Requirement 4: Protect cardholder data with strong cryptography during transmission over open, public networks
Card data in transit over public networks must be encrypted so it cannot be intercepted.
Sub-requirements
4.1
Processes and mechanisms are defined and understood
2 defined requirementsDocument transmission-security policy.
View defined requirements →4.2
PAN is protected with strong cryptography during transmission
4 defined requirementsUse strong TLS, accept only trusted keys/certificates, and maintain an inventory of where PAN is sent.
View defined requirements →Tips
- ›Enforce TLS 1.2+ and disable weak ciphers; test with a TLS scanner.
- ›Cover email and messaging, never send unprotected PAN over them.
Evidence to keep
- ✓TLS configuration/scan results
- ✓Inventory of PAN transmission paths
- ✓Transmission policy
Example
All payment traffic uses TLS 1.3 with modern ciphers, certificate validation is enforced, and weak protocols are disabled at the load balancer.
Policy templates for this control
Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.
Cryptography and key management policyUse for ISO 27001 A.8.24, secure authentication, encryption, SOC 2 Security, and PCI DSS encryption requirements.AI use and governance policyUse for ISO 42001, AI governance, employee AI use, data handling, human review, and AI supplier risk.Email and communications security policyUse for ISO 27001 A.5.14 and A.8.24, information transfer, encryption in transit, phishing response, and SOC 2 communication controls.Asset management policyUse for ISO 27001 A.5.9, A.5.10, A.5.11, A.7.9 to A.7.14, SOC 2 Security, and PCI DSS asset inventory expectations.
Open the control-to-policy map