ISO 25186:2026 PDF
Financial services — Methods for the generation and verification of card security codes
Financial services — Methods for the generation and verification of card security codes
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 8
- Дата публикации:
- 3 августа 2026 г.
- Издание:
- ISO IS 25186 edition 1 version 1
- ICS:
- 03.060
This document defines a method for generating and verifying card security codes (CSCs) using cipher-based message authentication code (CMAC) or keyed-hash message authentication code (HMAC). Key management mechanisms associated with these processes are beyond the scope of this document.
Abstract
Overview
ISO 25186:2026: Financial Services - Methods for the Generation and Verification of Card Security Codes is an international standard developed by ISO to establish secure, interoperable methods for generating and verifying card security codes (CSCs). This standard specifies the use of cryptographically strong message authentication codes, specifically cipher-based MAC (CMAC) and keyed-hash MAC (HMAC), for creating and validating CSCs. Card security codes are essential for authentication in remote payments and card-not-present transactions.
ISO 25186:2026 does not cover key management mechanisms for the cryptographic keys used in these processes, focusing solely on the methods for CSC generation and verification. The document aims to support secure, consistent, and widely accepted implementations across global financial services and payments industries.
Key Topics
-
Card Security Code (CSC) Generation: The standard defines a precise algorithm for generating CSCs using CMAC or HMAC techniques. Inputs include the primary account number (PAN), PAN sequence number, expiry date, service code, and optionally, diversification data to ensure uniqueness.
-
CSC Verification: Verification consists of using the same algorithm to recompute the expected CSC value and comparing it to the submitted code as part of transaction authentication, supporting security in remote or online card payments.
-
Use of Cryptographic Algorithms:
- CMAC is used with block ciphers, as specified in ISO/IEC 18033-3.
- HMAC is used with cryptographic hash functions, as outlined in ISO/IEC 10118-3. Both approaches require a CSC key with a minimum cryptographic strength of 128 bits.
-
Diversification Data: The inclusion of unique data-such as timestamp, counter, or random numbers-ensures uniqueness in dynamically generated CSCs and assists in anti-replay protection for single-use codes.
-
Multiple CSC Support: The standard allows for multiple CSCs per account. Each may be generated for different purposes, using either separate cryptographic keys or distinguishing diversification data.
Applications
ISO 25186:2026 is highly relevant for:
-
Payment Card Issuers and Acquirers: Implementing secure algorithms for CSC generation and validation in their card processing systems increases payment security and helps meet compliance requirements.
-
Payment Gateways and Processors: Adopting the methods within this standard ensures consistent CSC verification for card-not-present transactions, reducing fraud risk and enhancing trust.
-
Smart Cards and Mobile Payments: The standard supports both static and dynamic CSC generation, facilitating the integration of secure code generation into cards and mobile devices with cryptographic functions.
-
E-Commerce and Remote Payments: Merchants and e-commerce platforms benefit from interoperability and increased fraud prevention when relying on systems that comply with ISO 25186:2026.
Related Standards
For comprehensive implementation and broader context in payment card security, consider referencing:
- ISO/IEC 9797-1: Message Authentication Codes (MACs) utilizing block ciphers
- ISO/IEC 9797-2: MAC mechanisms using dedicated hash functions
- ISO/IEC 18033-3: Encryption algorithms - Block ciphers
- ISO/IEC 10118-3: Security techniques - Dedicated hash-functions
- ISO/IEC 7812-1: Card issuer identification numbering systems
- ISO 9564-1: PIN management and security for card-based systems
These related standards provide foundational cryptographic methods, card number structures, and guidelines for secure authentication in financial applications.
By following ISO 25186:2026, financial organizations and service providers can standardize secure, robust card security code generation and verification, strengthening card payment security across all channels.
Технические детали
- Технический комитет
- ISO/TC 68/SC 2 - Financial Services, security
- SKU
- ISO 25186:2026
Похожие стандарты
Стандарты, упомянутые в описании
ISO/IEC 18033-3:2010/Amd 1:2021
ДействующийInformation technology — Security techniques — Encryption algorithms — Part 3: Block ciphers — Amendment 1: S…
Overview ISO/IEC 18033-3:2010/Amd 1:2021 is an important international standard amendment that expands the scope of encryption algorithms covered under Part 3 of ISO/IEC 18033-3, which focuses on blo…
ISO/IEC 10118-3:2004/Amd 1:2006
ОтменёнInformation technology — Security techniques — Hash-functions — Part 3: Dedicated hash-functions — Amendment…
ISO/IEC 9797-1:2011/Amd 1:2023
ДействующийInformation technology — Security techniques — Message Authentication Codes (MACs) — Part 1: Mechanisms using…
Overview ISO/IEC 9797-1:2011/Amd 1:2023 is the latest amendment to the international standard for message authentication codes (MACs) that use block cipher mechanisms. Developed under ISO and IEC, th…
ISO/IEC 9797-2:2002
ОтменёнInformation technology — Security techniques — Message Authentication Codes (MACs) — Part 2: Mechanisms using…
ISO/IEC 7812-1:2015
ОтменёнIdentification cards — Identification of issuers — Part 1: Numbering system
SIST ISO 9564-1:1995
ДействующийBanking -- Personal Identification Number management and security -- Part 1: PIN protection principles and te…
Overview SIST ISO 9564-1:1995 is an international standard defining minimum security measures for effective management and protection of Personal Identification Numbers (PINs) in banking. Published b…