2. THE FUNDAMENTALS
This chapter presents the fundamentals of Personal Identity Verification (PIV) Card Issuer (PCI)
accreditation including: (i) definitions of a PCI and a PCI Facility; (ii) outsourcing PCI services
or functions; (iii) the differences between assessment and accreditation; (iv) accreditation
boundaries of a PCI; (v) roles and responsibilities; (vi) the relationship between accreditation
under Special Publication (SP) 800-37 and SP 800-79-1; (vii) preparing for the assessment; (viii)
types of accreditation decisions; (ix) use of risk in the accreditation decision; and (x) the contents
of the accreditation package.
2.1 PCI
At the highest level, a PCI includes all functions required to produce, issue, and maintain PIV
Cards for an organization. A PCI is considered operational if all relevant roles and
responsibilities have been defined and appointed; suitable policies and compliant procedures
have been implemented for processes, including sponsorship, enrollment/identity proofing,
adjudication, card production, card activation/issuance, and maintenance; and information
system components that are utilized for performing the above-mentioned functions (processes)
have been assessed and shown to meet all technical and operational requirements prescribed in
FIPS 201-1 and related documents.
In order to comply with Homeland Security Presidential Directive 12 (HSPD-12), an
organization must first establish a PCI that conforms to and satisfies the requirements of FIPS
201-1 and related documents. The PCI must then be accredited (i.e., using the guidelines
specified in SP 800-79-1). An organization has certain flexibility in establishing a PCI. It may
outsource some of the required processes within its PCI. Large organizations with widely
varying missions for its operating units may even establish multiple PCIs. Regardless of how a
PCI is structured, the organization (e.g., Federal agency, Federal contractor) is responsible for
the management and oversight of the PCI and maintains full responsibility for the accreditation
of the PCI as required in HSPD-12.
A PCI must be completely described in its PCI operations plan. This comprehensive document
incorporates all the information about the PCI that is needed for any independent party to review
it and assess the capability and reliability of the PCI’s operations. A PCI operations plan includes
a description of the structure of the PCI, its facilities, any external service providers, the roles
and responsibilities within the PCI, policies and procedures which govern its operations, and a
description of how requirements of FIPS 201-1 are being met. A template for a PCI operations
plan is provided in Appendix D.
2.2 PCI Facilities
A PCI Facility (PCIF) is a physical site or location–including all equipment, staff, and
documentation–that is responsible for carrying out one or more of the following PIV functions:
(i) enrollment/identity proofing; (ii) card production; (iii) card activation/issuance; or (iv)
maintenance. A PCIF operates under the auspices of a PCI, and implements the policies and
executes procedures prescribed by the PCI for those functions sanctioned for the facility (e.g. an
enrollment/identity proofing facility).
8