When looking to deploy Point-of-Interaction (POI) payment systems, Point-to-Point Encryption (P2PE) validated solutions are the gold standard.
They have been through rigorous testing by qualified assessors and help merchants reduce the number of controls on their environment for their PCI assessment.
Unfortunately, payment solution sales representatives and account managers are misusing the term of P2PE and leading merchants to believe their solution has this kind of encryption.
Many times, our QSAs start to assess a merchant’s environment and, while validating their POI payment solution, discover that it is actually not P2PE and instead an End-to-End Encryption (E2EE) solution with inconsistent or no scope reduction available to the end merchant.
Below, we’ll demonstrate, as a merchant, how to engage with these vendors to validate P2PE solutions to save you hours of headache in the future. We can help prepare you to gain better assurances that the solution you are entertaining is in fact what you need instead of simply taking the vendor's word for it.
2 Quick Steps to Ensure Point-to-Point Encryption
- Request and gather the following information and documents from the vendor:
- P2PE solution name
- POI Device Make and Model for the P2PE solution to be injected onto
- P2PE Instruction Manual (PIM)
- Note: If the vendor is unable to provide this information to you, that is a good indication that they are not a true Point-to-Point Encryption solution and you should proceed with caution.
- After you have gathered the above information and documents from the vendor, perform the following actions on the PCI SSC website:
- When on the Home page of the website, click on the "Products & Solutions Listing" dropdown from the main navigation menu. Select "Point-to-Point Encryption Solutions.”
- Once there, search the name of the P2PE solution that the vendor has provided and ensure that it is listed on the PCI SSC website, is valid, and has no additional warnings.
- Once the solution is found, select "Solutions Details" for the listed solution and ensure that the POI Device Make and Model is listed under the "PCI-Approved POI Devices Supported" section.
That’s it! Taking a few minutes to conduct this verification of your POI vendors when doing your vendor due diligence will help avoid any surprises on your next PCI audit.
If you have any questions that pop up during this verification process, always ask your QSA and get them in the loop to catch any inconsistencies while they can still be fixed or adjusted easily.
If you have any questions about PCI or whether your solution is P2PE, please don’t hesitate to contact us to speak with one of our QSAs.
Like our content? Subscribe and stay informed.
Related posts
Tags
- Access Control (3)
- Amazon (1)
- Artificial Intelligence (3)
- Assessment (1)
- Attack Surface (2)
- Attack Surface Management (3)
- Attestation (1)
- Audit (1)
- Awareness Week (3)
- AWS (2)
- Backup And Recovery (1)
- BCAW (4)
- BCMS (1)
- Blackbasta (1)
- Business (16)
- Business Continuity (6)
- Business Continuity Planning (2)
- Caas (1)
- Certification (1)
- Christian Hyatt (19)
- CI (1)
- CISO (8)
- CISO Discussions (24)
- Cloud (1)
- CMMC (1)
- Competitive (1)
- Compliance (17)
- Compliance As A Service (5)
- COVID (1)
- Cyber Risk (6)
- Cyber Risk Management (59)
- Cyber Security Law (2)
- Cybersecurity (26)
- Cybersecurity Controls (4)
- Disaster Recovery (5)
- Engineers (1)
- Ethical Hacking (1)
- EU AI Act (3)
- Exercises (1)
- GDPR (4)
- GRC Tool (6)
- Grit (1)
- Hacking (3)
- Hashcat (1)
- HITRUST (16)
- IaaS (1)
- Information Security (11)
- Internal Audit (2)
- ISO (3)
- ISO 22301 (1)
- ISO 27001 (18)
- ISO 27001 Compliance (19)
- ISO 27018 (1)
- ISO 27701 (2)
- ISO 42001 (6)
- ISO 42005 (1)
- IT Audit (9)
- IT Audit And Compliance (33)
- Kahoot (1)
- Leadership (6)
- Management (1)
- Network Security (4)
- News (5)
- News And Events (20)
- NIST 800 Series (2)
- NIST 800-171 (1)
- OSINT (1)
- Outsourced Pci (1)
- P2pe (1)
- Passwords (3)
- PCI DSS (13)
- Penetration Test (7)
- Penetration Testing (31)
- Pentest Report (1)
- Phishing (1)
- PIA (1)
- Press Release (3)
- Privacy (8)
- Privacy Compliance (7)
- Privacy Impact Assessment (1)
- Privacy Shield (1)
- Ransomeware (1)
- Regulatory Compliance (12)
- Report (2)
- Risk Assessment (5)
- Risk Management (19)
- SDLC (2)
- Security (22)
- Security Advisory (1)
- SOC 2 (18)
- SOC Reporting (23)
- Soc2 (1)
- Strategy (1)
- System Backdoor (1)
- Tabletop (1)
- Training (5)
- VCISO (7)
- Vendor Management (2)
- Vulnerability Management (2)
- Vulnerability Scan (1)
- Wannacry (1)
- Webinars (9)