---
title: "Request for Comments: PTS HSM Security Requirements v4.0"
description: From 9 February to 11 March, specified PCI SSC stakeholders can participate in a Request for Comments (RFC) on the PTS HSM Security Requirements v4.0 draft.
image: https://blog.pcisecuritystandards.org/hubfs/2019_Blog%20Images/RFC-PTS-HSM-Security-Requirements-v4.jpg
---

[< Return to Blog Home](https://blog.pcisecuritystandards.org) [Print](https://blog.pcisecuritystandards.org/request-for-comments-pts-hsm-security-requirements-v4.0#)

# [Request for Comments: PTS HSM Security Requirements v4.0](https://blog.pcisecuritystandards.org/request-for-comments-pts-hsm-security-requirements-v4.0)

 Posted by [Lindsay Goodspeed](https://blog.pcisecuritystandards.org/author/lindsay-goodspeed) on 9 Feb, 2021 in [Participation](https://blog.pcisecuritystandards.org/topic/participation) and [Request for Comments](https://blog.pcisecuritystandards.org/topic/request-for-comments) and [PTS HSM](https://blog.pcisecuritystandards.org/topic/pts-hsm)

![RFC-PTS-HSM-Security-Requirements-v4](https://blog.pcisecuritystandards.org/hs-fs/hubfs/2019_Blog%20Images/RFC-PTS-HSM-Security-Requirements-v4.jpg?width=800&name=RFC-PTS-HSM-Security-Requirements-v4.jpg "RFC-PTS-HSM-Security-Requirements-v4")

<https://www.linkedin.com/shareArticle?mini=true&url=https://blog.pcisecuritystandards.org/request-for-comments-pts-hsm-security-requirements-v4.0>

<https://www.facebook.com/share.php?u=https://blog.pcisecuritystandards.org/request-for-comments-pts-hsm-security-requirements-v4.0>

<https://twitter.com/intent/tweet?original_referer=https://blog.pcisecuritystandards.org/request-for-comments-pts-hsm-security-requirements-v4.0&url=https://blog.pcisecuritystandards.org/request-for-comments-pts-hsm-security-requirements-v4.0&source=tweetbutton&text=Request%20for%20Comments:%20PTS%20HSM%20Security%20Requirements%20v4.0> 

[mailto:?subject=Check%20out%20this%20article&body=https://blog.pcisecuritystandards.org/request-for-comments-pts-hsm-security-requirements-v4.0](mailto:?subject=Check%20out%20this%20article&body=https://blog.pcisecuritystandards.org/request-for-comments-pts-hsm-security-requirements-v4.0)

 

PTS Vendors who are [Participating Organizations](https://www.pcisecuritystandards.org/get_involved/participating_organizations) and PCI Recognized labs are invited to review and provide feedback on the draft PCI PIN Transaction Security (PTS) Hardware Security Module (HSM) Modular Security Requirements during a 30 day [request for comments](https://www.pcisecuritystandards.org/get_involved/request_for_comments) (RFC) period running from 9 February 2021 through 11 March. This is the first of two RFCs for v4.0 of the requirements. A second RFC is planned in Q3 and will be open to all PCI SSC Participating Organizations and Assessors.

The RFC will be available to primary contacts through the [PCI SSC portal](https://programs.pcissc.org/), including instructions on how to access the document and submit feedback. Eligible stakeholders will also receive instructions via email. As a reminder, participants are required to accept a Non-Disclosure Agreement (NDA) to download the document. Please review the [RFC Process Guide](https://www.pcisecuritystandards.org/pdfs/RFC_Process_Guide.pdf) for more information.

***Please note that PCI SSC can only accept comments that are submitted via the PCI SSC portal and received within the defined RFC period. ***

**Background on the PTS HSM Security Requirements**  
PTS HSM Security Requirements are designed to ensure HSM devices provide the strongest protection for critical data elements used in card verification, PIN processing, chip transaction processing, payment card personalization, secure cryptographic key loading, remote HSM administration and other payment and authentication activities.

The updates in the RFC are designed to address industry needs by:

- Adding a new module for Cloud Based HSMs as a Service – Multi-tenant Usage Security Requirements
- Requiring support for ANSI and ISO standards based Key Blocks
- Requiring support for AES

Please review the [RFC Process Guide](https://www.pcisecuritystandards.org/pdfs/RFC_Process_Guide.pdf)  and our resource guide: [What to Know Before Participating in a PCI SSC RFC](https://blog.pcisecuritystandards.org/what-to-know-before-participating-in-a-pci-ssc-rfc) for more information on the PCI SSC RFC process.

[![Access the PCI SSC portal and provide comments](https://no-cache.hubspot.com/cta/default/281302/c57a5715-e372-452d-8722-cc618fd9c4bd.png)](https://cta-redirect.hubspot.com/cta/redirect/281302/c57a5715-e372-452d-8722-cc618fd9c4bd)

### LIKE WHAT YOU READ?

Subscribe to the PCI Perspectives blog to receive insights, information and practical resources to help your organization protect payment data.

[Subscribe Here](https://training.pcisecuritystandards.org/subscribe-to-pci-perspectives-blog)

![Lindsay Goodspeed](https://blog.pcisecuritystandards.org/hubfs/Headshots/lindsay-goodspeed.jpg)

[ Lindsay Goodspeed ](https://blog.pcisecuritystandards.org/author/lindsay-goodspeed)

[Twitter ](https://twitter.com/PCISSC) [LinkedIn](https://www.linkedin.com/in/lindsaygoodspeed) [Email](mailto:blog@pcisecuritystandards.org) [Website](https://www.pcisecuritystandards.org/)

 As Senior Manager, Corporate Communications for the Council, Ms. Goodspeed drives awareness of PCI Security Standards and resources for the protection of payment card data.

[< Return to Blog Home](https://blog.pcisecuritystandards.org) [Print](https://blog.pcisecuritystandards.org/request-for-comments-pts-hsm-security-requirements-v4.0#)