Reset to Today

To access the FCA Handbook Archive choose a date between 1 January 2001 and 31 December 2004.

Content Options:

Content Options

View Options:


You are viewing the version of the document as on 2021-03-03.

Alternative versions

  1. Point in time
    2021-03-03

Chapter 4 Confidentiality and integrity of the payment service users’ personalised security credentials

Article 22 General requirements

  1. (1)

    Payment service providers shall ensure the confidentiality and integrity of the personalised security credentials of the payment service user, including authentication codes, during all phases of the authentication.

  2. (2)

    For the purpose of paragraph 1, payment service providers shall ensure that each of the following requirements is met:

    1. (a)

      personalised security credentials are masked when displayed and are not readable in their full extent when input by the payment service user during the authentication;

    2. (b)

      personalised security credentials in data format, as well as cryptographic materials related to the encryption of the personalised security credentials are not stored in plain text;

    3. (c)

      secret cryptographic material is protected from unauthorised disclosure.

  3. (3)

    Payment service providers shall fully document the process related to the management of cryptographic material used to encrypt or otherwise render unreadable the personalised security credentials.

  4. (4)

    Payment service providers shall ensure that the processing and routing of personalised security credentials and of the authentication codes generated in accordance with Chapter 2 take place in secure environments in accordance with strong and widely recognised industry standards.

Chapter 4 Confidentiality and integrity of the payment service users’ personalised security credentials

Article 22 General requirements

  1. (1)

    Payment service providers shall ensure the confidentiality and integrity of the personalised security credentials of the payment service user, including authentication codes, during all phases of the authentication.

  2. (2)

    For the purpose of paragraph 1, payment service providers shall ensure that each of the following requirements is met:

    1. (a)

      personalised security credentials are masked when displayed and are not readable in their full extent when input by the payment service user during the authentication;

    2. (b)

      personalised security credentials in data format, as well as cryptographic materials related to the encryption of the personalised security credentials are not stored in plain text;

    3. (c)

      secret cryptographic material is protected from unauthorised disclosure.

  3. (3)

    Payment service providers shall fully document the process related to the management of cryptographic material used to encrypt or otherwise render unreadable the personalised security credentials.

  4. (4)

    Payment service providers shall ensure that the processing and routing of personalised security credentials and of the authentication codes generated in accordance with Chapter 2 take place in secure environments in accordance with strong and widely recognised industry standards.

Article 23 Creation and transmission of credentials

Payment service providers shall ensure that the creation of personalised security credentials is performed in a secure environment.

They shall mitigate the risks of unauthorised use of the personalised security credentials and of the authentication devices and software following their loss, theft or copying before their delivery to the payer.

Article 24 Association with the payment service user

  1. (1)

    Payment service providers shall ensure that only the payment service user is associated, in a secure manner, with the personalised security credentials, the authentication devices and the software.

  2. (2)

    For the purpose of paragraph 1, payment service providers shall ensure that each of the following requirements is met:

    1. (a)

      the association of the payment service user’s identity with personalised security credentials, authentication devices and software is carried out in secure environments under the payment service provider’s responsibility comprising at least the payment service provider’s premises, the internet environment provided by the payment service provider or other similar secure websites used by the payment service provider and its automated teller machine services, and taking into account risks associated with devices and underlying components used during the association process that are not under the responsibility of the payment service provider;

    2. (b)

      the association by means of a remote channel of the payment service user’s identity with the personalised security credentials and with authentication devices or software is performed using strong customer authentication.

Article 25 Delivery of credentials, authentication devices and software

  1. (1)

    Payment service providers shall ensure that the delivery of personalised security credentials, authentication devices and software to the payment service user is carried out in a secure manner designed to address the risks related to their unauthorised use due to their loss, theft or copying.

  2. (2)

    For the purpose of paragraph 1, payment service providers shall at least apply each of the following measures:

    1. (a)

      effective and secure delivery mechanisms ensuring that the personalised security credentials, authentication devices and software are delivered to the legitimate payment service user;

    2. (b)

      mechanisms that allow the payment service provider to verify the authenticity of the authentication software delivered to the payment services user by means of the internet;

    3. (c)

      arrangements ensuring that, where the delivery of personalised security credentials is executed outside the premises of the payment service provider or through a remote channel:

      1. (i)

        no unauthorised party can obtain more than one feature of the personalised security credentials, the authentication devices or software when delivered through the same channel;

      2. (ii)

        the delivered personalised security credentials, authentication devices or software require activation before usage;

    4. (d)

      arrangements ensuring that, in cases where the personalised security credentials, the authentication devices or software have to be activated before their first use, the activation shall take place in a secure environment in accordance with the association procedures referred to in Article 24.

Article 26 Renewal of personalised security credentials

Payment service providers shall ensure that the renewal or re-activation of personalised security credentials adhere to the procedures for the creation, association and delivery of the credentials and of the authentication devices in accordance with Articles 23, 24 and 25.

Article 27 Destruction, deactivation and revocation

Payment service providers shall ensure that they have effective processes in place to apply each of the following security measures:

  1. (a)

    the secure destruction, deactivation or revocation of the personalised security credentials, authentication devices and software;

  2. (b)

    where the payment service provider distributes reusable authentication devices and software, the secure re-use of a device or software is established, documented and implemented before making it available to another payment services user;

  3. (c)

    the deactivation or revocation of information related to personalised security credentials stored in the payment service provider’s systems and databases and, where relevant, in public repositories.