PCI P2PE
Validate your P2PE solution, application or component against PCI P2PE v3.2, and give the merchants who use it a shorter route through PCI DSS.
0
0 +
0 +
What is PCI P2PE?
PCI Point-to-Point Encryption (P2PE) is a security standard for protecting payment account data by encrypting it from the point where a payment card is accepted through to a secure decryption environment. Between those two points the data stays unreadable, so a compromise of the systems or networks in between yields nothing usable.
The standard sets security requirements and testing procedures for P2PE solutions, components and applications, covering encryption, decryption, key management, device management and application security.
How does P2PE reduce PCI DSS scope?
When cardholder data is encrypted at the point of interaction and only decrypted inside a secure environment the merchant doesn't control, clear-text account data is removed from the merchant's systems. Fewer systems handle payment data, so fewer PCI DSS requirements apply.
Merchants using a PCI-listed P2PE solution may also be eligible to validate using SAQ P2PE, which covers substantially fewer requirements than the other self-assessment questionnaires. Eligibility depends on how the solution is deployed and on the requirements of the merchant's acquiring bank.
Who the PCI P2PE Standard applies to
-
P2PE Solution Providers
-
P2PE Application Vendors
-
Encryption Management Component Providers (EMCP)
-
Decryption Management Component Providers (DMCP)
-
Key Injection Facilities (KIF)
-
Certification Authorities and Registration Authorities (CA/RA)
PCI P2PE compliance in two steps
P2PE Preliminary Gap Assessment Review (GAR)
Before committing to a formal assessment, the GAR benchmarks your solution, components or application against the standard's requirements. You get a clear picture of where you stand and what needs addressing, with the effort quantified before you commit to the formal process.
P2PE Formal Assessment of Compliance (FAC)
The FAC applies to organizations managing P2PE solutions for their customers, merchants managing their own P2PE implementations, and P2PE component providers. It provides the independent validation required for a solution to be listed by the PCI Security Standards Council.
Speak to an expert
Whether you're preparing a solution for listing or reviewing where your current implementation stands, the starting point depends on how far along you are. Talk to an advisor about the right first step.
Dublin: +353 01 293 4027
London: +44 20 3397 3414
Sofia: +359 2 491 0110
Cape Town: +27 08 606 25673
Johannesburg: +27 08 606 25673
