1. Cryptographic Inventory & CBOM (PCI DSS Req 4.2.1.1 & 12.3.3)
Under active QSA enforcement of PCI DSS v4.0.1 (specifically Requirements 4.2.1.1 and 12.3.3, strictly mandatory since March 31, 2025): QSAs actively issue formal findings of QSA non-conformance if an automated, machine-readable Cryptographic Bill of Materials (CBOM) is missing across Cardholder Data Environment (CDE) switches. Do you maintain an automated, machine-readable inventory?
2. Asymmetric Public-Key Algorithms in Transaction Routing
What cryptographic algorithms protect authorization messages between your API gateways, merchant endpoints, and clearing switches?
3. Cardholder Data Retention Window & HNDL Risk Exposure
How long are encrypted Primary Account Numbers (PANs), cardholder metadata, or tokenization mapping tables retained in your databases and backup archives?
4. Payment HSMs, TR-31 Key Blocks & Storage Capacity (PCI PTS HSM v5.0)
Under PCI PTS HSM v5.0, PCI PIN Security Phase 3 (TR-31 key block wrapping mandate), and the September 2026 NIST FIPS 140-2 sunset, have you evaluated your HSM fleet (Thales payShield, Atalla AT1000, IBM Crypto Express CEX cards) for ML-KEM-768 key block database bloat (1,184-byte keys causing 7.4× storage expansion)?
6. Legacy Heavy Iron & Switch Crypto-Agility (IBM zSystems & HP NonStop)
Are cryptographic calls decoupled via an abstraction layer across your core transaction infrastructure (e.g. IBM zSystems mainframes, HP NonStop Tandem servers running BASE24, or cloud microservices)?
7. Third-Party Vendor & Card Scheme Dependencies
Have you audited whether your upstream payment processors, card brand connections, and SaaS tokenization vendors support PQC algorithms?
8. C-Suite, QSA & CNSA 2.0 Post-Quantum Migration Strategy
Does your organization have a board-approved post-quantum migration budget and roadmap aligned with the January 1, 2027 CNSA 2.0 Procurement Gate, active PCI DSS Req 12.3.3 cipher review standards, and QSA expectations?