SchellmanCON is back! Join us for our virtual conference on March 6 & 7, 2025

Contact Us
Services
Services
Crypto and Digital Trust
Crypto and Digital Trust
Schellman Training
Schellman Training
Sustainability Services
Sustainability Services
AI Services
AI Services
About Us
About Us
Leadership Team
Leadership Team
Corporate Social Responsibility
Corporate Social Responsibility
Careers
Careers
Strategic Partnerships
Strategic Partnerships

Payment Card Assessments

EMV 3 Domain Secure

PCI 3DS is a messaging protocol that enables consumers to authenticate with their card issuer when making card-not-present e-commerce purchases.

Contact a Specialist

Why PCI 3DS?

Having an additional security layer assists in preventing unauthorized card-not-present transactions and protects the merchant from exposure to fraud. There are three (3) domains within the standard, consisting of the merchant/acquirer, issuer, and interoperability domain (e.g. payments systems). Schellman 3DS assessors can assist in navigating Parts 1 and 2 of a customer's 3DE (3DS environment) and assessing the appropriate requirements.

Our Process

The PCI 3DS Program is designed to be a set of procedural and security requirements supporting the 3-D Secure - Protocol and Core Functions Specification requirements set forth by EMVCo. The goal of 3DS is to support app-based authentication and integration with digital wallets and traditional browser-based e-commerce transactions. Consisting of Parts 1 and 2, the PCI 3DS Program supports the security requirements and assessment procedures for a customer's 3DE (3DS environment) that may consist of one or more of the following: the Access Control Server (ACS), Directory Server (DS), and 3DS Server. Part 1: The Baseline Security Requirements looks and feels similar to a PCI DSS assessment, while Part 2: 3DS Security Requirements looks at the specific functionality of the 3DS components and their interworkings.

Image

Planning

After the agreement is executed, the first phase of the engagement is planning. This is to ensure that Schellman and the Client are fully aware of the what, who, when, why, and how prior to the beginning of testing.

Proper planning is imperative to the success of a project. Schellman has standard processes to cover the important pieces of the engagement.

Image

Understanding and Kickoff

The kickoff is considered the start of the engagement. If needed, Schellman will schedule a call at the beginning of, or just prior to, the kickoff to finalize any outstanding items. Schellman will be available to the client with any questions.

By including communication prior to starting, Schellman ensures that no last -minute changes to the project or team have occurred and the Client has the plan prior to the testing and on-site visit.

Image

Testing and Gathering

Testing and gathering is the core of the compliance engagement. Due to the planning and understanding processes, this phase will be an accumulation of gathering the evidence needed for the objectives discussed.

Schellman provides comprehensive solutions for all PCI standards including PCI DSS, which can be used in place of Part 1 if the 3DS environment is physically and logically located within a customer's CDE. If we are performing the DSS and 3DS assessments in tandem, we can help identify areas and provide guidance as to where we can leverage information from DSS.

Image

Reporting

Schellman’s testing methodology ends with reporting, but the entire assessment is focused on creating a deliverable that is clear, concise, and accurate.

Schellman’s report takes into account the entire process and customizes a report for each Client. The draft report will be provided within 2 weeks of the last day of testing and gathering phase, and a final report will be provided within 30 days. This timing is unsurpassed by the industry.

Contact a Specialist

Joe O'Donnell

Joe O'Donnell is a Manager with Schellman mainly dedicated to the PCI and PCI specialty service lines. Before focusing his career on IT auditing services, Joe worked as an Enterprise Operations Computing Analyst where he gained experience in IT systems analysis and data center operations.

Meet Joe Contact Us

  • Fixed-Fee Using an outcome based, fixed-fee pricing model based on our extensive experience
  • Scope Creep We see less than 5% of our clients that see amendments and are often the result of a scope expansion
  • Low Overhead Low overhead means a flexible financial structure

How much will your audit cost?

Whether it is an ISO 27001 certification, SOC 2 examination or a FedRAMP assessment, companies are often challenged by the need to address customer requirements while ensuring a return on compliance investment.

The most important factor in scoping a potential assessment is understanding what deliverable the recipient (i.e. your customer or partner) is expecting.

Once we have scoped your environment and needs, there are several factors that contribute to Schellman’s pricing:

  • Fixed-Fee Using an outcome based, fixed-fee pricing model based on our extensive experience
  • Scope Creep We see less than 5% of our clients that see amendments and are often the result of a scope expansion
  • Low Overhead Low overhead means a flexible financial structure
Don't see a service you're interested in? 

Talk to a Practice Leader