As financial services organizations strengthen authentication and fraud prevention, passwords and other knowledge-based security methods are increasingly being questioned. Consumers frequently reuse passwords and PINs across multiple accounts, while data breaches and information available on the dark web have made many traditional credentials easier for criminals to obtain. Against that backdrop, the introduction of a unified PIN security standard from X9 and the PCI Security Standards Council highlights an interesting tension: the payments industry must continue protecting PIN-based transactions even as broader authentication strategies increasingly move beyond “what you know” toward stronger methods of verifying identity.
While a clear consensus has been established that passwords are a terrible security solution, X9 and the PCI council have published a new PIN standard. While we haven’t yet read the 233 page “Payment Card Industry (PCI) PIN Security” paper, it appears to be out of synch with the overall market effort to move away from using “what you know” identity solutions.
Here’s an excerpt from a PaymentsSource article which covers the topic further:
“Seeking to clarify how merchants and banks should handle PIN debit transactions, the Accredited Standards Committee X9 and PCI Security Standards Council have created a unified standard.
Since 2018, X9 and the PCI council have been partners in combining technical reports, requirements and testing procedures to begin a joint initiative that would eliminate the need for separate standards and processes related to accepting PIN transactions and keeping PINs safe.
Ultimately, the security organizations worked to merge their processes into one document, which has become version 3.0 of the PCI council’s PIN Security requirements and testing standard.
With much of the X9 standard becoming outdated during the process, X9 approved its withdrawal from the publication to establish a new, unified single standard. X9 will continue to partner with the PCI council on future versions of the standard.
The organizations said they reached their goal to create a single PIN security standard and assessor qualification program that PCI SSC would manage.”
With the amount of information available on the dark web, combined with the bad habit people have of re-using the same PIN and password for multiple sites, has made out of wallet questions, passwords, and PINs problematic.
The creation of a unified PIN security standard should simplify how merchants, financial institutions, and assessors approach the protection of PIN transactions. Combining previously separate requirements and testing procedures into a single framework could provide greater consistency and eliminate outdated or overlapping standards.
However, stronger standards for protecting PINs do not address the fundamental weaknesses associated with knowledge-based authentication. Consumers routinely reuse PINs and passwords, while criminals have access to an enormous amount of compromised personal information that can undermine passwords, security questions, and other traditional authentication methods.
As fraud threats continue to evolve, the payments industry will need to look beyond simply improving the security surrounding existing credentials. Biometrics, device intelligence, behavioral analytics, and other authentication technologies can provide additional layers of protection without relying entirely on information a consumer must remember. PINs will likely remain part of the payments ecosystem for some time, making strong PIN security standards necessary. But the longer-term direction of authentication is likely to involve reducing dependence on “what you know” and embracing more sophisticated methods of determining whether someone attempting a transaction is actually the authorized user.
Overview by Tim Sloane, VP, Payments Innovation at Mercator Advisory Group








