Frequently Asked Question

Are P2PE solution providers required to have their solutions validated and listed by the Council?
No.
Please reference FAQ 1158 What effect does the use of a PCI-listed P2PE solution have on a merchant’s PCI DSS validation? and Can merchants use encryption solutions not listed on the PCI Council’s website to reduce their PCI DSS validation effort? for additional information.
Please reference FAQ 1158 What effect does the use of a PCI-listed P2PE solution have on a merchant’s PCI DSS validation? and Can merchants use encryption solutions not listed on the PCI Council’s website to reduce their PCI DSS validation effort? for additional information.
June 2016
Article Number: 1165
Related
-
How should payment terminals be considered during a PCI DSS assessment?
-
Are P2PE Products (P2PE Solutions, P2PE Components, P2PE Applications) on the P2PE Expired Listings still considered “validated” per the P2PE Program Guide?
-
If a P2PE Solution is on PCI’s list of Point-to-Point Encryption Solutions with Expired Validations, does the solution meet the eligibility criteria for SAQ P2PE?