Framework · Last verified

P2PE Standard

P2PE is a PCI SSC standard for point-to-point encrypted payment solutions, validated by independent P2PE Assessors — PCI SSC itself does not mandate it. PCI SSC states that compliance programs for all its standards, including P2PE, are managed by the payment brands, not by PCI SSC itself.

Class
Framework
Owner
PCI Security Standards Council (PCI SSC)
Public register
Not confirmed at our last check
Last verified

What it is

PCI SSC describes the standard's purpose directly: "The security requirements and test procedures for P2PE Solutions, P2PE Components, and P2PE Applications are intended to protect payment account data via encryption from the point it is captured in the merchant's payment device to the point it is decrypted in a solution or component provider's environment."

The current version is P2PE Standard v3.2, last updated 2025-06-30 per PCI SSC's own document-library data; the prior version, v3.1 (last updated 2021-09-30), remains in effect in parallel — no earlier version was found archived.

PCI SSC itself does not mandate the standard: "Compliance programs for all PCI SSC standards are managed by the payment brands. Questions about which entities need to validate compliance to any PCI SSC standard, or whether use of a PCI-listed product is required and for which entities, should be referred to the payment brands."

PCI SSC "encourages merchants, acquirers, and solution providers to use the PCI SSC listings in selecting P2PE Solutions, P2PE Components, and P2PE Applications."

Who owns it

The standard is owned and published by the PCI Security Standards Council (PCI SSC).

Who assesses it

Independent assessments are performed by two named roles distinct from the QSA program used for PCI DSS: the "Point-to-Point Encryption Assessor (P2PE Assessor)" and the "Point-to-Point Encryption Application Assessor (P2PE Application Assessor)". PCI SSC's own P2PE page does not use the term "QSA (P2PE)" for either role.

Who asks for it

Voluntary. PCI SSC's own page states: "Compliance programs for all PCI SSC standards are managed by the payment brands. Questions about which entities need to validate compliance to any PCI SSC standard, or whether use of a PCI-listed product is required and for which entities, should be referred to the payment brands." PCI SSC itself imposes no mandate for P2PE; a payment brand or acquirer may require it contractually — the specific contractual clauses have not been opened and verified in this record (open question, see below).

PCI SSC's own standards pages put the decision to require validation with the payment brands: "Compliance programs for all PCI SSC standards are managed by the payment brands. Questions about which entities need to validate compliance to any PCI SSC standard, or whether use of a PCI-listed product is required and for which entities, should be referred to the payment brands." PCI SSC itself names no universal requirement.

Sources

Last verified:

This page is for information only; it does not accredit, certify or endorse any organisation. Requirements and programs change — always confirm against the primary source linked above.

Cite this page

Attributing this record helps other researchers verify it independently.

"P2PE Standard." Certifidex, FutureTechnologies. Last verified 31 August 2026. https://certifidex.com/frameworks/pci-p2pe

All frameworks & audits →