ISO 25186:2026
(Main)Financial services — Methods for the generation and verification of card security codes
General Information
- Abstract
This document defines a method for generating and verifying card security codes (CSCs) using cipher-based message authentication code (CMAC) or keyed-hash message authentication code (HMAC). Key management mechanisms associated with these processes are beyond the scope of this document.
- Status
- Published
- Publication Date
- 02-Aug-2026
- Technical Committee
- ISO/TC 68/SC 2 - Financial Services, security
- Drafting Committee
- ISO/TC 68/SC 2/WG 13 - Security in retail banking
- Current Stage
- 6060 - International Standard published
- Start Date
- 03-Aug-2026
- Due Date
- 01-Jul-2027
- Completion Date
- 03-Aug-2026
Overview
ISO 25186: Financial services - Methods for the generation and verification of card security codes is an International Standard developed by ISO Technical Committee 68, Subcommittee 2 (ISO/TC 68/SC 2). This standard establishes globally recognized requirements and guidance for generating, changing, and verifying card authentication codes, commonly referred to as card security codes (CSCs). It specifies the use of strong cryptographic techniques such as block cipher-based MACs (e.g., CMAC) and hash-based MACs (e.g., HMAC) for securing both static and dynamic CSCs used in payment card transactions. By directing compliant implementations, ISO 25186 supports interoperability and robust security for digital payment and card-based authentication environments.
Key Topics
Card Security Codes (CSCs)
ISO 25186 addresses both static and dynamic CSCs. CSCs protect card-not-present transactions by authenticating the cardholder and enhancing payment security.Cryptographic Algorithms
The standard requires CSC generation and verification methods to use a 16-byte block cipher or a hash-based MAC with equivalent cryptographic strength. Supported algorithms include:- CMAC according to ISO/IEC 9797-1 (block cipher-based MAC)
- HMAC according to ISO/IEC 9797-2 (hash-based MAC)
- Block ciphers and hash functions referenced must comply with ISO/IEC 18033-3 and ISO/IEC 10118-3 respectively.
Generation and Verification Process
- The CSC is generated by applying a MAC algorithm to essential card data fields, such as the primary account number (PAN), expiry date, service code, and optional diversification data.
- Diversification data (e.g., timestamp, counter, or random number) helps ensure uniqueness for dynamic CSCs.
- The verification process involves recalculating the CSC using the same cryptographic method and comparing it to the provided value.
Support for Multiple CSCs
The standard allows for the generation and management of multiple CSCs for a single card account, accommodating different purposes by using distinct keys or incorporating purpose identifiers in the cryptographic process.
Applications
ISO 25186 plays a critical role for organizations in the financial services sector-especially issuers, payment processors, and service providers managing card-based transactions. Key applications include:
Remote Commerce and Online Payments
Implementation of ISO 25186 facilitates secure authentication for card-not-present transactions, reducing fraud.Dynamic CSC Generation
Enables the use of dynamic card security codes delivered through smart cards, mobile devices, or digital wallets, increasing security with single-use or time-based codes.Interoperability and Compliance
By adhering to ISO 25186, organizations ensure compatibility across international payment systems while meeting regulatory and security expectations.Development of Secure Payment Products
Vendors and developers adopt this standard to build or update hardware security modules (HSMs), payment gateways, and card issuance systems capable of secure CSC processing.
Related Standards
ISO 25186 references and complements several important international standards related to card security and cryptography, including:
- ISO/IEC 9797-1: Security techniques – Message Authentication Codes (MACs) – Mechanisms using a block cipher
- ISO/IEC 9797-2: Information security – Message authentication codes (MACs) – Mechanisms using a dedicated hash-function
- ISO/IEC 18033-3: Security techniques – Encryption algorithms – Part 3: Block ciphers
- ISO/IEC 10118-3: IT Security techniques – Hash-functions – Part 3: Dedicated hash-functions
- ISO/IEC 7812-1: Identification cards – Numbering system (for defining PAN structure)
- ISO 9564-1: PIN management and security – Basic principles and requirements in card-based systems
Organizations adopting ISO 25186 improve payment security, contribute to global interoperability, and align with best practices for card security code generation and verification.
Get Certified
Connect with accredited certification bodies for this standard

BSI Group
BSI (British Standards Institution) is the business standards company that helps organizations make excellence a habit.
Great Wall Tianjin Quality Assurance Center
Established 1993, first batch to receive national accreditation with IAF recognition.
Hong Kong Quality Assurance Agency (HKQAA)
Hong Kong's leading certification body.
Sponsored listings
Frequently Asked Questions
ISO 25186:2026 is a standard published by the International Organization for Standardization (ISO). Its full title is "Financial services — Methods for the generation and verification of card security codes". This standard covers: This document defines a method for generating and verifying card security codes (CSCs) using cipher-based message authentication code (CMAC) or keyed-hash message authentication code (HMAC). Key management mechanisms associated with these processes are beyond the scope of this document.
This document defines a method for generating and verifying card security codes (CSCs) using cipher-based message authentication code (CMAC) or keyed-hash message authentication code (HMAC). Key management mechanisms associated with these processes are beyond the scope of this document.
ISO 25186:2026 is classified under the following ICS (International Classification for Standards) categories: 03.060 - Finances. Banking. Monetary systems. Insurance; 35.240.15 - Identification cards. Chip cards. Biometrics. The ICS classification helps identify the subject area and facilitates finding related standards.
ISO 25186:2026 is available in PDF format for immediate download after purchase. The document can be added to your cart and obtained through the secure checkout process. Digital delivery ensures instant access to the complete standard document.
Standards Content (Sample)
International
Standard
ISO 25186
First edition
Financial services — Methods for
2026-08
the generation and verification of
card security codes
Reference number
© ISO 2026
All rights reserved. Unless otherwise specified, or required in the context of its implementation, no part of this publication may
be reproduced or utilized otherwise in any form or by any means, electronic or mechanical, including photocopying, or posting on
the internet or an intranet, without prior written permission. Permission can be requested from either ISO at the address below
or ISO’s member body in the country of the requester.
ISO copyright office
CP 401 • Ch. de Blandonnet 8
CH-1214 Vernier, Geneva
Phone: +41 22 749 01 11
Email: copyright@iso.org
Website: www.iso.org
Published in Switzerland
ii
Contents Page
Foreword .iv
Introduction .v
1 Scope . 1
2 Normative references . 1
3 Terms and definitions . 1
4 Generation and verification . 2
4.1 CSC algorithm .2
4.2 Generation .3
4.3 Verification . .4
4.4 Multiple CSCs .4
5 MAC algorithm . 4
Annex A (informative) Worked examples . 5
Bibliography . 8
iii
Foreword
ISO (the International Organization for Standardization) is a worldwide federation of national standards
bodies (ISO member bodies). The work of preparing International Standards is normally carried out through
ISO technical committees. Each member body interested in a subject for which a technical committee
has been established has the right to be represented on that committee. International organizations,
governmental and non-governmental, in liaison with ISO, also take part in the work. ISO collaborates closely
with the International Electrotechnical Commission (IEC) on all matters of electrotechnical standardization.
The procedures used to develop this document and those intended for its further maintenance are described
in the ISO/IEC Directives, Part 1. In particular, the different approval criteria needed for the different types
of ISO documents should be noted. This document was drafted in accordance with the editorial rules of the
ISO/IEC Directives, Part 2 (see www.iso.org/directives).
ISO draws attention to the possibility that the implementation of this document may involve the use of (a)
patent(s). ISO takes no position concerning the evidence, validity or applicability of any claimed patent
rights in respect thereof. As of the date of publication of this document, ISO had not received notice of (a)
patent(s) which may be required to implement this document. However, implementers are cautioned that
this may not represent the latest information, which may be obtained from the patent database available at
www.iso.org/patents. ISO shall not be held responsible for identifying any or all such patent rights.
Any trade name used in this document is information given for the convenience of users and does not
constitute an endorsement.
For an explanation of the voluntary nature of standards, the meaning of ISO specific terms and expressions
related to conformity assessment, as well as information about ISO's adherence to the World Trade
Organization (WTO) principles in the Technical Barriers to Trade (TBT), see www.iso.org/iso/foreword.html.
This document was prepared by Technical Committee ISO/TC 68, Financial services, Subcommittee SC 2
Financial services, security.
Any feedback or questions on this document should be directed to the user’s national standards body. A
complete listing of these bodies can be found at www.iso.org/members.html.
iv
Introduction
Payment cards commonly carry a static three-digit or four-digit card security code (CSC) used for
authenticating remote commerce transactions. Card security codes can also be dynamically generated on
devices with cryptographic computation capabilities such as smart cards and phones or retrieved from
another system.
This document provides requirements and guidance for methods for generation and verification of CSCs.
Requirements and guidance are designed to support secure and interoperable implementations.
This document identifies ciphers and algorithms that are specifically approved for use with CSCs.
v
International Standard ISO 25186:2026(en)
Financial services — Methods for the generation and
verification of card security codes
1 Scope
This document defines a method for generating and verifying card security codes (CSCs) using cipher-based
message authentication code (CMAC) or keyed-hash message authentication code (HMAC).
Key management mechanisms associated with these processes are beyond the scope of this document.
2 Normative references
The following documents are referred to in the text in such a way that some or all of their content constitutes
requirements of this document. For dated references, only the edition cited applies. For undated references,
the latest edition of the referenced document (including any amendments) applies.
ISO/IEC 9797-1, Information technology — Security techniques — Message Authentication Codes (MACs) —
Part 1: Mechanisms using a block cipher
ISO/IEC 9797-2, Information security — Message authentication codes (MACs) — Part 2: Mechanisms using a
dedicated hash-function
ISO/IEC 18033-3, Information technology — Security techniques — Encryption algorithms — Part 3: Block
ciphers
ISO/IEC 10118-3, IT Security techniques — Hash-functions — Part 3: Dedicated hash-functions
3 Terms and definitions
For the purposes of this document, the following terms and definitions apply.
ISO and IEC maintain terminology databases for use in standardization at the following addresses:
— ISO online browsing platform: available at https:// www .iso .org/ obp
— IEC Electropedia: available at https:// www .electropedia .org/
3.1
CMAC
cipher-based message authentication code
message authentication code (3.5) based on a symmetric block cipher, as defined in ISO/IEC 9797-1 (MAC
algorithm 5)
3.2
card security code
CSC
cryptographic checksum generated by a card issuer or its agent for the purpose of providing authentication
of a primary account number (3.7) and its service code with expiry date
3.3
CSC key
cryptographic key used with a message authentication code algorithm (3.6) to calculate the card security
code (3.2)
3.4
HMAC
keyed-hash message authentication code
message authentication code (3.5) based on a cryptographic hash function, as defined in ISO/IEC 9797-2
(MAC algorithm 2)
3.5
MAC
message authentication code
string of bits which is the output of a MAC algorithm
[SOURCE: ISO/IEC 9797-1:2011, 3.9]
3.6
MAC algorithm
algorithm for computing a function which maps strings of bits and a secret key to fixed-length strings of
bits, satisfying the following two properties:
— for any key and any input string, the function can be computed efficien
...



