PCI 3DSEMV® 3-D SecureQualified 3DS AssessorQSA since 2014

Achieve PCI 3DS Compliance with Confidence: Partner with Expert 3DS Professional

Your business handles sensitive payment data daily. Don’t let compliance gaps put your reputation, finances, or customer trust at risk. Cianaa is a Qualified PCI 3DS Assessor securing EMV® 3-D Secure environments — ACS, DS, and 3DSS — across New Zealand, Australia, Asia Pacific, Europe, USA, and Canada.

PCI 3DS Components We Secure

EMV® 3-D Secure stack

ACS
Access Control ServerIssuer-side authentication
DS
Directory ServerRouting & coordination
3DSS
3DS ServerMerchant-side flow
Mandatory · not optional

Why Your Business Needs a Qualified 3DS Security Assessor (QSA)

The PCI 3DS assessment is required to ensure that organizations implementing EMV® 3-D Secure (3DS) technologies — specifically the Access Control Server (ACS), Directory Server (DS), and 3DS Server (3DSS) — are operating in a secure environment that protects sensitive 3DS data and processes.

Expertise You Can Trust

Our certified 3DS team deciphers complex PCI requirements into actionable steps.

Reduce Risk

Identify vulnerabilities before attackers do.

Build Customer Trust

Show clients you prioritize security.

Avoid Costly Breaches

Streamline compliance across both PCI DSS and 3DS standards.

3DS Assessment Coverage

Part 1 + Part 2: Full 3DS Requirement Coverage

Cianaa’s 3DS assessment covers both the baseline security controls (Part 1) and the 3DS-specific deeper controls (Part 2) — ensuring complete compliance for ACS, DS, and 3DSS environments.

3DS Assessment · Part 1

Baseline Security Requirements

Synopsis of requirements in Part 1 include:

  • Security Policies
  • Network Security
  • Secure Systems
  • Vulnerability Management
  • Access Management
  • Physical Security
  • Incident Response
3DS Assessment · Part 2

3DS Security Requirements

Exploring 3DS Security Depth: synopsis of requirements in Part 2 include:

  • Scope Validation
  • Security Governance
  • System Protection
  • Logical Access
  • Data Protection
  • Cryptography & Key Management
  • Physical Security for ACS/DS
PCI 3DS Assessment process

Simple Steps for PCI Assessment — with EMVCo Prerequisite

Here, you’ll find key details that highlight what we do and how we can help you. Our goal is to provide a clear procedure for assessments that resonate with your needs and simplify your journey with us.

Prerequisite — Obtain a Letter of Approval from EMVCo confirming compliance. Before our QSA assessment begins, you must hold an EMVCo Letter of Approval for the ACS, DS, or 3DSS components in scope.
01

Scoping

We identify all systems and devices that store, transmit, or process cardholder data.

02

Policy Review

We review to see that policies and procedures are updated for protecting cardholder data.

03

Compliance Checks

We review the environment using interviews, system assessment and documentation.

04

Annual Attestation

We also provide annual attestation after a PCI DSS assessment of the client annually.

Why choose us

Quick Answers to Your PCI 3DS Questions

What is PCI 3DS and why does it matter?

PCI 3DS is a security standard developed to protect environments that support EMV® 3-D Secure transactions — like authentication servers and systems used by banks and merchants. It ensures that sensitive data is handled securely during online cardholder authentication.

Who needs to comply with PCI 3DS?

Any organization that operates or provides services for 3DS components — such as Access Control Servers (ACS), Directory Servers (DS), or 3DS Servers (3DSS) — may be required to comply. Whether compliance is mandatory depends on the payment brand’s rule.

How is PCI 3DS different from PCI DSS?

PCI DSS focuses on protecting cardholder data across payment environments, while PCI 3DS specifically secures the systems and data involved in 3-D Secure authentication. Some requirements overlap, but PCI 3DS includes additional controls tailored to 3DS operation.

What are the benefits of PCI 3DS compliance?

Compliance helps protect customer data, reduce fraud, and build trust with payment brands. It also strengthens your organization’s security posture and may streamline integration with other PCI standards like PCI DSS.

Card · Get Better Awareness Today

Avoid Credit Card Scams

Understanding the threats helps reinforce why secure 3DS authentication matters. Here are six common attack vectors merchants and banks face today.

Skimming

Attaching a device to a card reader (such as an ATM or gas pump) that captures information from the magnetic strip on a credit card. A sophisticated attack that could happen.

Phishing

Fake emails or text messages that appear to be from a legitimate company, asking the recipient to provide sensitive information such as credit card numbers or login credentials.

Malware

Malicious software installed on a computer or device that can capture credit card information as it is entered. It also takes control of your machines through key loggers to extract information.

Physical Theft

Physically stealing credit cards or card information by pickpocketing or raiding mailboxes. This could still happen.

Card-not-present

Making purchases using stolen credit card information. This type of fraud is common for online or phone orders.

Web Skimming / Magecart

A sophisticated attack known as “web skimming” or “Magecart” — injecting malicious code into the website payment page to capture card data during checkout.

Ready to start your 3DS assessment

Achieve PCI 3DS Compliance with Confidence

Partner with a Qualified PCI 3DS Assessor. QSA-accredited since 2014. Covering ACS, DS, and 3DSS components across New Zealand, Australia, Asia Pacific, Europe, USA, and Canada.