---
title: "PCI DSS Compliance: Only 1 out of 3 Companies Are Properly Protecting Credit Card Data"
description: Despite weekly breaches dominating the news, organizations that accept credit card payments are decreasing their efforts around protecting credit card data
image: https://blog.strongkey.com/hubfs/PCI-DSS%20Compliance%20Blog%20Post%20(2).png
---

[![StrongKey Logo](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa118387d144_STR.Horizontal1_LightUSB_TM.png)](https://www.strongkey.com/)

[Home](https://www.strongkey.com/)

Solutions

![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa554a87d2a0_chevron-down.svg)

INDUSTRY

![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa50e587d1ab_cpu%20(1).svg) 

[Fintech Payments, card capture ![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/6026cfe6abf7e7861b604289_bank.svg)](https://www.strongkey.com/solutions/industry/fintech) [Enterprise Fully scalable customization ![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aaf9e687d218_star.svg)](https://www.strongkey.com/solutions/industry/enterprise) [Manufacturing IIoT integration, key injection ![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/6026d009d6756ce5aa5a0cf6_manufacturing.svg)](https://www.strongkey.com/solutions/industry/manufacturing)

![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa2d4787d1e0_check-square.svg)

COMPLIANCE

[![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa1de987d1e1_zap%20(1).svg) PSD2/SCA Integrated; low abandonment](https://www.strongkey.com/solutions/compliance/psd2-strong-customer-authentication) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa6a5787d1a2_credit-card.svg) PCI DSS Reduce costs and burden of audits](https://www.strongkey.com/solutions/compliance/pci-dss-card-capture-services) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aaf26e87d1ac_lock%20(1).svg) NACHA Easily secure deposit data](https://www.strongkey.com/solutions/compliance/nacha-deposit-data-protection) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa298687d1a1_database.svg) GDPR Application-level data protection](https://www.strongkey.com/solutions/compliance/gdpr-general-data-protection-2) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aaf0ba87d1ba_users.svg) CCPA Consumer data privacy](https://www.strongkey.com/solutions/compliance/ccpa-california-consumer-protection-act)

Products

![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa554a87d2a0_chevron-down.svg)

SOFTWARE

![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa215487d1ca_activity.svg) 

[FIDO2 Passwordless Authentication Reduce password-related costs ![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aaea2f87d1d9_user-check.svg)](https://www.strongkey.com/products/software/fido-strong-authentication) [Public Key Infrastructure Build new or update existing ![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa991687d1d4_key.svg)](https://www.strongkey.com/products/software/pki-key-and-certificate-management) [Encryption & Tokenization For small and mid-sized applications ![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa477087d1d3_shield.svg)](https://www.strongkey.com/products/software/tokenization-and-encryption) [Custom Solutions Work with us to find a solution ![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/6026cffdbccd1c7f01ee3fce_cicruit.svg)](https://www.strongkey.com/products/software/custom-solutions)

![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aaa92287d205_truck.svg)

HARDWARE

[![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa1afb87d1b4_server%20(1).svg) Hosted Solutions We do the heavy lifting](https://www.strongkey.com/products/hardware/hosted-solution) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aac83e87d1d1_hard-drive%20(1).svg) Tellaro T-Series Specifically for SMBs](https://www.strongkey.com/products/hardware/products-tellaro-t-midmarket-small-business-data-security) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa298687d1a1_database.svg) Tellaro E-Series Enterprise data protection](https://www.strongkey.com/products/hardware/products-tellaro-e-enterprise-data-security-solution)

Developer

![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa554a87d2a0_chevron-down.svg)

[![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa65cf87d1db_codepen%20(2).svg) Open Source Development Everyone wins when we share](https://www.strongkey.com/developer/developer) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aaa41287d1e5_terminal.svg) Swagger API Docs Easy to use and learn](https://demo4.strongkey.com/getstarted/#/openapi) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa2b7687d1dc_log-in.svg) GitHub StrongKey FIDO Server Sample code, tutorials](https://github.com/StrongKey/fido2)

About

![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa554a87d2a0_chevron-down.svg)

[![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aad93e87d1b7_home%20(1).svg) Company Our history, philosophy and future](https://www.strongkey.com/company) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aaf0ba87d1ba_users.svg) Partners and Resellers Who we do business with](https://blog.strongkey.com/) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa600c87d207_tv.svg) Newsroom Latest news about StrongKey](https://blog.strongkey.com/newsroom) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa000d87d1b5_book-open.svg) Resources Access our content and documentation](https://blog.strongkey.com/resources) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aaf14f87d20c_mic.svg) Events Where you'll be able to meet us](https://www.strongkey.com/events) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa54be87d1ce_briefcase%20(1).svg) Careers Join us to improve data security for all](https://www.strongkey.com/careers)

[Blog](https://blog.strongkey.com/blog) [CONTACT](https://www.strongkey.com/contact) 

[DEMOS ![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa61e187d118_arrow-left.svg)](https://www.strongkey.com/demos)

[![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa118387d144_STR.Horizontal1_LightUSB_TM.png)](https://www.strongkey.com/)

[Home](https://www.strongkey.com/)

Solutions

COMPLIANCE

[![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa1de987d1e1_zap%20(1).svg) PSD2/SCA Integrated for low abandonment](https://www.strongkey.com/solutions/compliance/psd2-strong-customer-authentication) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa6a5787d1a2_credit-card.svg) PCI DSS Reduce costs and burdens of audits](https://www.strongkey.com/solutions/compliance/pci-dss-card-capture-services) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aaf26e87d1ac_lock%20(1).svg) NACHA Easily secure deposit data](https://www.strongkey.com/solutions/compliance/nacha-deposit-data-protection) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa298687d1a1_database.svg) GDPR Application-level data protection](https://www.strongkey.com/solutions/compliance/gdpr-general-data-protection-2) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aaf0ba87d1ba_users.svg) CCPA Consumer data privacy](https://www.strongkey.com/solutions/compliance/ccpa-california-consumer-protection-act)

INDUSTRY

[![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/6026cfe6abf7e7861b604289_bank.svg) Fintech Payments, card capture](https://www.strongkey.com/solutions/industry/fintech) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aaf9e687d218_star.svg) Enterprise Fully scalable customization](https://www.strongkey.com/solutions/industry/enterprise) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/6026d009d6756ce5aa5a0cf6_manufacturing.svg) Manufacturing IIoT integration, key injection](https://www.strongkey.com/solutions/industry/manufacturing)

Products

SOFTWARE

[![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aaea2f87d1d9_user-check.svg) FIDO Passwordless Authentication Reduce password-related costs](https://www.strongkey.com/products/software/fido-strong-authentication) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa991687d1d4_key.svg) Public Key Infrastructure Build new or update existing](https://www.strongkey.com/products/software/pki-key-and-certificate-management) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa477087d1d3_shield.svg) Encryption & Tokenization For enterprise applications](https://www.strongkey.com/products/software/tokenization-and-encryption)

HARDWARE

[![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa1afb87d1b4_server%20(1).svg) Hosted Solutions We do the heavy lifting](https://www.strongkey.com/products/hardware/hosted-solution) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aac83e87d1d1_hard-drive%20(1).svg) Tellaro T-Series Specifically for SMBs](https://www.strongkey.com/products/hardware/products-tellaro-t-midmarket-small-business-data-security) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa298687d1a1_database.svg) Tellaro E-Series Enterprise data protection](https://www.strongkey.com/products/hardware/products-tellaro-e-enterprise-data-security-solution)

Developer

[![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa65cf87d1db_codepen%20(2).svg) Open Source Collaboration Everyone wins when we share](https://www.strongkey.com/developer/developer) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aaa41287d1e5_terminal.svg) Swagger API Docs Easy to use and learn](https://demo4.strongkey.com/getstarted/#/openapi) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa2b7687d1dc_log-in.svg) GitHub StrongKey FIDO Server Sample code, tutorials](https://github.com/StrongKey/fido2)

About

[![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aad93e87d1b7_home%20(1).svg) Company Our history, philosophy, and future](https://www.strongkey.com/about/company) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa600c87d207_tv.svg) Newsroom Latest news about StrongKey](https://blog.strongkey.com/newsroom) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa000d87d1b5_book-open.svg) Resources Access our content and documentation](https://blog.strongkey.com/resources) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aaf14f87d20c_mic.svg) Events Where you'll be able to meet us](https://www.strongkey.com/about/events) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa54be87d1ce_briefcase%20(1).svg) Careers Join us to improve data security for all](https://www.strongkey.com/about/careers) 

[Blog](https://blog.strongkey.com/blog) [CONTACT](https://www.strongkey.com/contact) [Demos](https://www.strongkey.com/demos)

[Suhail Noor](https://blog.strongkey.com/blog/author/suhail-noor) - Dec 17, 2019

# PCI DSS Compliance: Only 1 out of 3 Companies Are Properly Protecting Credit Card Data

- [Tweet](https://twitter.com/share)

[Payments/E-Commerce](https://blog.strongkey.com/blog/tag/payments-e-commerce)  [Key Management](https://blog.strongkey.com/blog/tag/key-management)  [PCI DSS](https://blog.strongkey.com/blog/tag/pci-dss)  [Encryption/Tokenization](https://blog.strongkey.com/blog/tag/encryption-tokenization)

**LAST UPDATED: **06/05/2020

*“We’ve been breached and millions of records are in the hands of attackers. But don’t worry; we promise to do better.”*

This is a headline that has been published on a seemingly weekly basis over the last few years. Multi-million and multi-billion dollar companies publish vague press releases notifying the public of a data security breach with guarantees that they will learn from this experience so that it can’t happen again.

Uber, Capital One, Marriott, and British Airways are a few companies whose well-publicized data breaches compromised the sensitive information of millions of their customers due to poor security practices. If you believed their press releases, however, you would think that these were abnormal events. That these companies have rigorous data protection policies in place and that bad actors managed to find a backdoor entrance.

Surely in an industry like credit card payment processing, which has had rigorous data security standards for nearly two decades, the vast majority of companies that handle sensitive information would be compliant? Unfortunately, this graph (Figure 1) tells a very different story.

Every year, a division of Verizon publishes a “Payment Security Report.” In the [2019 r](https://enterprise.verizon.com/resources/reports/payment-security/)[eport,](https://enterprise.verizon.com/resources/reports/payment-security/) their team analyzed data from over 300 representative organizations in the Americas, Asia Pacific, Europe, the Middle East, and Africa. They worked with organizations that spanned several industries: finance, hospitality, retail, IT services, and more. 

![PCI DSS Sustainability Trends Chart](https://blog.strongkey.com/hs-fs/hubfs/image-8.png?width=300&name=image-8.png)

**They found that only about 36% of companies are in full compliance with the Payment Card Industry Data Security Standards (PCI DSS). And what’s most worrisome, is that the percentage of companies in full compliance has been trending downward since 2016.**

This means that despite the weekly breaches dominating the headlines, **organizations that accept payment card data are actually** *decreasing* **their efforts around data security**.

#### **What Is PCI Compliance?**

In 2006, several major credit card companies (Visa, MasterCard, AmEx, and Discover, among others) decided to merge their proprietary data protection standards into what came to be known as PCI DSS. The goal was to provide a single set of comprehensive guidelines that organizations using payment card data would have to follow, rather than have different card types requiring different protections.

[PCI DSS](https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf?agreement=true&time=1575390445702) has six groups of “control objectives”:

1. Build and Maintain a Secure Network and Systems
2. Protect Cardholder Data
3. Maintain a Vulnerability Management Program
4. Implement Strong Access Control Measures
5. Regularly Monitor and Test Networks
6. Maintain an Information Security Policy

Organizations that handle credit card data can fall under one of four levels of PCI compliance. These levels are based on the number of transactions processed per year. Level 4 is the lowest, for organizations processing less than 20,000 transactions annually, while Level 1 is for those that process more than 6 million transactions annually.

#### **What Makes PCI Compliance So Challenging?**

In [testimony](https://www.hsdl.org/?abstract&did=27800) before the House of Representatives Subcommittee on Cybersecurity in 2009, the CIO of Michael’s stores made the following statement:

*“The PCI Data Security Standards are an extraordinarily complex set of requirements. They are very expensive to implement, confusing to comply with, and ultimately subjective, both in their interpretation and in their enforcement. It is often stated that there are only twelve ‘requirements’ for PCI compliance. In fact, there are over 220 sub-requirements; some of which can place an incredible burden on a retailer and many of which are subject to interpretation.”*

*It doesn’t take much analysis to see the validity to this CIO’s point — the regulations are:*

- **Complex:** In one of the more detailed sections of the PCI standards, under Control Objective 3 for Protecting Stored Cardholder Data, you run into terms like cryptographic key management, one-way hashes, and PAN truncation. Not only would these be completely new to most companies that have to comply with PCI DSS, but they wouldn’t even be able to find any helpful definitions within the regulation. These are things that, prior to PCI DSS, only central banks and the military had to worry about; all of a sudden, it became a problem for a much larger group of companies.
- **Expensive:** Many of the compliance solutions available right now charge companies on a per-transaction basis: the more credit card transactions your organization handles the more their data protection solutions cost you. Many of these solutions have appealing deals with low up-front costs, rapid deployment in the cloud — everything to make it quick and easy to sign on with them. Very soon, however, the problem shifts from complying with PCI DSS to paying for compliance.
- **Subjective:** Even if your company has all the proper policies and procedures in place for compliance and is spending the money it takes to sustain them, there is still a chance that they might not be considered compliant. This is because the compliance decision rests fully with Qualified Security Assessors who conduct the audit. Different QSAs have varying levels of experience and may have different levels of familiarity with certain technologies. The breaches mentioned above at Capital One and Uber were not the result of hackers breaking down defenses, but rather, bad actors taking advantage of simple misconfigurations in their environments. These are things that should have been spotted by QSAs, but clearly were not.

The Verizon report suggests that as a response to these vague and subjective guidelines, companies have embraced the “checklist” attitude towards data protection — that if they follow a certain number of steps, then they are sufficiently covered. Unfortunately, this only provides a false sense of security, and is the primary reason why the vast majority of companies would not be considered PCI compliant.

#### **Strategies for Improving PCI Compliance**

Although these downward trends and frequent headlines seem disheartening, there are a handful of very clear and immediate steps your organization can take to move towards sustainable PCI Compliance.

1. **Isolate** **Sensitive Data:** Once you have a clear picture of how sensitive data is flowing around your different applications, limiting the places in which it is used would be the best first step you can take. This can be accomplished by tokenizing the sensitive data and using it as a pointer, rather than duplicating the actual piece of data in various applications. If you can cut down on applications that rely on sensitive data and make use of tokenization instead, the points of entry for any attacker are sharply reduced.
2. **Ask the Experts:** There are a number of companies who have been helping companies achieve PCI Compliance for over a decade. They have learned along the way which strategies work and which don’t. Experts will be able to suggest industry best practices that go above and beyond the PCI regulations to ensure the strongest data protection strategies are being used.
3. **Make Use of Cryptographic Hardware:** Although this is not specifically mandated by the PCI regulations, using cryptographic hardware to store and manage encryption keys is one of those industry best practices mentioned above. There are several reasons why [key management in the cloud is never going to be secure](https://blog.strongkey.com/blog/do-cryptographic-keys-belong-in-the-cloud), all of which are solved by using cryptographic hardware. Another benefit of this is that you can avoid paying per-transaction fees by relying on this hardware for encryption and tokenization making it an accessible tool to companies of all sizes.

StrongKey has been helping companies pass PCI DSS audits for over a decade. [Contact us](https://go.strongkey.com/pci-dss-compliance-made-easy) to get personalized recommendations for your organization.

Continue to [Twitter Hack in Bitcoin Scam Reveals Fundamental Security Flaw.](https://blog.strongkey.com/blog/twitter-hack-in-bitcoin-scam-reveals-fundamental-security-flaw)

[![Click here to request our expertise and become PCI-DSS compliant.](https://no-cache.hubspot.com/cta/default/4723359/cfc1c9ea-799b-4675-b938-b9f63bf539e2.png)](https://cta-redirect.hubspot.com/cta/redirect/4723359/cfc1c9ea-799b-4675-b938-b9f63bf539e2)

### ALL TOPICS

- [FIDO (45)](https://blog.strongkey.com/blog/tag/fido)
- [Culture/Influence (31)](https://blog.strongkey.com/blog/tag/culture-influence)
- [Cybersecurity ROI (29)](https://blog.strongkey.com/blog/tag/cybersecurity-roi)
- [Breaches (16)](https://blog.strongkey.com/blog/tag/breaches)
- [Encryption/Tokenization (16)](https://blog.strongkey.com/blog/tag/encryption-tokenization)
- [Payments/E-Commerce (15)](https://blog.strongkey.com/blog/tag/payments-e-commerce)
- [Disruptive Defenses (14)](https://blog.strongkey.com/blog/tag/disruptive-defenses)
- [Key Management (11)](https://blog.strongkey.com/blog/tag/key-management)
- [PSD2 (11)](https://blog.strongkey.com/blog/tag/psd2)
- [GDPR and CCPA (8)](https://blog.strongkey.com/blog/tag/gdpr-and-ccpa)
- [SCA (8)](https://blog.strongkey.com/blog/tag/sca)
- [Events (7)](https://blog.strongkey.com/blog/tag/events)
- [Employee Spotlight (6)](https://blog.strongkey.com/blog/tag/employee-spotlight)
- [Ransomware (5)](https://blog.strongkey.com/blog/tag/ransomware)
- [COVID-19 (4)](https://blog.strongkey.com/blog/tag/covid-19)
- [PCI DSS (4)](https://blog.strongkey.com/blog/tag/pci-dss)
- [Products (4)](https://blog.strongkey.com/blog/tag/products)
- [Blockchain (3)](https://blog.strongkey.com/blog/tag/blockchain)
- [Healthcare (3)](https://blog.strongkey.com/blog/tag/healthcare)
- [Hybrid Cloud (RC3) (3)](https://blog.strongkey.com/blog/tag/hybrid-cloud-rc3)
- [IoT (3)](https://blog.strongkey.com/blog/tag/iot)
- [PKI (3)](https://blog.strongkey.com/blog/tag/pki)
- [Press Releases (2)](https://blog.strongkey.com/blog/tag/press-releases)
- [Citrix (1)](https://blog.strongkey.com/blog/tag/citrix)
- [Passkeys (1)](https://blog.strongkey.com/blog/tag/passkeys)

### Most Popular

<https://blog.strongkey.com/blog/would-you-trust-your-bank-with-both-keys-to-your-safe-deposit-box>

[FIDO](https://blog.strongkey.com/blog/tag/fido) [Key Management](https://blog.strongkey.com/blog/tag/key-management) [Passkeys](https://blog.strongkey.com/blog/tag/passkeys)

**[“Would you trust your bank with both keys to your ....](https://blog.strongkey.com/blog/would-you-trust-your-bank-with-both-keys-to-your-safe-deposit-box)**

<https://blog.strongkey.com/blog/guide-to-fido-protocols-u2f-uaf-webauthn-fido2>

[FIDO](https://blog.strongkey.com/blog/tag/fido) [Disruptive Defenses](https://blog.strongkey.com/blog/tag/disruptive-defenses)

**[An In-depth Guide to FIDO Protocols: U2F, UAF, and....](https://blog.strongkey.com/blog/guide-to-fido-protocols-u2f-uaf-webauthn-fido2)**

<https://blog.strongkey.com/blog/key-custodians-who-what-where-when-why-and-how>

[Key Management](https://blog.strongkey.com/blog/tag/key-management) [Cybersecurity ROI](https://blog.strongkey.com/blog/tag/cybersecurity-roi)

**[Key Custodians: Who, What, Where, When, Why, and H....](https://blog.strongkey.com/blog/key-custodians-who-what-where-when-why-and-how)**

<https://blog.strongkey.com/blog/fido-101-strong-authentication>

[FIDO](https://blog.strongkey.com/blog/tag/fido) [Disruptive Defenses](https://blog.strongkey.com/blog/tag/disruptive-defenses) [Culture/Influence](https://blog.strongkey.com/blog/tag/culture-influence)

**[FIDO 101: Understanding FIDO Strong Authentication....](https://blog.strongkey.com/blog/fido-101-strong-authentication)**

### Archive

- [March 2026 (1)](https://blog.strongkey.com/newsroom/archive/2026/03)
- [June 2025 (1)](https://blog.strongkey.com/newsroom/archive/2025/06)
- [March 2022 (1)](https://blog.strongkey.com/newsroom/archive/2022/03)
- [December 2021 (1)](https://blog.strongkey.com/newsroom/archive/2021/12)
- [March 2021 (6)](https://blog.strongkey.com/newsroom/archive/2021/03)
- [December 2020 (4)](https://blog.strongkey.com/newsroom/archive/2020/12)
- [November 2020 (2)](https://blog.strongkey.com/newsroom/archive/2020/11)
- [October 2020 (3)](https://blog.strongkey.com/newsroom/archive/2020/10)
- [September 2020 (1)](https://blog.strongkey.com/newsroom/archive/2020/09)
- [August 2020 (3)](https://blog.strongkey.com/newsroom/archive/2020/08)
- [June 2020 (1)](https://blog.strongkey.com/newsroom/archive/2020/06)
- [April 2020 (2)](https://blog.strongkey.com/newsroom/archive/2020/04)
- [February 2020 (1)](https://blog.strongkey.com/newsroom/archive/2020/02)
- [January 2020 (1)](https://blog.strongkey.com/newsroom/archive/2020/01)
- [December 2019 (1)](https://blog.strongkey.com/newsroom/archive/2019/12)
- [September 2019 (1)](https://blog.strongkey.com/newsroom/archive/2019/09)
- [August 2019 (3)](https://blog.strongkey.com/newsroom/archive/2019/08)
- [July 2019 (1)](https://blog.strongkey.com/newsroom/archive/2019/07)
- [June 2019 (1)](https://blog.strongkey.com/newsroom/archive/2019/06)
- [May 2019 (1)](https://blog.strongkey.com/newsroom/archive/2019/05)
- [April 2019 (1)](https://blog.strongkey.com/newsroom/archive/2019/04)
- [March 2019 (1)](https://blog.strongkey.com/newsroom/archive/2019/03)
- [February 2019 (3)](https://blog.strongkey.com/newsroom/archive/2019/02)
- [January 2019 (3)](https://blog.strongkey.com/newsroom/archive/2019/01)
- [December 2018 (2)](https://blog.strongkey.com/newsroom/archive/2018/12)
- [November 2018 (3)](https://blog.strongkey.com/newsroom/archive/2018/11)
- [October 2018 (3)](https://blog.strongkey.com/newsroom/archive/2018/10)
- [September 2018 (2)](https://blog.strongkey.com/newsroom/archive/2018/09)
- [August 2018 (1)](https://blog.strongkey.com/newsroom/archive/2018/08)
- [July 2018 (1)](https://blog.strongkey.com/newsroom/archive/2018/07)
- [April 2018 (2)](https://blog.strongkey.com/newsroom/archive/2018/04)
- [January 2018 (1)](https://blog.strongkey.com/newsroom/archive/2018/01)
- [October 2017 (1)](https://blog.strongkey.com/newsroom/archive/2017/10)

![Strongkey - Logo](https://blog.strongkey.com/hubfs/Strongkey%20-%20Logo.png "Strongkey - Logo")

StrongKey provides solutions to companies looking to solve for PCI DSS, PSD2 Strong Customer Authentication, passwordless authentication with FIDO, data privacy, public key infrastructure and other security challenges.

Copyright 2022 StrongKey, Inc.

- [Privacy Policy](https://www.strongkey.com/about/privacy-policy)
- [Terms of Use](https://www.strongkey.com/about/terms-of-use)
- [Cookie Policy](https://www.strongkey.com/about/cookie-policy)

#### About

- [Company](https://www.strongkey.com/about/company)
- [Newsroom](https://blog.strongkey.com/newsroom)
- [Events](https://www.strongkey.com/about/events)
- [Careers](https://www.strongkey.com/about/careers)

#### Solutions

- [PCI DSS](https://www.strongkey.com/solutions/compliance/pci-dss-card-capture-services)
- [FIDO](https://www.strongkey.com/products/software/fido-strong-authentication)
- [PSD2 SCA](https://www.strongkey.com/solutions/compliance/psd2-strong-customer-authentication)
- [CCPA](https://www.strongkey.com/solutions/compliance/ccpa-california-consumer-protection-act)
- [GDPR](https://www.strongkey.com/solutions/compliance/gdpr-general-data-protection-2)
- [NACHA](https://www.strongkey.com/solutions/compliance/nacha-deposit-data-protection)

#### Resources

- [Library](https://blog.strongkey.com/resources)
- [CONTACT US](https://www.strongkey.com/contact)

[![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/60526cad36f3a5e723525fba_GitHub_logo_white_10%25.png)](https://github.com/StrongKey) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa071787d2c3_Twitter.png)](https://twitter.com/strongkeyinc) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa775287d2c0_Linkedin.png)](https://www.linkedin.com/company/strongkey)

[![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/60526bcf0df80d185f961b8d_youtube_white_icon.png)](https://www.youtube.com/channel/UCueU61oRt9G6MILRSHIfimA) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/6036be2bdf2d65e2d2fc906f_Instagram_5%25.png)](https://www.instagram.com/strongkeyinc/) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/6036bd8ef3da6a4bb2e24382_facebook_10%25.png)](https://www.facebook.com/strongkeyinc/)

#### Subscribe to Our Newsletter

Receive helpful information and the latest news from the world of cybersecurity