PCI P2PE
Protect payment card data from the point of interaction to secure decryption.
Integrity360 provides PCI Point-to-Point Encryption (P2PE) assessment and advisory services to help solution providers, component providers and application developers meet the requirements of the PCI P2PE Standard.
Our PCI specialists support organisations from initial gap assessment through to formal assessment, helping protect payment account data and simplify PCI compliance.
0
0 +
0 +
What Is PCI P2PE?
PCI Point-to-Point Encryption (P2PE) is a security standard designed to protect payment account data by encrypting it from the point where a payment card is accepted through to a secure decryption environment.
When properly implemented, cardholder data remains unreadable between these points, reducing the opportunity for attackers to obtain usable payment information if systems or networks are compromised.
PCI-listed P2PE solutions can also reduce the number of PCI DSS requirements applicable to merchants, helping simplify compliance.
P2PE and Integrity360
Integrity360 supports organisations assessing against PCI P2PE v3.1, the current version of the PCI Point-to-Point Encryption Standard.
The standard defines security requirements and testing procedures for P2PE solutions, components and applications, covering areas such as encryption, decryption, key management, device management and application security.
P2PE applies to:
-
P2PE Solution Providers
-
P2PE Application Vendors
-
Encryption Management Component Provider (EMCP)
-
Decryption Management Component Provider (DMCP)
-
Key Injection Facility (KIF)
-
Certification Authority/Registration Authority (CA/RA)
Speak to an expert
London: +44 20 3397 3414
Sofia: +359 2 491 0110
Cape Town: +27 08 606 25673
Johannesburg: +27 08 606 25673
PCI SSC level P2PE Compliance in 2 steps
P2PE Preliminary Gap Assessment Review (GAR)
P2PE GAR provides a benchmarking against industry requirements to analyse your solution, components, or application. This review process allows an organisation to review its compliance position before committing to the formal P2PE compliance assessment.
P2PE Formal Assessment of Compliance (FAC)
P2PE Formal assessment of compliance (FAC) applies to entities that manage P2PE Solutions for their customers, Merchants that manage their P2PE solutions, and P2PE Component Providers.
