Skip to content

Payments

PCI-DSS 4.0 crypto agility

PCI-DSS 4.0 emphasizes crypto agility — knowing what algorithms you use and planning migration before assessors ask.

Framework

Cryptographic agility and key management requirements

Deadline: 2025–ongoing

Executive summary

PCI-DSS version 4.0 strengthens requirements around cryptographic key management, inventory, and agility. Regional banks and payment processors must document cryptographic implementations protecting cardholder data — and demonstrate ability to migrate algorithms as standards evolve.

What QSAs probe

  • TLS configurations on payment application boundaries
  • Key management for encryption of stored cardholder data
  • Use of deprecated algorithms (SSL, early TLS, weak ciphers)
  • Readiness to adopt industry-standard replacements — including post-quantum algorithms on NIST timeline

Inventory scope for banks

  • External TLS for customer-facing banking APIs
  • JWKS endpoints for OAuth and Open Banking integrations
  • Email STARTTLS for statements and notifications
  • Third-party payment gateway dependencies

Qtangl mapping

TLS + JWKS + STARTTLS inventory, PCI-relevant control mapping in compliance pack, signed report for QSA review via /verify. Monitor tier tracks drift between annual assessments.

Migration path

  1. Baseline inventory with algorithm tags
  2. Prioritize external TLS and API signing keys
  3. Pilot hybrid ML-KEM on non-production payment APIs
  4. Re-scan and attach proof before QSA interview

Qtangl mapping

  • TLS + JWKS + email STARTTLS inventory
  • PCI-DSS 4.0 control mapping in compliance pack
  • Signed report for assessor review via /verify

References & further reading

Authoritative primary sources cited in this article. Summaries are our own — follow links for full context.

Last verified 2026-06-03