FPT Supports Nam A Bank in Achieving PCI DSS v4.0.1 Level 1 Certification to Strengthen Payment Card Security

10/07/2026

Nam A Bank has officially achieved the Payment Card Industry Data Security Standard (PCI DSS) v4.0.1 Level 1 certification—the most stringent level of PCI DSS compliance—with consulting and assessment support from FPT. This milestone underscores Nam A Bank’s commitment to meeting international security standards, strengthening cardholder data protection, and enhancing information security governance to address the increasingly demanding requirements of the digital payments ecosystem.

FPT awards PCI DSS v4.0.1 Level 1 certification to Nam A Bank.

PCI DSS (Payment Card Industry Data Security Standard) is the global security standard for payment card data established by the Payment Card Industry Security Standards Council (PCI SSC), an organization founded by the world's major payment card brands, including Visa Inc., Mastercard, American Express, Discover, and JCB. Its primary objective is to safeguard cardholder data from unauthorized access and minimize payment card fraud. PCI DSS categorizes organizations into different compliance levels based on transaction volume, with Level 1 representing the highest and most rigorous level of assessment for organizations with the most demanding card data security requirements.

As digital transformation continues to reshape the banking and financial services industry, data security has become a strategic priority. According to the IBM Cost of a Data Breach Report 2025, the financial services sector remains among the industries with the highest average cost of data breaches, exceeding USD 5.5 million per incident. Consequently, international security standards such as PCI DSS have become increasingly important for financial institutions.

For Nam A Bank, achieving the highest level of PCI DSS compliance is not only about meeting the requirements of international payment card organizations but also represents a strategic step toward strengthening information security governance and technology risk management. By implementing internationally recognized security standards, the bank aims to enhance customer data protection, improve service quality, reinforce customer and partner trust, and establish a solid foundation for developing digital banking services aligned with global best practices.

From the outset of the project, FPT worked closely with Nam A Bank to conduct a comprehensive review of the bank’s existing systems, accurately define the PCI DSS scope, and optimize the cardholder data environment. This approach ensured full compliance with the standard while reducing the operational burden of maintaining compliance in future assessment cycles.

According to Nam A Bank representatives, the greatest challenge was not the complexity of individual technical requirements, but rather the need to simultaneously satisfy a large number of detailed controls, identify every cardholder data flow, and review and adjust systems to ensure end-to-end protection of sensitive data throughout processing.

Ms. Ngo Thu Hong, Lead Assessor from FPT, presents the implementation process and the joint efforts of both organizations.

Throughout the implementation process, FPT partnered with Nam A Bank on a wide range of technical and governance activities to strengthen the security of the cardholder data environment. These included compliance gap assessments, vulnerability scanning, application and network penetration testing, network segmentation testing, cardholder data discovery, firewall rule reviews, PCI DSS risk assessments, wireless network scanning, and security awareness training for employees.

In parallel, FPT assisted the bank in refining governance processes, collecting compliance evidence, and addressing identified gaps before conducting the final certification assessment.

Following the assessment, Nam A Bank was officially awarded PCI DSS v4.0.1 Level 1 certification by FPT—the highest level of PCI DSS compliance. The certification confirms that the bank’s assessed environment fully satisfies PCI DSS requirements for protecting cardholder data while effectively addressing compliance gaps identified during the implementation process.

As one of Vietnam’s commercial banks actively accelerating its digital transformation strategy, Nam A Bank continues to invest in modernizing its technology infrastructure and strengthening governance capabilities. Most recently, the bank successfully deployed its next-generation Core Banking system and launched Open Banking 3.0, creating a stronger foundation for operational efficiency, regulatory compliance, and digital banking ecosystem development. Achieving PCI DSS v4.0.1 Level 1 further reinforces one of the bank’s key information security pillars, ensuring its payment services operate in accordance with internationally recognized security standards.

Mr. Nguyen Vinh Tuyen of Nam A Bank shares the bank’s commitment to developing secure digital financial services.

Representing Nam A Bank, Mr. Nguyen Vinh Tuyen, Deputy Chief Executive Officer, said: "For Nam A Bank, the greatest value of the PCI DSS project extends beyond obtaining an internationally recognized security certification. More importantly, it has driven a significant transformation in our organization's approach to information security governance. What began as a compliance initiative has evolved into a shared commitment across departments, with protecting customer data becoming a collective priority. This achievement provides a strong foundation for us to further enhance risk management capabilities, develop secure digital financial services, and deliver trusted experiences to our customers."

Mr. Mai Trong Kha of FPT expresses pride in supporting Nam A Bank on this important milestone toward building a secure and modern digital payment ecosystem.

Representing FPT, Mr. Mai Trong Kha commented: "Achieving PCI DSS certification is not simply about passing a compliance assessment. More importantly, it means establishing a comprehensive information security management system capable of continuous operation and improvement. FPT is proud to have supported Nam A Bank throughout the entire journey—from initial assessments and scope optimization to technical evaluations and compliance documentation. This achievement further demonstrates FPT’s capabilities in helping banks and financial institutions meet international security standards while contributing to the development of a secure and sustainable digital payments ecosystem in Vietnam."

With nearly four decades of experience delivering mission-critical technology and cybersecurity projects, FPT is among the few organizations in Vietnam with comprehensive capabilities to provide PCI DSS consulting, assessment, and certification services for banks, financial institutions, and payment service providers.

Since 2015, FPT has supported numerous leading organizations—including MB, OCB, SeABank, Eximbank, Lotte Finance Vietnam, FE CREDIT, PVcomBank, One Mount Group, and Pay2Pay—in achieving international security compliance, strengthening data protection capabilities, and fostering the sustainable development of Vietnam’s digital financial ecosystem.