
Payment service providers (PSPs) have traditionally relied on compliance assessments and periodic security reviews to demonstrate that their payment devices are secure. However, that model is becoming increasingly difficult to sustain. Vulnerabilities emerge daily, attackers can weaponise them within hours, and AI is accelerating the speed at which cybercriminals can identify and exploit weaknesses. As a result, a device that was considered secure during its last assessment may already represent a growing risk.
This creates a fundamental challenge for PSPs. They remain responsible for securing devices throughout their lifecycle, yet often lack the visibility needed to understand how new vulnerabilities affect the hardware and software components operating inside them. In an environment where risks are constantly changing, relying on point-in-time compliance alone is no longer enough.
AI is not only helping attackers move faster. It is also giving product security teams new ways to continuously monitor risk, assess emerging vulnerabilities and reconstruct incomplete Software Bills of Materials (SBOMs), helping them build a more accurate picture of their exposure.
PSPs now need to use these capabilities to move beyond periodic assessments and towards continuous, intelligence-led oversight of device security.
The drawbacks of point-in-time compliance:
PSPs have long relied on compliance (PCI PTS) testing results provided by OEMs as the foundation of device security. Such compliance remains an important baseline, but it was designed for a world in which risks evolved more slowly than they do today.
Payment devices are typically tested before launch and then reassessed periodically. This is not fit for purpose when 133 CVEs are published daily and attackers can weaponise new vulnerabilities within hours or days of disclosure. In that environment, a certification result from the past cannot be treated as proof of present security.
The issue is not that compliance has become irrelevant. Rather, compliance alone cannot provide assurance that a device remains secure between assessment cycles. A device can still be compliant on paper while becoming increasingly exposed in practice.
This gap is increasingly recognized by both industry standards and regulation. While PCI standards continue to evolve toward greater emphasis on ongoing security, vulnerability management, and software integrity throughout a product’s lifecycle, the EU Cyber Resilience Act (CRA) will make continuous vulnerability handling, timely security updates, and coordinated vulnerability disclosure legal obligations for manufacturers of connected products when entering the European market.
Together, these developments signal a clear shift away from point-in-time certification toward continuous security assurance across the entire lifecycle of payment devices as well.
Traditional security models are losing ground
One of the biggest reasons for this growing disconnect is that PSPs often lack complete visibility into the devices they are responsible for securing.
Payment terminals are built from multiple layers of hardware and software components sourced from different vendors, and frequently incorporate open-source libraries. This creates a fragmented flow of information and makes it difficult for PSPs to maintain a complete understanding of device composition throughout its lifecycle.
Software Bills of Materials (SBOMs) are intended to improve that visibility by documenting the software components within a device and their dependencies. However, they are often incomplete, outdated or limited in scope, overlooking deeper dependencies and open-source elements. Suppliers may also disclose vulnerabilities inconsistently, while fixes made elsewhere in the supply chain are not always communicated upwards.
As a result, PSPs are frequently forced to make security decisions using partial or outdated information. Research shows that 86 per cent of commercial codebases contain open-source vulnerabilities, while the average codebase now contains hundreds of software components, many of which are several years old.
Historically, this lack of visibility created management challenges. Today, however, it is becoming a much more significant security risk because attackers can exploit these blind spots far more quickly through AI than organisations can identify them through traditional review processes.
AI is accelerating the threat cycle
The pressure on traditional assessment models is being amplified by AI.
Security teams are already dealing with huge volumes of vulnerability data. The challenge is not just spotting a new issue but understanding whether it affects a specific payment device. That requires detailed knowledge of the device’s software, firmware, and hardware configuration, which many PSPs do not have.
At the same time, AI is lowering the barrier to entry for cybercriminals. This is particularly significant for payment providers, which remain an attractive target for AI-enabled attacks. In 2025, payment systems accounted for 33 percent of all AI-driven incidents, driven by their proximity to sensitive data, money movement, and wider payment ecosystems.
AI enables attackers to analyse systems, identify weaknesses and scale attacks more efficiently. Once a vulnerability is discovered, attackers can rapidly chain together multiple weaknesses across the technology stack, reducing the amount of time organisations have to detect and respond to potential threats.
This means the gap between a vulnerability emerging and it being exploited is continuing to shrink. For PSPs that rely primarily on periodic assessments, the risk is that threats evolve faster than their ability to identify them.
Continuous monitoring closes the assurance gap
Fortunately, AI is not only benefiting attackers. It is also giving PSPs new tools to address the limitations of traditional security models.
To move beyond point-in-time assurance, organisations need a more complete and continuously updated understanding of the devices they operate. This requires identifying hidden dependencies, mapping component versions, and understanding how different elements interact in practice.
AI can support this process by analysing code and firmware, rebuilding incomplete SBOMs, identifying inconsistencies and highlighting areas where vulnerabilities may still exist despite appearing resolved. When combined with real-time threat intelligence, it allows organisations to assess emerging vulnerabilities continuously rather than waiting for scheduled reviews.
Continuous monitoring means tracking new vulnerabilities as they emerge and assessing whether they affect devices currently in operation. However, it usually requires the processing of large amount of data, struggling with vulnerability applicability analysis, and identification of real threats.
AI is playing a significant role in this process. The knowledge of the device composition, attack surface, and TTPs can be used by AI is to automate the initial analysis phase, which gives the threat intelligence analysts with curated and tailored list of most risky and potentially applicable signals. By combining AI-enabled device visibility with AI-enabled vulnerability intelligence, PSPs can identify weaknesses in open-source libraries, firmware, and communications components before they become significant security issues.
Rather than providing periodic snapshots of risk, this approach creates an ongoing view of device security that reflects the reality of a constantly changing threat landscape.
Moving from compliance to continuous assurance
PSPs can no longer rely on periodic checks to understand device risk. They need continuous visibility into what is inside their payment devices, how new vulnerabilities affect them and where action is needed before exposure becomes compromised.
Point-in-time validation is no longer enough. Continuous assurance must become part of every stage of payment device security.


