[in]security blog

What Is The Difference Between Masking And Truncation In PCI Compliance? | blog,pci | Control Gap

Written by David Gamey | Jan 18, 2017 3:07:00 AM

Masking and truncation of cardholder data may seem the same on the surface (eg. 423456XXXXXX7890); however, each implies different functionality.

Masking applies to displays and implies the data can be accessed behind the scenes.

Truncation applies to storage and implies the permanent and irrecoverable transformation of the original data.

For more see the official PCI Compliance glossary.