Skip to content

    How Tokenization and PCI Compliance Impact a Fintech

    Tokenization and PCI Compliance

    The data security rules around payments can be puzzling to new and seasoned payments professionals alike. If your fintech touches card data, whether it be issuing, processing, or storing it, PCI compliance isn’t optional.

    And being non-compliant is expensive. While the Payments Card Industry Data Security Standard (PCI DSS) outlines encryption best practices for meeting PCI compliance, much can be left up to interpretation.

    Tokenization is the fastest way to shrink a PCI compliance burden.

    What is payment tokenization? 

    Payment tokenization replaces sensitive payment information, such as a credit card number, with a unique identifier or token that can be used for payment transactions. The tokenization process creates a random string of characters that represents the actual payment information, which is stored in a secure token vault. The token can then be used to process payments, without exposing the actual card information to potential attackers or fraudsters.

    Tokenization is used to secure online, in-app, and mobile payments, where sensitive payment data is transmitted across multiple devices and networks. By tokenizing payment data, fintechs can reduce the risk of data breaches, pass cards downstream, and keep sensitive customer information protected.

    Return to Top

    Is tokenization of payments data PCI compliant? 

    Yes, tokenization is a PCI-compliant way to secure and mask sensitive cardholder data (CHD) under PCI DSS Requirement 3.

    Encryption, masking, hashing, and tokenization are critical ways to protect account data and are necessary for maintaining compliance. Tokenization, in particular, replaces the sensitive cardholder data with an irreversible token that would be effectively useless should malicious individuals come into contact with it.

    However, the implementation of the tokenization must also be compliant. For instance, if you are leveraging a third-party tokenization provider for secure CHD storage, known as a cardholder data environment (CDE), that CDE must also meet PCI compliance requirements. While you may build the CDE in-house, building and maintaining the necessary infrastructure and programs can require hundreds of thousands of dollars and months to implement and assess. Third-party tokenization providers, like Basis Theory, provide the platform, infrastructure, and tools to secure cardholder data in minutes without these costs and distractions.

    Return to Top

    Does tokenization reduce PCI compliance burden? 

    When used effectively, tokenization can reduce PCI compliance burden, but it won’t eliminate it completely. This will, however, reduce PCI compliance scope and potentially shift the compliance burden onto a third party.

    Reduced Scope: Because you replace the sensitive card data with tokens and don't store sensitive cardholder data (CHD) in your systems, you will reduce the compliance scope of your systems. This translates to fewer PCI requirements you need to comply with.

    Shifted Responsibility: When you use a tokenization service, the responsibility for storing and securing the actual card numbers often falls on the tokenization provider. These providers are typically PCI DSS compliant and specialize in securing sensitive data. This can lessen the burden on your business to maintain strict PCI compliance for card data storage.

    Marble, an insurtech platform that helps members manage and pay for insurance policies, wanted to reduce its PCI burden. As Matt Donofrio, Head of Revenue at Marble explains, offloading PCI compliance responsibilities to Basis Theory was preferred, while their team kept building its customer experience.

    “We needed a solution that we could implement quickly and was not super operationally heavy,” Donofrio says. “It was clear to me that Basis Theory was what we needed, and I’d be hard pressed to think there’s something more relevant to what we were trying to solve—which was to maintain PCI compliance.”

    As a PCI Level 1 compliant service provider, Basis Theory combines a suite of configurable tools, services, and tokens for companies to collect, secure, and share credit card data without bringing their systems into PCI scope. This approach allows companies to stop storing credit card data on paper, through email, and avoid many of the costs associated with nearly 95% of the PCI requirements.

    Return to Top

    What are my options for payment tokenization? 

    There are effectively three payment token types that are used during tokenization: universal tokens, payment service provider tokens, and network tokens.

    • Universal Tokens: These tokens are designed to be used across various different channels, payment networks, and processors without needing to be recreated or replaced.
    • PSP Tokens (Payment Service Provider Tokens): These tokens are issued by a specific payment service provider (PSP) and are only valid within that provider's network. They are convenient for transactions processed through that particular PSP but limit usability with other providers.
    • Network Tokens are issued directly by card networks like Visa, Mastercard, or Amex. They are designed to replace the card details and can be used with any PSP or acquirer connected with the issuing network. They offer wider acceptance within the network but might not be compatible with all processors.

    For a fintech that needs to operate with raw card data, not just display it, a programmable vault can sit between you and your issuer or processor. This would allow for tokenization at the moment of capture, but still route the raw payment data to any downstream service.

    We created a guide to PCI that goes into each of the 12 requirements of PCI DSS, its history, what is in scope, and what this means for a fintech.

    If you are ready to get started with a programmable vault, sign in to the portal and start testing. Paste our documentation into your favorite coding agent and get started.

    Return to Top

    Stay Connected

    Receive the latest updates straight to your inbox