlier can create a risk-based upgrade roadmap that considers device age, vendor support, firmware expiry, operational needs, and deployment cost.
Ingenico can help develop a strategy that gives your payment device estate the functionality, security controls, and supported lifecycle your business requires. Learn more about Ingenico’s PCI PTS v7-approved devices or contact our team to discuss a deployment and upgrade plan.