FPT Supports Nam A Bank in Achieving PCI DSS v4.0.1 Level 1 Certification to Strengthen Payment Card Security
Nam A Bank has officially achieved PCI DSS (Payment Card Industry Data Security Standard) v4.0.1 Level 1 certification—the highest and most rigorous level of PCI DSS compliance—with consulting and assessment support from FPT. This milestone reaffirms the bank’s commitment to meeting international security standards, strengthening cardholder data protection, and enhancing information security governance to address the increasingly stringent requirements of today’s digital payments ecosystem.
FPT awards Nam A Bank the PCI DSS v4.0.1 Level 1 international security certification.
PCI DSS (Payment Card Industry Data Security Standard) is the global security standard established by the Payment Card Industry Security Standards Council (PCI SSC), an organization founded by major international payment brands including Visa, Mastercard, American Express, Discover, and JCB. The standard is designed to protect cardholder data from unauthorized access and reduce fraud risks in payment card transactions. PCI DSS categorizes organizations into different compliance levels based on transaction volume, with Level 1 representing the most stringent assessment applicable to organizations with the highest card data security requirements.
As digital transformation accelerates across the financial services industry, cybersecurity has become a strategic priority. According to the IBM Cost of a Data Breach Report 2025, the financial services sector continues to rank among the industries with the highest average cost of data breaches, exceeding USD 5.5 million per incident. This underscores why international security standards such as PCI DSS have become increasingly essential for financial institutions.
For Nam A Bank, implementing the highest level of PCI DSS compliance is not only intended to satisfy the requirements of international payment card organizations but also represents a significant step in strengthening information security governance and technology risk management. By adopting internationally recognized security standards, the bank aims to enhance customer data protection, improve service quality, reinforce the trust of customers and partners, and establish a strong foundation for developing digital banking services aligned with global best practices.
From the outset of the project, FPT and Nam A Bank worked closely to conduct a comprehensive review of the bank’s existing systems, accurately define the PCI DSS assessment scope, and optimize the cardholder data environment. This approach ensured full compliance with PCI DSS requirements while minimizing the operational burden of maintaining compliance in future assessments.
According to Nam A Bank, the project’s greatest challenge was not the complexity of individual technical requirements but the need to simultaneously satisfy a vast number of detailed compliance controls, comprehensively identify every cardholder data flow, and review and adjust systems to ensure end-to-end protection of sensitive payment card information.
Ms. Ngo Thu Hong, FPT’s Lead Assessor, presents the implementation process and the joint efforts of both organizations.
Throughout the implementation, FPT supported Nam A Bank through a series of in-depth security activities designed to strengthen the security of the cardholder data environment. These included compliance gap assessments, vulnerability scanning, application and network penetration testing, network segmentation testing, cardholder data discovery, firewall rule reviews, PCI DSS risk assessments, wireless network security assessments, and cybersecurity awareness training for employees. In parallel, FPT assisted the bank in refining governance processes, collecting compliance evidence, and addressing identified gaps before the final certification assessment.
Following the assessment process, Nam A Bank was officially awarded the PCI DSS v4.0.1 Level 1 certification by FPT. The certification confirms that the systems within the assessment scope fully comply with PCI DSS requirements for protecting cardholder data while effectively addressing the non-conformities identified during the implementation process.
As one of Vietnam’s joint-stock commercial banks actively accelerating its digital transformation strategy, Nam A Bank continues to invest in modernizing its technology infrastructure and strengthening governance capabilities. The bank recently deployed its next-generation core banking system and launched Open Banking 3.0, creating a stronger foundation for operational efficiency, regulatory compliance, and the expansion of its digital banking ecosystem. Achieving PCI DSS v4.0.1 Level 1 further reinforces one of the bank’s critical cybersecurity pillars, ensuring its payment services operate in accordance with internationally recognized security standards.
Mr. Nguyen Vinh Tuyen of Nam A Bank shares the bank’s commitment to delivering secure digital financial services.
Representing Nam A Bank, Mr. Nguyen Vinh Tuyen, Deputy CEO of Nam A Bank, said: “For Nam A Bank, the greatest value of the PCI DSS project extends far beyond obtaining an international security certification. More importantly, it has fundamentally transformed our approach to information security governance across the organization. What began as a compliance initiative has evolved into a shared commitment, fostering cross-functional collaboration and placing customer data protection at the center of our operations. This achievement provides a solid foundation for us to further strengthen risk management capabilities, develop secure digital financial services, and deliver trusted experiences for our customers.”
Mr. Mai Trong Kha of FPT expresses pride in supporting Nam A Bank on this important milestone toward building a secure and modern digital payments ecosystem.
Representing FPT, Mr. Mai Trong Kha stated: “Achieving PCI DSS certification is not simply about passing a compliance assessment; more importantly, it is about establishing a robust information security management framework capable of continuous operation and improvement. FPT is proud to have partnered with Nam A Bank throughout the entire journey—from initial system assessment and scope optimization to technical security assessments and compliance documentation. This achievement further demonstrates FPT’s capability to help banks and financial institutions meet international security standards while contributing to the development of a secure and sustainable digital payments ecosystem in Vietnam.”
With nearly four decades of experience delivering mission-critical technology and cybersecurity projects, FPT is among the few organizations in Vietnam with comprehensive capabilities to provide PCI DSS consulting, assessment, and certification services for banks, financial institutions, and payment service providers. Since 2015, FPT has partnered with leading organizations including MB, OCB, SeABank, Eximbank, Lotte Finance Vietnam, FE CREDIT, PVcomBank, One Mount Group, and Pay2Pay, helping them achieve international security compliance, strengthen data protection capabilities, and support the secure development of Vietnam’s digital financial ecosystem.



