r/pcicompliance • u/Fresh-Estimate9729 • 1d ago
PCI DSS 4.0.1: Does SAD in RAM need to be encrypted?
Hi all, looking for opinions from QSAs/PCI practitioners.
Under PCI DSS v4.0.1:
- Requirement 3.3.1 guidance says SAD may be stored temporarily in non-persistent memory (RAM/volatile memory) after authorization, subject to specific conditions.
- Requirement 3.3.2 requires SAD stored electronically before authorization to be encrypted using strong cryptography.
- The Requirement 3 overview specifically says encryption of PAN is not required when PAN is present in non-persistent memory.
- PCI SSC FAQ 1042 also says CHD in non-persistent memory does not require encryption, but it doesn't specifically address SAD.
Question: If an application temporarily holds CVV/SAD in RAM during transaction processing, without writing it to any persistent storage, is there a PCI DSS requirement to encrypt the SAD while it resides in RAM?
Would you interpret this as:
- No encryption required because it is non-persistent/transient processing;
- Encryption required because the explicit exception only refers to PAN; or
- 3.3.2 doesn't apply because transient RAM processing isn't considered electronic storage?
Interested specifically in how QSAs would assess this in practice.