Sunday, 13 September 2026
Nigeria Communications Week
E-Financial

Concerns as Banks March Slowly to PCIDSS Version 3.1 Certification

Comms Week2 Aug 20150 Comments
Concerns as Banks March Slowly to PCIDSS Version 3.1 Certification
Kindly share this post

Fidelity and Sterling banks are the only two money deposit banks in the country  that have completed certification of Payment Card Industry Data Security Standards (PCI DSS) version 3.1, the…

Fidelity and Sterling banks are the only two money deposit banks in the country  that have completed certification of Payment Card Industry Data Security Standards (PCI DSS) version 3.1, the latest security measure aimed at waging off hackers from their system, Nigeria CommunicationsWeek can report.

First Bank, Standard Chartered and Wema bank are at various stages in the completion of the certification for the framework for ensuring that critical information assets are protected from unauthorized access, use, disclosure, disruption, modification, perusal, inspection, recording or destruction.

The major global payment brands require that every entity including financial institutions as well as merchants and service providers stores, processes, or transmits payment card data, in every channel including catalogue and online retailers as well as brick-and-mortar businesses -- must be in compliance with the PCI Data Security Standard.

Oluseyi Akindeinde, chief technical officer, Digital Encode, a company that assist banks and other organisations to achieve PCI DSS, said though there is no deadline by CBN to banks on this version, but it is mandatory for banks to upgrade to this version as a security measure to protect their customers against external fraud.

He added that, PCI DSS Version 3.1 is just an update to the already existing PCI DSS version 3.0.

“It was brought about by the ever evolving and changing sphere of information security. It has updated a few of the objectives and added new controls in line with the current landscape of payment systems threats and risks. There are quite a number of advantages. One now is that it makes application security testing a very key component of the overall process. Other key advantages include systems component inventory, third party and vendor relationships, advanced persistent threats and malware as well as physical access and point of sale security,” he stated.

Nodding in agreement, Ahmed Adesanya, IT Security and Connectivity consultant, said that version 3.1 compliance extends to merchants, payment application providers, communications service providers as well as cloud service providers.

He said that the new version has 12 requirements and over 200 control processes.

“Banks need to show a report of compliance, covering all the processes of security control that applied to them. If any bank doesn’t meet up with this version 3 compliance, payment card brands such as Visa and MasterCard will sanction such bank,” he noted.

He added that such sanctions include fine of $450 per card bridge recorded by the bank that did not comply to this version 3.

He pointed out that the tedious process of compliance to PCI DSS has led to some banks to outsource some of the process to cloud services providers that have met the requirement.


 

C
Published by

Comms Week

Trained and practicing journalist passionate about telecommunications, fintech, cybersecurity, and digital economy reporting.

More in E-Financial
E-Financial

NAICOM Revokes NICON’s Licence, Appoints Liquidator

By Ebere Melum-Nwogbo8 Sept 2026

National Insurance Commission (NAICOM) has cancelled the Certificate of Registration of NICON Insurance Company Limited (RIC-049), and has appointed Chukwuma-Machukwu Ume, Senior Advocate of Nigeria, as receiver/provisional liquidator of the company.