When looking to deploy Point-of-Interaction (POI) payment systems, Point-to-Point Encryption (P2PE) validated solutions are the gold standard.
They have been through rigorous testing by qualified assessors and help merchants reduce the number of controls on their environment for their PCI assessment.
Unfortunately, payment solution sales representatives and account managers are misusing the term of P2PE and leading merchants to believe their solution has this kind of encryption.
Many times, our QSAs start to assess a merchant’s environment and, while validating their POI payment solution, discover that it is actually not P2PE and instead an End-to-End Encryption (E2EE) solution with inconsistent or no scope reduction available to the end merchant.
Below, we’ll demonstrate, as a merchant, how to engage with these vendors to validate P2PE solutions to save you hours of headache in the future. We can help prepare you to gain better assurances that the solution you are entertaining is in fact what you need instead of simply taking the vendor's word for it.
That’s it! Taking a few minutes to conduct this verification of your POI vendors when doing your vendor due diligence will help avoid any surprises on your next PCI audit.
If you have any questions that pop up during this verification process, always ask your QSA and get them in the loop to catch any inconsistencies while they can still be fixed or adjusted easily.
If you have any questions about PCI or whether your solution is P2PE, please don’t hesitate to contact us to speak with one of our QSAs.