Frequently Asked Question
Does PCI P2PE allow for partial assessments of third parties with services that will be used in one or more P2PE solutions?
All third parties providing services to P2PE solution providers must be assessed against the P2PE standard. As stated in the PCI P2PE standard: There are two options for third-party entities performing functions on behalf of solution providers to validate compliance:
- Undergo a P2PE assessment of relevant P2PE requirements on their own and submit the applicable P2PE Report of Validation (P-ROV) to PCI SSC for review and acceptance. Upon acceptance, the P2PE component is listed on PCI SSCs list of Validated P2PE Components.
- Have their services reviewed during the course of each of their solution-provider customers P2PE assessments.