Services
Services
SOC & Attestations
SOC & Attestations
Payment Card Assessments
Payment Card Assessments
ISO Certifications
ISO Certifications
Privacy Assessments
Privacy Assessments
Federal Assessments
Federal Assessments
Healthcare Assessments
Healthcare Assessments
Penetration Testing
Penetration Testing
Cybersecurity Assessments
Cybersecurity Assessments
Crypto and Digital Trust
Crypto and Digital Trust
Schellman Training
Schellman Training
ESG & Sustainability
ESG & Sustainability
AI Services
AI Services
Industry Solutions
Industry Solutions
Cloud Computing & Data Centers
Cloud Computing & Data Centers
Financial Services & Fintech
Financial Services & Fintech
Healthcare
Healthcare
Payment Card Processing
Payment Card Processing
US Government
US Government
Higher Education & Research Laboratories
Higher Education & Research Laboratories
About Us
About Us
Leadership Team
Leadership Team
Careers
Careers
Corporate Social Responsibility
Corporate Social Responsibility
Strategic Partnerships
Strategic Partnerships

What is Cardholder Data?

Payment Card Assessments | PCI DSS

Hi, I'm Matt Crane. I'm a leader in the Payment Security Practice, and today we're going to tackle what exactly cardholder data is because the PCI Council has introduced a new term in PCI DSS v4.0. But first, let's talk about PCI DSS v3.2.1, because--similar to the dinosaurs on my shirt in this video--some of the terminology in v3.2.1 is now extinct, as this version was officially retired on March 31, 2024.

Cardholder Data vs. Sensitive Authentication Data

That includes how the Council previously defined the broad concept of cardholder data under PCI DSS v4. The term "cardholder data" is still in use, but they're now lumping it under a larger term called "account data," of which there are two total subcategories:

Cardholder Data Sensitive Authentication Data (SAD)
  • Primary account number (PAN) service code*
  • Expiration date (sometimes referred to as expiry)
  • Cardholder name

* Only the primary account number needs to be encrypted--for the rest of your cardholder data, you must just meet the standard data protection rules in Requirement 3.

3 types of SAD: 

  • Full track data (or track data): Typically only found in card present transactions. And that's track being information on the magnetic strip or track equivalent data in the chip.
  • PIN (or PIN blocks): PINs for debit cards 
    (NOTE: For international organizations, the PIN can also be used for chip and PIN for credit card transactions.
  • Card Verification Codes: The 3- or 4-digit number on the front or back of the card (typically only used for card-not-present transactions over the Internet).

We hope that helps you gain a basic understanding of the new distinctions of account data--including what still counts as cardholder data and what's now SAD. But if you have any other questions,  feel free to reach out to us so we can set up some time to go over any other concerns you may have. 

About Schellman

Schellman is a leading provider of attestation and compliance services. We are the only company in the world that is a CPA firm, a globally licensed PCI Qualified Security Assessor, an ISO Certification Body, HITRUST CSF Assessor, a FedRAMP 3PAO, and most recently, an APEC Accountability Agent. Renowned for expertise tempered by practical experience, Schellman's professionals provide superior client service balanced by steadfast independence. Our approach builds successful, long-term relationships and allows our clients to achieve multiple compliance objectives through a single third-party assessor.