Frequently Asked Question

Does PCI P2PE allow for partial assessments of third parties with services that will be used in one or more P2PE solutions?
No. PCI P2PE allows for P2PE component providers to formalize the process of assessing third parties. Therefore, it is not allowable to perform partial P2PE assessments and reuse (for example, via a partial P-ROV) those partial assessments for either P2PE component provider and/or solution provider assessments.
All third parties providing services to P2PE solution providers must be assessed against the P2PE standard. As stated in the PCI P2PE standard: There are two options for third-party entities performing functions on behalf of solution providers to validate compliance:
- Undergo a P2PE assessment of relevant P2PE requirements on their own and submit the applicable P2PE Report of Validation (P-ROV) to PCI SSC for review and acceptance. Upon acceptance, the P2PE component is listed on PCI SSCs list of Validated P2PE Components.
Or:
- Have their services reviewed during the course of each of their solution-provider customers P2PE assessments.
May 2020
Article Number: 1369
Related
-
How should payment terminals be considered during a PCI DSS assessment?
-
Are P2PE Products (P2PE Solutions, P2PE Components, P2PE Applications) on the P2PE Expired Listings still considered “validated” per the P2PE Program Guide?
-
If a P2PE Solution is on PCI’s list of Point-to-Point Encryption Solutions with Expired Validations, does the solution meet the eligibility criteria for SAQ P2PE?
Featured FAQ Articles
Most Recently Updated
-
Is the expectation that any PFI investigation initiated must result in a PFI Final Report?
-
Can SAQ eligibility criteria be used for determining applicability of PCI DSS requirements for assessments documented in a Report on Compliance?
-
Do PCI DSS requirements for keyed cryptographic hashing apply to previously hashed PANs?