The PCI 3DS Core Security Standard and PCI 3DS SDK Security Standard are independent standards defining security controls covering different areas of the 3DS ecosystem.
Who needs to be validated? 3DS Server (3DSS) providers, Access Control Server (ACS) providers and Directory Server (DS) providers.
PCI 3DS is a one-year program, so assessment should be performed annually by a PCI 3DS auditor.
Kickoff and Planning — including the critical "3DS scoping" step. Formal validation — the 3DS QSA conducts on-site interviews, configuration sampling and document reviews. Reporting — within 3 weeks of successful completion.
Deliverables may include: 3DS Core RoC, 3DS Core AoC, 3DS SDK RoV, 3DS SDK AoV. Completed 3DS documentation is submitted to the customer's participating payment brands.
Continual Support after certification.
Reference: PCI SSC Document Library.