WithPCI Logo
WithPCI.com

Requirement 6.5.5: Live PANs are not used in pre-production environments

Original requirement from PCI DSS v4.0.1

Defined Approach Requirements

6.5.5 Live PANs are not used in pre-production environments, except where those environments are included in the CDE and protected in accordance with all applicable PCI DSS requirements.

Customized Approach Objective

Live PANs cannot be present in pre-production environments outside the CDE.

Defined Approach Testing Procedures

6.5.5.a Examine policies and procedures to verify that processes are defined for not using live PANs in pre-production environments, except where those environments are in a CDE and protected in accordance with all applicable PCI DSS requirements.

6.5.5.b Observe testing processes and interview personnel to verify procedures are in place to ensure live PANs are not used in pre-production environments, except where those environments are in a CDE and protected in accordance with all applicable PCI DSS requirements.

6.5.5.c Examine pre-production test data to verify live PANs are not used in pre-production environments, except where those environments are in a CDE and protected in accordance with all applicable PCI DSS requirements.

Purpose

Use of live PANs outside of protected CDEs provides malicious individuals with the opportunity to gain unauthorized access to cardholder data.

Definitions

Live PANs refer to valid PANs (not test PANs) issued by, or on behalf of, a payment brand. Additionally, when payment cards expire, the same PAN is often reused with a different expiry date. All PANs must be verified as being unable to conduct payment transactions or pose fraud risk to the payment system before they are excluded from PCI DSS scope. It is the responsibility of the entity to confirm that PANs are not live.

purpose

Production data is not used for testing or development.

compliance strategies

  • Data masking
  • Synthetic test data

typical policies

  • Test Data Management Policy

common pitfalls

  • Live data in test/dev environments

type

Technical/Process Control

difficulty

Moderate

key risks

  • Sensitive data exposure in non-secure environments

recommendations

  • Mask or anonymize data before use in non-prod

Eligible SAQ

  • SAQ-D MERCHANT
  • SAQ-D SERVICE PROVIDER

Your perspective on this PCI DSS requirement matters! Share your implementation experiences, challenges, or questions below. Your insights help other organizations improve their compliance journey and build a stronger security community.Comment Policy