Frequently Asked Question

What effect does the use of a PCI-listed P2PE solution have on a merchant’s PCI DSS validation?
A PCI-listed P2PE solution can significantly help to reduce the PCI DSS validation effort of a merchant’s cardholder data environment. However, it does not completely remove the need for PCI DSS validation in the merchant environment. See Who can use SAQ P2PE? for additional information.
June 2016
Article Number: 1158
Related
-
How should payment terminals be considered during a PCI DSS assessment?
-
Are P2PE Products (P2PE Solutions, P2PE Components, P2PE Applications) on the P2PE Expired Listings still considered “validated” per the P2PE Program Guide?
-
If a P2PE Solution is on PCI’s list of Point-to-Point Encryption Solutions with Expired Validations, does the solution meet the eligibility criteria for SAQ P2PE?
Featured FAQ Articles
Most Recently Updated
-
Is the expectation that any PFI investigation initiated must result in a PFI Final Report?
-
Can SAQ eligibility criteria be used for determining applicability of PCI DSS requirements for assessments documented in a Report on Compliance?
-
Do PCI DSS requirements for keyed cryptographic hashing apply to previously hashed PANs?