Frequently Asked Question

Is it permissible to use self-decrypting files for encryption to send cardholder data?

PCI DSS Requirement 4.1 states that transmission of cardholder data over an open or public network must be secured using strong cryptography and security protocols. Examples provided in the requirement include TLS, IPSEC, and SSH.

There may also be other protocols and processes that can meet the intent of this requirement.  Whichever method is used, it must meet all applicable requirements, including that only secure versions and configurations are supported, and that the proper encryption strength is implemented for the encryption methodology in use.

Refer to the PCI DSS and PA-DSS Glossary of Terms, Abbreviations, and Acronyms for additional information regarding “strong cryptography”.

May 2015
Article Number: 1075