PCI P2PE (point-to-point encryption) requires credit card information to be encrypted instantly upon its initial swipe/insert at the payment terminal and securely transferred directly to the payment processor before it can be decrypted and processed. A P2PE solution includes validated hardware, software and solution-provider environment and processes, and may include validated services from a component provider. Validation is performed by a PCI-qualified P2PE assessor.
P2PE applies to: P2PE Solution Providers; Terminal Payment Application Vendors; Encryption Management Component Providers; Decryption Management Component Providers; Key Injection Facilities; and Certification/Registration Authorities involved in remote key-injection processes.
P2PE is a three-year program — each year the vendor is required to confirm its status to PCI SSC.
Kickoff and Planning. Define the certification process, points of contact, timelines and roadmap.
Preparation Phase. Tailored support: P2PE training/workshop; P2PE scoping; Pre-Assessment or full Gap Assessment; remediation/advisory support.
Formal validation. The accredited auditor assesses all domains and controls of P2PE — POI device review, device management, encryption/decryption environment, third-party applications, inventory management, key management, PCI DSS compliance, cardholder data flows and solution documentation. Our auditor checks: encryption device management; application security; encryption environment; segmentation between encryption and decryption environments; decryption environment and device management; P2PE cryptographic key operations; and the P2PE Instruction Manual.
Reporting. Delivered within 3 weeks; the report is sent to the PCI Council for review, after which a certificate is issued and the company is listed on the PCI website as a P2PE validated solution.
Deliverables: P2PE Solution / Application / Components RoV (Report of Validation) and corresponding AoC (Attestation of Validation).
Continual Support after certification.