Compliance DeadlineSeptember 1, 20266 min read
PCI SSC Extends HSM v3 and v4 Deadlines: What US Merchants Need to Know
The PCI SSC has extended expiration dates for HSM v3 and v4 devices, providing merchants a critical window to transition to the new v5.0 security standards.
By ONKORE Payment Solutions

What Happened
PCI SSC Extends HSM v3 and v4 Deadlines: What US Merchants Need to Know\n\nIn the complex ecosystem of payment security, Hardware Security Modules (HSMs) serve as the silent sentinels of data integrity. These specialized physical devices manage, process, and store cryptographic keys, ensuring that sensitive information like Personal Identification Numbers (PINs) remains encrypted and secure throughout the transaction lifecycle. Recently, the PCI Security Standards Council (PCI SSC) issued a critical update that provides much-needed breathing room for the industry. In a bulletin titled Extension of PCI PTS HSM v4 Security Requirements, the Council announced significant extensions for the expiration dates of PCI PTS HSM version 3 and version 4 devices.\n\nFor US merchants and payment service providers, this announcement is more than a simple administrative shift; it is a strategic window to align hardware lifecycles with the next generation of security standards. As the industry moves toward the newly published PCI PTS HSM v5.0, understanding these new timelines is essential for maintaining compliance and operational stability.\n\n## Understanding the Role of HSMs in Modern Payments\n\nBefore diving into the specific date changes, it is important to recognize why HSMs are so vital. Unlike general-purpose servers, HSMs are tamper-resistant hardware designed specifically for high-volume cryptographic operations. They are used by banks, payment processors, and large merchants to protect the keys that encrypt cardholder data. If an HSM is compromised, the entire security architecture of a payment network could fail. Consequently, the PCI SSC maintains rigorous standards (the PIN Transaction Security or PTS HSM requirements) to ensure these devices can withstand both physical and logical attacks.\n\n## Breaking Down the PCI SSC Extension Dates\n\nThe recent bulletin introduces three primary changes to the HSM lifecycle timeline. These extensions are designed to provide a minimum 12-month overlap between major versions of security requirements, allowing vendors and merchants to adapt without disrupting their services.\n\n### 1. PCI PTS HSM v3 Device Expiration\nOriginally, HSM v3 devices were scheduled to expire in April 2026. The PCI SSC has now extended this expiration date to April 2028. This two-year extension is particularly significant for organizations still relying on older hardware, as it prevents an immediate compliance crisis and allows for a more measured upgrade path.\n\n### 2. PCI PTS HSM v4 Approval Window\nThe window for manufacturers to submit new devices for approval under the HSM v4 standard was set to close on December 31, 2025. This has been extended to June 30, 2027. This change ensures that vendors can continue to bring v4-compliant hardware to market while they finalize designs for the newer v5.0 standard.\n\n### 3. PCI PTS HSM v4 Device Expiration\nFor devices already approved under the v4 standard, the expiration date has been moved from April 2032 to April 2033. This one-year extension provides long-term certainty for merchants who have recently invested in v4 hardware, ensuring their investment remains compliant for a full decade.\n\n## Why the PCI SSC Granted More Time\n\nThe primary driver for these extensions is the publication of PCI PTS HSM v5.0 in May 2026. The v5.0 standard introduces several major revisions, including strengthened vulnerability management and improved lifecycle security. By extending the v3 and v4 dates, the Council is ensuring that the industry does not face a "hardware gap" where old devices are expired but new v5.0 devices are not yet widely available or fully tested in production environments.\n\nFurthermore, the payments industry is currently navigating a broader shift toward "crypto-agility." As quantum computing and other advanced threats emerge, the ability to quickly update cryptographic algorithms becomes paramount. The v5.0 standard is built with these future threats in mind, and the extensions provide the necessary time for a stable transition to this more robust framework.\n\n## The Road to HSM v5.0: What Changes?\n\nWhile the extensions provide relief, merchants should not lose sight of the ultimate goal: transitioning to HSM v5.0. The new standard is not just a minor update; it represents a significant leap in security requirements. Key changes in v5.0 include:\n\n* Enhanced Vulnerability Management: Requirements have been moved into the lifecycle security section, emphasizing that security is a continuous process, not a one-time certification.\n* Cloud-Ready Requirements: As noted by industry experts at Utimaco, modern standards are increasingly addressing cloud-based and multi-tenant payment environments, a trend that v5.0 continues to refine.\n* Alignment with Modern Cryptography: v5.0 prepares the industry for the eventual migration to stronger algorithms, such as AES and Post-Quantum Cryptography (PQC).\n\n## Merchant Recommendations: Navigating the Transition\n\nFor US merchants, the extension should be viewed as a strategic opportunity rather than a reason to delay security upgrades. We recommend the following actions:\n\n1. Conduct a Hardware Inventory: Identify every HSM in your environment and determine its current PCI PTS version (v3, v4, or older). Map these against the new expiration dates (April 2028 for v3, April 2033 for v4).\n2. Consult with Your Vendors: Reach out to your HSM providers to understand their roadmap for v5.0. Ask when they expect to have v5.0-certified hardware available and what the migration path looks like for your specific use cases.\n3. Review Budgetary Cycles: Hardware refreshes are capital-intensive. Use the extended timelines to align your HSM upgrades with your organization's broader IT budget cycles, avoiding the need for emergency funding as deadlines approach.\n4. Assess Crypto-Agility: Evaluate your current payment applications to see how easily they can support new cryptographic standards. The hardware is only one part of the equation; your software must also be ready to handle the stronger keys required by v5.0.\n5. Stay Informed on PCI DSS 4.0: Remember that HSM compliance is a subset of your broader PCI DSS obligations. Ensure your HSM strategy aligns with the requirements of PCI DSS 4.0, which places a heavy emphasis on continuous security monitoring.\n\n## ONKORE Perspective: Strategic Security Planning\n\nAt ONKORE, we view the PCI SSC's decision to extend these deadlines as a pragmatic and welcome move for the merchant community. In an era where "compliance fatigue" is a real risk, providing clear, extended timelines allows businesses to focus on meaningful security improvements rather than rushing to meet arbitrary deadlines. However, we caution merchants against complacency. The transition from v3 to v5.0 involves significant technical hurdles, particularly regarding key management and application compatibility. The "gift of time" provided by the Council should be used to conduct thorough testing and pilot programs for v5.0 hardware. By starting the planning process now, merchants can ensure a seamless transition that protects both their customers' data and their own operational continuity.\n\nIn conclusion, while the immediate pressure of the 2026 v3 expiration has been lifted, the trajectory of the industry is clear. The move toward more resilient, cloud-aware, and crypto-agile hardware is well underway. Merchants who use this extension to build a robust, long-term hardware strategy will be best positioned to navigate the evolving threat landscape of the late 2020s and beyond.","meta_title":"PCI PTS HSM v3 & v4 Expiration Extensions: Merchant Guide","meta_description":"PCI SSC extends HSM v3 and v4 expiration dates. Learn how these new deadlines affect your payment security compliance and hardware upgrade strategy.","faq_items":[{"question":"What is a Hardware Security Module (HSM)?","answer":"An HSM is a specialized, tamper-resistant physical device used to safeguard and manage digital keys for strong authentication and cryptoprocessing within payment networks."},{"question":"Why did the PCI SSC extend the HSM v3 and v4 dates?","answer":"The extensions were granted to ensure industry stability during the transition to the new HSM v5.0 standard and to provide a 12-month overlap between major versions."},{"question":"When do PCI PTS HSM v3 devices now expire?","answer":"The expiration date for HSM v3 devices has been extended from April 2026 to April 2028."},{"question":"What is the new expiration date for HSM v4 devices?","answer":"The expiration date for HSM v4 devices has been extended from April 2032 to April 2033."}],"recommendations":["Inventory all current HSM devices and their version levels.","Contact hardware vendors to discuss v5.0 migration roadmaps.","Align hardware refresh budgets with the new 2028 and 2033 deadlines.","Evaluate application readiness for next-generation cryptographic standards."],"onkore_perspective":"ONKORE views this extension as a strategic opportunity for merchants to avoid rushed migrations. The extra time should be used to rigorously test v5.0 hardware and ensure that internal systems are ready for the shift toward crypto-agility and post-quantum security standards.","suggested_related_resources":["PCI SSC Bulletin: Extension of HSM v4 and v3 Dates","PCI PTS HSM v5.0 Security Requirements","ONKORE Guide to PCI DSS 4.0 Compliance"],"suggested_internal_links":["Understanding Payment Encryption Basics","The Future of Crypto-Agility in Payments","Merchant Guide to Hardware Security"],"suggested_cta":"Contact ONKORE today for a comprehensive review of your payment security roadmap and HSM compliance strategy.","social_post":"Important update for payment pros! The PCI SSC has extended the expiration dates for HSM v3 and v4 devices. This gives merchants more time to plan their transition to the new v5.0 standard. Check out our full breakdown of the new timelines and what they mean for your business. #PCISSC #PaymentSecurity #HSM #Compliance","newsletter_summary":"The PCI SSC has announced a significant extension for PCI PTS HSM v3 and v4 expiration dates, moving the v3 deadline to April 2028. This update provides merchants with a critical window to plan for the transition to the new v5.0 standard while maintaining operational stability.","affected_industries":["Banking","Retail","E-commerce","Payment Processing","Financial Services"],"effective_date":"2026-03-02","reading_time":6}
Why It Matters
The PCI SSC has extended expiration dates for HSM v3 and v4 devices, providing merchants a critical window to transition to the new v5.0 security standards.
PCI SSC Extends HSM v3 and v4 Deadlines: What US Merchants Need to Know\n\nIn the complex ecosystem of payment security, Hardware Security Modules (HSMs) serve as the silent sentinels of data integrity. These specialized physical devices manage, process, and store cryptographic keys, ensuring that sensitive information like Personal Identification Numbers (PINs) remains encrypted and secure throughout the transaction lifecycle. Recently, the PCI Security Standards Council (PCI SSC) issued a critical update that provides much-needed breathing room for the industry. In a bulletin titled Extension of PCI PTS HSM v4 Security Requirements, the Council announced significant extensions for the expiration dates of PCI PTS HSM version 3 and version 4 devices.\n\nFor US merchants and payment service providers, this announcement is more than a simple administrative shift; it is a strategic window to align hardware lifecycles with the next generation of security standards. As the industry moves toward the newly published PCI PTS HSM v5.0, understanding these new timelines is essential for maintaining compliance and operational stability.\n\n## Understanding the Role of HSMs in Modern Payments\n\nBefore diving into the specific date changes, it is important to recognize why HSMs are so vital. Unlike general-purpose servers, HSMs are tamper-resistant hardware designed specifically for high-volume cryptographic operations. They are used by banks, payment processors, and large merchants to protect the keys that encrypt cardholder data. If an HSM is compromised, the entire security architecture of a payment network could fail. Consequently, the PCI SSC maintains rigorous standards (the PIN Transaction Security or PTS HSM requirements) to ensure these devices can withstand both physical and logical attacks.\n\n## Breaking Down the PCI SSC Extension Dates\n\nThe recent bulletin introduces three primary changes to the HSM lifecycle timeline. These extensions are designed to provide a minimum 12-month overlap between major versions of security requirements, allowing vendors and merchants to adapt without disrupting their services.\n\n### 1. PCI PTS HSM v3 Device Expiration\nOriginally, HSM v3 devices were scheduled to expire in April 2026. The PCI SSC has now extended this expiration date to April 2028. This two-year extension is particularly significant for organizations still relying on older hardware, as it prevents an immediate compliance crisis and allows for a more measured upgrade path.\n\n### 2. PCI PTS HSM v4 Approval Window\nThe window for manufacturers to submit new devices for approval under the HSM v4 standard was set to close on December 31, 2025. This has been extended to June 30, 2027. This change ensures that vendors can continue to bring v4-compliant hardware to market while they finalize designs for the newer v5.0 standard.\n\n### 3. PCI PTS HSM v4 Device Expiration\nFor devices already approved under the v4 standard, the expiration date has been moved from April 2032 to April 2033. This one-year extension provides long-term certainty for merchants who have recently invested in v4 hardware, ensuring their investment remains compliant for a full decade.\n\n## Why the PCI SSC Granted More Time\n\nThe primary driver for these extensions is the publication of PCI PTS HSM v5.0 in May 2026. The v5.0 standard introduces several major revisions, including strengthened vulnerability management and improved lifecycle security. By extending the v3 and v4 dates, the Council is ensuring that the industry does not face a "hardware gap" where old devices are expired but new v5.0 devices are not yet widely available or fully tested in production environments.\n\nFurthermore, the payments industry is currently navigating a broader shift toward "crypto-agility." As quantum computing and other advanced threats emerge, the ability to quickly update cryptographic algorithms becomes paramount. The v5.0 standard is built with these future threats in mind, and the extensions provide the necessary time for a stable transition to this more robust framework.\n\n## The Road to HSM v5.0: What Changes?\n\nWhile the extensions provide relief, merchants should not lose sight of the ultimate goal: transitioning to HSM v5.0. The new standard is not just a minor update; it represents a significant leap in security requirements. Key changes in v5.0 include:\n\n* Enhanced Vulnerability Management: Requirements have been moved into the lifecycle security section, emphasizing that security is a continuous process, not a one-time certification.\n* Cloud-Ready Requirements: As noted by industry experts at Utimaco, modern standards are increasingly addressing cloud-based and multi-tenant payment environments, a trend that v5.0 continues to refine.\n* Alignment with Modern Cryptography: v5.0 prepares the industry for the eventual migration to stronger algorithms, such as AES and Post-Quantum Cryptography (PQC).\n\n## Merchant Recommendations: Navigating the Transition\n\nFor US merchants, the extension should be viewed as a strategic opportunity rather than a reason to delay security upgrades. We recommend the following actions:\n\n1. Conduct a Hardware Inventory: Identify every HSM in your environment and determine its current PCI PTS version (v3, v4, or older). Map these against the new expiration dates (April 2028 for v3, April 2033 for v4).\n2. Consult with Your Vendors: Reach out to your HSM providers to understand their roadmap for v5.0. Ask when they expect to have v5.0-certified hardware available and what the migration path looks like for your specific use cases.\n3. Review Budgetary Cycles: Hardware refreshes are capital-intensive. Use the extended timelines to align your HSM upgrades with your organization's broader IT budget cycles, avoiding the need for emergency funding as deadlines approach.\n4. Assess Crypto-Agility: Evaluate your current payment applications to see how easily they can support new cryptographic standards. The hardware is only one part of the equation; your software must also be ready to handle the stronger keys required by v5.0.\n5. Stay Informed on PCI DSS 4.0: Remember that HSM compliance is a subset of your broader PCI DSS obligations. Ensure your HSM strategy aligns with the requirements of PCI DSS 4.0, which places a heavy emphasis on continuous security monitoring.\n\n## ONKORE Perspective: Strategic Security Planning\n\nAt ONKORE, we view the PCI SSC's decision to extend these deadlines as a pragmatic and welcome move for the merchant community. In an era where "compliance fatigue" is a real risk, providing clear, extended timelines allows businesses to focus on meaningful security improvements rather than rushing to meet arbitrary deadlines. However, we caution merchants against complacency. The transition from v3 to v5.0 involves significant technical hurdles, particularly regarding key management and application compatibility. The "gift of time" provided by the Council should be used to conduct thorough testing and pilot programs for v5.0 hardware. By starting the planning process now, merchants can ensure a seamless transition that protects both their customers' data and their own operational continuity.\n\nIn conclusion, while the immediate pressure of the 2026 v3 expiration has been lifted, the trajectory of the industry is clear. The move toward more resilient, cloud-aware, and crypto-agile hardware is well underway. Merchants who use this extension to build a robust, long-term hardware strategy will be best positioned to navigate the evolving threat landscape of the late 2020s and beyond.","meta_title":"PCI PTS HSM v3 & v4 Expiration Extensions: Merchant Guide","meta_description":"PCI SSC extends HSM v3 and v4 expiration dates. Learn how these new deadlines affect your payment security compliance and hardware upgrade strategy.","faq_items":[{"question":"What is a Hardware Security Module (HSM)?","answer":"An HSM is a specialized, tamper-resistant physical device used to safeguard and manage digital keys for strong authentication and cryptoprocessing within payment networks."},{"question":"Why did the PCI SSC extend the HSM v3 and v4 dates?","answer":"The extensions were granted to ensure industry stability during the transition to the new HSM v5.0 standard and to provide a 12-month overlap between major versions."},{"question":"When do PCI PTS HSM v3 devices now expire?","answer":"The expiration date for HSM v3 devices has been extended from April 2026 to April 2028."},{"question":"What is the new expiration date for HSM v4 devices?","answer":"The expiration date for HSM v4 devices has been extended from April 2032 to April 2033."}],"recommendations":["Inventory all current HSM devices and their version levels.","Contact hardware vendors to discuss v5.0 migration roadmaps.","Align hardware refresh budgets with the new 2028 and 2033 deadlines.","Evaluate application readiness for next-generation cryptographic standards."],"onkore_perspective":"ONKORE views this extension as a strategic opportunity for merchants to avoid rushed migrations. The extra time should be used to rigorously test v5.0 hardware and ensure that internal systems are ready for the shift toward crypto-agility and post-quantum security standards.","suggested_related_resources":["PCI SSC Bulletin: Extension of HSM v4 and v3 Dates","PCI PTS HSM v5.0 Security Requirements","ONKORE Guide to PCI DSS 4.0 Compliance"],"suggested_internal_links":["Understanding Payment Encryption Basics","The Future of Crypto-Agility in Payments","Merchant Guide to Hardware Security"],"suggested_cta":"Contact ONKORE today for a comprehensive review of your payment security roadmap and HSM compliance strategy.","social_post":"Important update for payment pros! The PCI SSC has extended the expiration dates for HSM v3 and v4 devices. This gives merchants more time to plan their transition to the new v5.0 standard. Check out our full breakdown of the new timelines and what they mean for your business. #PCISSC #PaymentSecurity #HSM #Compliance","newsletter_summary":"The PCI SSC has announced a significant extension for PCI PTS HSM v3 and v4 expiration dates, moving the v3 deadline to April 2028. This update provides merchants with a critical window to plan for the transition to the new v5.0 standard while maintaining operational stability.","affected_industries":["Banking","Retail","E-commerce","Payment Processing","Financial Services"],"effective_date":"2026-03-02","reading_time":6}
Trust & Sources
Reviewed by: ONKORE Payment Solutions editorial team
Published: September 1, 2026
Last updated: September 1, 2026
Sources:



