August 08, 2018
Don’t Delay, Migrate Today (Away from SSL/Early TLS)
Written by
Steve Maxwell
Application Security Assessment
Penetration Testing
Security Testing & Analysis

For those tempted to delay migration away from Secure Sockets Layer (SSL)/early Transport Layer Security (TLS)—don't wait! This includes all versions of SSL and version 1.0 of TLS (TLS v1.1 and newer are fine).
For Payment Card Industry Data Security Standard (PCI-DSS) compliance, you can't simply migrate sometime before your next PCI audit. Rather, you must have compliant scans in every quarter, and your Approved Scanning Vendor (ASV) may no longer issue an Attestation of Scan Compliance (AoSC) with SSL/early TLS. Considering the fact that these scans are required each quarter, the next audit might fail if any quarter is not compliant. However, this might not apply to those seeking first-time compliance.
This is Now
June 30, 2018 was the last day that organizations could be compliant while running SSL and early TLS within the public, untrusted network (i.e. the Internet). Note that SSL and early TLS are still fine to use within the cardholder data environment or any trusted network.