einvoice / EN 16931 / XRechnung rule reference
BR-51
The last 4 to 6 digits of the Payment card primary account number (BT-87) shall be present if Payment card information (BG-18) is provided.
Gemäß den Sicherheitsstandards für Kartenzahlungen darf eine Rechnung niemals eine vollständige Kartennummer (primäre Kontonummer der Zahlungskarte) (BT-87) enthalten. Derzeit hat das PCI Security Standards Council festgelegt, dass höchstens die ersten 6 und die letzten 4 Ziffern angezeigt werden dürfen.
Deutsche Fassung: Übersetzung der gleichen BT/BG-Semantik (translation — not the official assert).
- Requires
- In accordance with card payments security standards an invoice should never include a full card primary account number (BT-87). At the moment PCI Security Standards Council has defined that the first 6 digits and last 4 digits are the maximum number of digits to be shown.
- Business terms
BG-18BT-87- Syntax
- Binds the UBL-2.1 Invoice / CreditNote syntax and the UN/CEFACT-CII syntax
- Location (UBL-2.1 path)
cac:PaymentMeans/cac:CardAccount/cbc:PrimaryAccountNumberID- Fix
- Correct `cac:PaymentMeans/cac:CardAccount/cbc:PrimaryAccountNumberID` so that In accordance with card payments security standards an invoice should never include a full card primary account number (BT-87). At the moment PCI Security Standards Council has defined that the first 6 digits and last 4 digits are the maximum number of digits to be shown.
- Fix (Deutsch)
- Korrigieren Sie `cac:PaymentMeans/cac:CardAccount/cbc:PrimaryAccountNumberID`, sodass gilt: Gemäß den Sicherheitsstandards für Kartenzahlungen darf eine Rechnung niemals eine vollständige Kartennummer (primäre Kontonummer der Zahlungskarte) (BT-87) enthalten. Derzeit hat das PCI Security Standards Council festgelegt, dass höchstens die ersten 6 und die letzten 4 Ziffern angezeigt werden dürfen.
- Severity
- warning
- Provenance source
en16931-ubl- Provenance assert
In accordance with card payments security standards an invoice should never include a full card primary account number (BT-87). At the moment PCI Security Standards Council has defined that the first 6 digits and last 4 digits are the maximum number of digits to be shown.
The Location above is a UBL-2.1 path, and no UN/CEFACT-CII path for this rule is published here; Fix and Fix (Deutsch), verbatim from remediation_catalog.json and not reworded here; the UN/CEFACT-CII binding of this rule is differentially proven against the official CEN EN 16931 1.3.16 Schematron.
Everything here is free and open source — pick up whatever helps, at your own pace:
- Licensing — Apache-2.0 for everyone, including closed-source embedding; an optional $29 / $290 commercial license adds support and rule-corpus update notices.
- German remediation (
--lang de) — the German fix for this rule is in the section above; the CLI surfaces it in place of the English message with--lang de. - Quickstart / free on-ramp — the README, a copy-paste CI-gate recipe, and a 5-minute worked walkthrough.