Get Demo
↑

PCI DSS Requirement 3: Protecting Stored Account Data

PCI DSS v4.0.1 Requirement 3 - minimize storage, never keep SAD after auth, mask PAN displays, render stored PAN unreadable, manage crypto keys.

Published: September 2026 Compliance · PCI DSS 8-12 min read

PCI DSS Requirement 3 in v4.0.1 is titled Protect Stored Account Data. It covers minimizing what you keep, never retaining SAD after authorization, restricting full-PAN displays, rendering stored PAN unreadable, and managing cryptographic keys.

Related: Requirement 4 (in transit) · v4.0.1 what changed.

v4.0.1 note: PCI SSC clarified issuer applicability and keyed cryptographic hash guidance for rendering PAN unreadable. Clause IDs below match the standard; 3.6.1.4 uses “fewest possible locations” for key storage.

Requirement 3 Structure

Clause
Focus
3.1
Processes and mechanisms for protecting stored account data
3.2
Storage of account data kept to a minimum (3.2.1 retention/disposal)
3.3
SAD is not stored after authorization
3.4
Access to full PAN displays and copy ability is restricted
3.5
PAN is secured wherever stored
3.6-3.7
Cryptographic key protection and key lifecycle management

Deep Dives

How CyberSilo Helps

Map PCI DSS v4.0.1 Controls to Continuous Evidence

CyberSilo CSA and ThreatHawk SIEM help US merchants and service providers collect QSA-ready evidence across the 12 requirements.

Frequently Asked Questions

What is SAD versus account data?

Sensitive authentication data (SAD) includes full track data, card verification codes, and PINs/PIN blocks (3.3.1.1-3.3.1.3). Account data is broader; PAN storage is governed by 3.5.x.

Is full-disk encryption enough to protect stored PAN?

Not by itself on non-removable media. 3.5.1.2 limits disk/partition encryption as the sole PAN protection; PAN must also meet 3.5.1 (for example field-level crypto or truncation) on non-removable storage.

What does “masking” require on displays?

3.4.1: when displayed, BIN and last four digits are the maximum most personnel may see; only roles with documented business need may see more.

PCI DSS hub · PCI DSS v4.0.1: What Changed · USA v4.0.1 services

📰 More from CyberSilo

Latest Articles

Stay ahead of evolving cyber threats with our expert insights

✅ Link copied!