An SSL padlock icon in a browser bar tells a player almost nothing about how an operator actually protects their data. Our algorithm treats the padlock as a starting point, not a conclusion: it runs automated TLS configuration scans, checks certificate hygiene, and cross-references each operator’s public security posture against the encryption baselines set by regulators such as the UK Gambling Commission and the Malta Gaming Authority, plus the payment-industry floor set by PCI DSS. Most licensed casinos clear the minimum bar. Meaningful differences show up in cipher suite quality, protocol support, and certificate management discipline — the details a marketing page never mentions.
Key takeaways
- PCI DSS v4.0.1 now mandates TLS 1.2 or higher for any transmission of cardholder data, with TLS 1.0, TLS 1.1 and all SSL versions explicitly banned since 2015.
- UK-licensed operators must submit an annual third-party security audit against sections of ISO/IEC 27001:2022, and MGA-licensed operators face an equivalent ISO 27001 and PCI DSS Level 1 expectation for hosting infrastructure.
- Modern SSL Labs-style grading now caps servers without TLS 1.3 support at an “A-“, reflecting how fast the encryption baseline is moving.
- Gambling and casino platforms rank among the most frequently targeted sectors for large-scale DDoS attacks, making uptime resilience part of the same security picture as encryption.
- Encryption failures are not theoretical: 2025-2026 saw data breaches at major operators affecting hundreds of thousands of customer records.
Table of contents
The regulatory baseline behind “secure”
Encryption requirements for online casinos are not a matter of operator discretion; they are licence conditions. Under the UK Gambling Commission’s Remote Gambling and Software Technical Standards,
the Commission sets out a summary of the RTS security requirements that licence holders must meet, based on the relevant sections of Annex A to the ISO/IEC 27001:2022 standard
, which
replaced ISO/IEC 27001:2013
. Licensees don’t self-certify:
under section 4 of the RTS, remote gambling operators must complete a third-party annual security audit against specific sections of the ISO 27001 standard and submit an audit report to the Commission
. New licensees don’t get a grace period either —
newly licensed remote gambling operators must also submit a security audit within six months of being granted a licence, irrespective of whether they are trading
.
Malta runs a parallel but distinct framework.
The MGA seeks the information security of ISO/IEC 27001:2013, and Cloud Service Providers are to be guided by ISO/IEC 27002:2013 for Information Security Management in implementing the Information Security Management System
. On top of that,
the MGA shall seek PCI DSS Level 1 certification
for the payment side of operations. Both regulators converge on the same underlying logic: encryption isn’t a checkbox, it’s an ongoing, independently verified control.
Payment processing overlays a third layer.
As of 2026, PCI DSS version 4.0.1 stands as the definitive global benchmark for securing cardholder data — a strict contractual mandate enforced by major card brands like Visa and Mastercard
, not just a suggestion for IT teams. This is the framework our algorithm checks first, because it is the most technically specific and the easiest to verify from the outside without operator cooperation. For the licensing angle specifically, see our Licensing & Jurisdictions hub.
What “SSL” actually means in 2026
“SSL” is industry shorthand that has outlived the protocol itself. Every SSL version and the first two TLS versions are now considered insecure for payment-adjacent traffic.
TLS 1.0 and 1.1 are explicitly prohibited, and SSL in all versions has been banned since PCI DSS 3.1 in 2015
. The current floor is TLS 1.2:
PCI DSS requirement 4.2.1 mandates strong cryptography for cardholder data in transit, with TLS 1.2 as the minimum acceptable version, and TLS 1.0 and TLS 1.1 are not considered strong cryptography under PCI DSS
.
Two administrative requirements now sit alongside the technical minimum.
4.2.1.1 wants an inventory of keys and certificates, and 12.3.3 wants the cipher suites and protocols documented and reviewed at least once every 12 months — both became mandatory on 31 March 2025
. In practice this means a compliant operator should be able to produce, on demand, a current list of every certificate in production and the cipher suites each one negotiates. Most can’t, on the first attempt.
How our algorithm audits encryption automatically
Rather than manually inspecting individual certificates, our algorithm runs scheduled, programmatic scans against every operator’s public-facing endpoints — the login page, the cashier, and the account/KYC upload forms, since these carry the most sensitive traffic. This mirrors the model pioneered by Qualys SSL Labs, whose
SSL Labs APIs expose the complete SSL/TLS server testing functionality in a programmatic fashion, allowing for scheduled and bulk assessment, so that site operators can regularly test their server configuration
. The same open tooling underpins independent audits across the industry:
ssllabs-scan is an open source command-line scanning tool that Qualys SSL Labs provides for free to conduct automated and bulk testing
.
Each scan checks four layers: protocol support (is TLS 1.3 offered, is TLS 1.0/1.1 disabled), cipher suite strength, certificate chain validity and expiry, and transport-layer hardening signals such as HSTS. This data feeds directly into the weighting logic described on our Scoring System & Algorithmic Weights hub, and it is generated by the same scraping infrastructure covered in Data Scraping & The Technical Engine. It’s a different signal from game fairness — for how we detect manipulation on the RNG side rather than the transport-security side, see Spotting Rigged RNGs: How Machine Learning Detects Statistical Anomalies.
Reading the grade: what separates an A from a C
Letter grades give a fast way to compare configurations without requiring the reader to parse raw cipher lists.
SSL Labs first launched in 2009 to provide comprehensive diagnostics of SSL/TLS and PKI configuration issues, and the project also provided a way to measure and compare configuration quality, chiefly using A-F letter grades — an approach that proved very popular and helped many organizations improve their security posture
. The grading logic has tightened considerably since then. As of the most recent revision,
TLS 1.3 is now given higher weight in the grading system; a server that does not support it receives a warning and is capped at a minimum grade of A-, because TLS 1.3 is now considered a 100% protocol strength
. HSTS matters too:
if HTTP Strict Transport Security is disabled or invalid, the grade drops from an A to an A-
.
The middle and lower grades describe real operational gaps, not cosmetic ones.
A B grade means adequate security with modern clients but older and potentially obsolete crypto used with older clients — potentially smaller configuration problems — while a C grade means an obsolete configuration that uses obsolete crypto with modern clients, a potentially bigger configuration problem
. Exceptional configurations exist too:
a flag is raised when an exceptional configuration is encountered, and the test will give such sites an A+
.
| Signal | Compliant baseline | Common failure our scans flag |
|---|---|---|
| Minimum protocol | TLS 1.2 or higher | TLS 1.0/1.1 still enabled for legacy client support |
| Preferred protocol | TLS 1.3 supported | TLS 1.3 absent, capping the grade near A- |
| HSTS | Enabled and valid | Missing or misconfigured, dropping A to A- |
| Certificate inventory | Documented and reviewed every 12 months | Unlisted wildcard certificates, forgotten load-balancer endpoints |
| Cipher suites | Forward-secrecy-capable, no legacy 64-bit block ciphers | Legacy CBC ciphers with TLS 1.2, triggering vulnerability-specific downgrades |
Beyond the padlock: data at rest and PCI scope
Transport encryption only protects data in motion. Regulators are explicit that storage matters just as much.
Information security requirements cover player personal data, financial data and game data, and include encryption in transit and at rest, access controls, network segregation, and penetration testing
, all of which
overlap with GDPR and PCI DSS requirements, but the gambling commission’s expectations are specific to gambling operations and tested independently
.
On the payments side specifically,
Requirement 3 focuses on protecting stored account data, and since March 31, 2025, merchants can’t rely solely on disk-level encryption for non-removable media — they must use strong cryptography or truncation to ensure Primary Account Numbers are unreadable
. This is a meaningfully higher bar than “the database is encrypted,” and it’s one our algorithm cannot verify directly from outside the operator’s infrastructure — which is exactly why we treat the presence or absence of a current PCI DSS attestation, disclosed licensing status, and ISO 27001 certification as scored inputs rather than assumptions. For more on how licensing status and jurisdiction feed into the overall trust picture, see Licensing & Jurisdictions, and for the broader argument against taking marketing claims at face value, see Our Core Principles & The Problem with “Human” Reviews.
Availability is a security metric too
Encryption quality is only half the security equation; an operator with a perfect TLS configuration but frequent downtime still fails players who can’t withdraw funds when they need to. Gambling platforms are disproportionately targeted for exactly this kind of disruption.
Cloudflare’s Q4 2025 ranking put telecommunications, IT, gambling, and gaming at the top of its most-attacked-industry list
, and in its broader annual data,
the Cloudflare 2025 Q4 DDoS Threat Report counted 47.1 million DDoS attacks mitigated across its network, up 121% year over year, and confirmed a record 31.4 terabits-per-second attack that lasted 35 seconds
. Separately,
Gambling and Casinos came in third and Gaming fourth among most-attacked sectors, with Computer Software and Business Services also climbing several spots quarter over quarter
.
Our algorithm logs uptime and response-time anomalies alongside encryption data because the two failure modes often share a root cause: under-provisioned or poorly segmented infrastructure. An operator whose certificate management is sloppy is statistically more likely to have skipped other basic hardening steps as well.
What happens when encryption fails
The consequences of weak data protection in this sector are not hypothetical.
In July 2025, Flutter Entertainment — the parent company of Paddy Power, Betfair, Sky Betting & Gaming, PokerStars and other brands — confirmed that it had suffered a data breach affecting 800,000 customers
. Less than a year later,
in February 2026, casino operator Wynn Resorts confirmed a cyberattack from the hacking group ShinyHunters, which claimed to have stolen over 800,000 records including employee data and personally identifiable information
. Both incidents involved companies with substantial compliance resources, which underscores that certification alone does not guarantee resilience — it establishes a floor, not a ceiling.
Regulatory penalties for these failures have also become more severe. Across UK data protection enforcement generally,
the average fine jumped from £150,000 to over £2.8 million as the ICO shifted from issuing regular small penalties to targeting serious data breaches with much heavier financial consequences
. Under GDPR’s structural ceiling,
organisations found in violation may face fines of up to €20 million or 4% of global annual revenue, whichever is higher
. For an operator processing millions in player deposits, that ceiling is not abstract.
Frequently asked questions
Does a valid SSL certificate mean a casino is safe to deposit at?
No. A valid certificate confirms the connection is encrypted and the domain identity is verified, but it says nothing about protocol version, cipher strength, certificate management discipline, or how data is protected once it reaches the operator’s servers. Our algorithm checks all of these separately rather than treating “has HTTPS” as a pass condition.
Why do regulators require annual security audits instead of one-time certification?
All licensed remote gambling operators and gambling software operators must comply with specific licensing requirements, including technical standards, and provide annual security audit reports
. Threats, cipher vulnerabilities, and best practices change constantly, so a single point-in-time certificate would go stale within months.
Can our algorithm see an operator’s internal encryption at rest?
No. External automated scanning can only observe what is exposed at the network edge: TLS configuration, certificate chains, and response behavior. Data-at-rest encryption, key management, and internal segmentation are verified through disclosed certifications like ISO 27001 and PCI DSS attestations rather than direct inspection.
Is TLS 1.2 still acceptable in 2026?
PCI DSS requirement 4.2.1 mandates strong cryptography for cardholder data in transit, with TLS 1.2 as the minimum acceptable version
, so it remains technically compliant. However, modern grading frameworks increasingly treat TLS 1.3-only configurations as the stronger benchmark, capping non-TLS-1.3 servers below the top grade.
Methodology
For this category, GamblScout’s algorithm runs scheduled automated scans of each operator’s public login, cashier, and account-verification endpoints, capturing TLS protocol support, cipher suite composition, certificate validity and chain integrity, and HSTS status. These technical signals are combined with disclosed regulatory data — licence status, ISO 27001 certification claims, and PCI DSS attestation level — sourced from regulator registers and operator disclosures rather than self-reported marketing pages, then weighted alongside uptime and incident-history data before contributing to an operator’s overall security score.
Gambling involves risk. Only play with money you can afford to lose and use the deposit limits and self-exclusion tools available in your jurisdiction.
