ISO 25186:2026
(Main)Financial services — Methods for the generation and verification of card security codes
General Information
- Abstract
This document defines a method for generating and verifying card security codes (CSCs) using cipher-based message authentication code (CMAC) or keyed-hash message authentication code (HMAC). Key management mechanisms associated with these processes are beyond the scope of this document.
- Status
- Published
- Publication Date
- 02-Aug-2026
- Technical Committee
- ISO/TC 68/SC 2 - Financial Services, security
- Drafting Committee
- ISO/TC 68/SC 2/WG 13 - Security in retail banking
- Current Stage
- 6060 - International Standard published
- Start Date
- 03-Aug-2026
- Due Date
- 01-Jul-2027
- Completion Date
- 03-Aug-2026
Overview
ISO 25186:2026: Financial Services - Methods for the Generation and Verification of Card Security Codes is an international standard developed by ISO to establish secure, interoperable methods for generating and verifying card security codes (CSCs). This standard specifies the use of cryptographically strong message authentication codes, specifically cipher-based MAC (CMAC) and keyed-hash MAC (HMAC), for creating and validating CSCs. Card security codes are essential for authentication in remote payments and card-not-present transactions.
ISO 25186:2026 does not cover key management mechanisms for the cryptographic keys used in these processes, focusing solely on the methods for CSC generation and verification. The document aims to support secure, consistent, and widely accepted implementations across global financial services and payments industries.
Key Topics
Card Security Code (CSC) Generation:
The standard defines a precise algorithm for generating CSCs using CMAC or HMAC techniques. Inputs include the primary account number (PAN), PAN sequence number, expiry date, service code, and optionally, diversification data to ensure uniqueness.CSC Verification:
Verification consists of using the same algorithm to recompute the expected CSC value and comparing it to the submitted code as part of transaction authentication, supporting security in remote or online card payments.Use of Cryptographic Algorithms:
- CMAC is used with block ciphers, as specified in ISO/IEC 18033-3.
- HMAC is used with cryptographic hash functions, as outlined in ISO/IEC 10118-3. Both approaches require a CSC key with a minimum cryptographic strength of 128 bits.
Diversification Data:
The inclusion of unique data-such as timestamp, counter, or random numbers-ensures uniqueness in dynamically generated CSCs and assists in anti-replay protection for single-use codes.Multiple CSC Support:
The standard allows for multiple CSCs per account. Each may be generated for different purposes, using either separate cryptographic keys or distinguishing diversification data.
Applications
ISO 25186:2026 is highly relevant for:
Payment Card Issuers and Acquirers:
Implementing secure algorithms for CSC generation and validation in their card processing systems increases payment security and helps meet compliance requirements.Payment Gateways and Processors:
Adopting the methods within this standard ensures consistent CSC verification for card-not-present transactions, reducing fraud risk and enhancing trust.Smart Cards and Mobile Payments:
The standard supports both static and dynamic CSC generation, facilitating the integration of secure code generation into cards and mobile devices with cryptographic functions.E-Commerce and Remote Payments:
Merchants and e-commerce platforms benefit from interoperability and increased fraud prevention when relying on systems that comply with ISO 25186:2026.
Related Standards
For comprehensive implementation and broader context in payment card security, consider referencing:
- ISO/IEC 9797-1: Message Authentication Codes (MACs) utilizing block ciphers
- ISO/IEC 9797-2: MAC mechanisms using dedicated hash functions
- ISO/IEC 18033-3: Encryption algorithms - Block ciphers
- ISO/IEC 10118-3: Security techniques - Dedicated hash-functions
- ISO/IEC 7812-1: Card issuer identification numbering systems
- ISO 9564-1: PIN management and security for card-based systems
These related standards provide foundational cryptographic methods, card number structures, and guidelines for secure authentication in financial applications.
By following ISO 25186:2026, financial organizations and service providers can standardize secure, robust card security code generation and verification, strengthening card payment security across all channels.
Get Certified
Connect with accredited certification bodies for this standard

BSI Group
BSI (British Standards Institution) is the business standards company that helps organizations make excellence a habit.
Great Wall Tianjin Quality Assurance Center
Established 1993, first batch to receive national accreditation with IAF recognition.
Hong Kong Quality Assurance Agency (HKQAA)
Hong Kong's leading certification body.
Sponsored listings
Frequently Asked Questions
ISO 25186:2026 is a standard published by the International Organization for Standardization (ISO). Its full title is "Financial services — Methods for the generation and verification of card security codes". This standard covers: This document defines a method for generating and verifying card security codes (CSCs) using cipher-based message authentication code (CMAC) or keyed-hash message authentication code (HMAC). Key management mechanisms associated with these processes are beyond the scope of this document.
This document defines a method for generating and verifying card security codes (CSCs) using cipher-based message authentication code (CMAC) or keyed-hash message authentication code (HMAC). Key management mechanisms associated with these processes are beyond the scope of this document.
ISO 25186:2026 is classified under the following ICS (International Classification for Standards) categories: 03.060 - Finances. Banking. Monetary systems. Insurance; 35.240.15 - Identification cards. Chip cards. Biometrics. The ICS classification helps identify the subject area and facilitates finding related standards.
ISO 25186:2026 is available in PDF format for immediate download after purchase. The document can be added to your cart and obtained through the secure checkout process. Digital delivery ensures instant access to the complete standard document.
Standards Content (Sample)
International
Standard
ISO 25186
First edition
Financial services — Methods for
2026-08
the generation and verification of
card security codes
Reference number
© ISO 2026
All rights reserved. Unless otherwise specified, or required in the context of its implementation, no part of this publication may
be reproduced or utilized otherwise in any form or by any means, electronic or mechanical, including photocopying, or posting on
the internet or an intranet, without prior written permission. Permission can be requested from either ISO at the address below
or ISO’s member body in the country of the requester.
ISO copyright office
CP 401 • Ch. de Blandonnet 8
CH-1214 Vernier, Geneva
Phone: +41 22 749 01 11
Email: copyright@iso.org
Website: www.iso.org
Published in Switzerland
ii
Contents Page
Foreword .iv
Introduction .v
1 Scope . 1
2 Normative references . 1
3 Terms and definitions . 1
4 Generation and verification . 2
4.1 CSC algorithm .2
4.2 Generation .3
4.3 Verification . .4
4.4 Multiple CSCs .4
5 MAC algorithm . 4
Annex A (informative) Worked examples . 5
Bibliography . 8
iii
Foreword
ISO (the International Organization for Standardization) is a worldwide federation of national standards
bodies (ISO member bodies). The work of preparing International Standards is normally carried out through
ISO technical committees. Each member body interested in a subject for which a technical committee
has been established has the right to be represented on that committee. International organizations,
governmental and non-governmental, in liaison with ISO, also take part in the work. ISO collaborates closely
with the International Electrotechnical Commission (IEC) on all matters of electrotechnical standardization.
The procedures used to develop this document and those intended for its further maintenance are described
in the ISO/IEC Directives, Part 1. In particular, the different approval criteria needed for the different types
of ISO documents should be noted. This document was drafted in accordance with the editorial rules of the
ISO/IEC Directives, Part 2 (see www.iso.org/directives).
ISO draws attention to the possibility that the implementation of this document may involve the use of (a)
patent(s). ISO takes no position concerning the evidence, validity or applicability of any claimed patent
rights in respect thereof. As of the date of publication of this document, ISO had not received notice of (a)
patent(s) which may be required to implement this document. However, implementers are cautioned that
this may not represent the latest information, which may be obtained from the patent database available at
www.iso.org/patents. ISO shall not be held responsible for identifying any or all such patent rights.
Any trade name used in this document is information given for the convenience of users and does not
constitute an endorsement.
For an explanation of the voluntary nature of standards, the meaning of ISO specific terms and expressions
related to conformity assessment, as well as information about ISO's adherence to the World Trade
Organization (WTO) principles in the Technical Barriers to Trade (TBT), see www.iso.org/iso/foreword.html.
This document was prepared by Technical Committee ISO/TC 68, Financial services, Subcommittee SC 2
Financial services, security.
Any feedback or questions on this document should be directed to the user’s national standards body. A
complete listing of these bodies can be found at www.iso.org/members.html.
iv
Introduction
Payment cards commonly carry a static three-digit or four-digit card security code (CSC) used for
authenticating remote commerce transactions. Card security codes can also be dynamically generated on
devices with cryptographic computation capabilities such as smart cards and phones or retrieved from
another system.
This document provides requirements and guidance for methods for generation and verification of CSCs.
Requirements and guidance are designed to support secure and interoperable implementations.
This document identifies ciphers and algorithms that are specifically approved for use with CSCs.
v
International Standard ISO 25186:2026(en)
Financial services — Methods for the generation and
verification of card security codes
1 Scope
This document defines a method for generating and verifying card security codes (CSCs) using cipher-based
message authentication code (CMAC) or keyed-hash message authentication code (HMAC).
Key management mechanisms associated with these processes are beyond the scope of this document.
2 Normative references
The following documents are referred to in the text in such a way that some or all of their content constitutes
requirements of this document. For dated references, only the edition cited applies. For undated references,
the latest edition of the referenced document (including any amendments) applies.
ISO/IEC 9797-1, Information technology — Security techniques — Message Authentication Codes (MACs) —
Part 1: Mechanisms using a block cipher
ISO/IEC 9797-2, Information security — Message authentication codes (MACs) — Part 2: Mechanisms using a
dedicated hash-function
ISO/IEC 18033-3, Information technology — Security techniques — Encryption algorithms — Part 3: Block
ciphers
ISO/IEC 10118-3, IT Security techniques — Hash-functions — Part 3: Dedicated hash-functions
3 Terms and definitions
For the purposes of this document, the following terms and definitions apply.
ISO and IEC maintain terminology databases for use in standardization at the following addresses:
— ISO online browsing platform: available at https:// www .iso .org/ obp
— IEC Electropedia: available at https:// www .electropedia .org/
3.1
CMAC
cipher-based message authentication code
message authentication code (3.5) based on a symmetric block cipher, as defined in ISO/IEC 9797-1 (MAC
algorithm 5)
3.2
card security code
CSC
cryptographic checksum generated by a card issuer or its agent for the purpose of providing authentication
of a primary account number (3.7) and its service code with expiry date
3.3
CSC key
cryptographic key used with a message authentication code algorithm (3.6) to calculate the card security
code (3.2)
3.4
HMAC
keyed-hash message authentication code
message authentication code (3.5) based on a cryptographic hash function, as defined in ISO/IEC 9797-2
(MAC algorithm 2)
3.5
MAC
message authentication code
string of bits which is the output of a MAC algorithm
[SOURCE: ISO/IEC 9797-1:2011, 3.9]
3.6
MAC algorithm
algorithm for computing a function which maps strings of bits and a secret key to fixed-length strings of
bits, satisfying the following two properties:
— for any key and any input string, the function can be computed efficien
...



