Framework · Last verified
P2PE Standard
P2PE is a PCI SSC standard for point-to-point encrypted payment solutions, validated by independent P2PE Assessors — PCI SSC itself does not mandate it. PCI SSC states that compliance programs for all its standards, including P2PE, are managed by the payment brands, not by PCI SSC itself.
- Class
- Framework
- Owner
- PCI Security Standards Council (PCI SSC)
- Public register
- Not confirmed at our last check
- Last verified
What it is
PCI SSC describes the standard's purpose directly: "The security requirements and test procedures for P2PE Solutions, P2PE Components, and P2PE Applications are intended to protect payment account data via encryption from the point it is captured in the merchant's payment device to the point it is decrypted in a solution or component provider's environment."
The current version is P2PE Standard v3.2, last updated 2025-06-30 per PCI SSC's own document-library data; the prior version, v3.1 (last updated 2021-09-30), remains in effect in parallel — no earlier version was found archived.
PCI SSC itself does not mandate the standard: "Compliance programs for all PCI SSC standards are managed by the payment brands. Questions about which entities need to validate compliance to any PCI SSC standard, or whether use of a PCI-listed product is required and for which entities, should be referred to the payment brands."
PCI SSC "encourages merchants, acquirers, and solution providers to use the PCI SSC listings in selecting P2PE Solutions, P2PE Components, and P2PE Applications."
Who owns it
The standard is owned and published by the PCI Security Standards Council (PCI SSC).
Who assesses it
Independent assessments are performed by two named roles distinct from the QSA program used for PCI DSS: the "Point-to-Point Encryption Assessor (P2PE Assessor)" and the "Point-to-Point Encryption Application Assessor (P2PE Application Assessor)". PCI SSC's own P2PE page does not use the term "QSA (P2PE)" for either role.
Who asks for it
Voluntary. PCI SSC's own page states: "Compliance programs for all PCI SSC standards are managed by the payment brands. Questions about which entities need to validate compliance to any PCI SSC standard, or whether use of a PCI-listed product is required and for which entities, should be referred to the payment brands." PCI SSC itself imposes no mandate for P2PE; a payment brand or acquirer may require it contractually — the specific contractual clauses have not been opened and verified in this record (open question, see below).
PCI SSC's own standards pages put the decision to require validation with the payment brands: "Compliance programs for all PCI SSC standards are managed by the payment brands. Questions about which entities need to validate compliance to any PCI SSC standard, or whether use of a PCI-listed product is required and for which entities, should be referred to the payment brands." PCI SSC itself names no universal requirement.
Sources
- PCI Security Standards Council — P2PE Standard page (scheme owner) ↗ — accessed
- PCI SSC — P2PE Solutions listing (click-through disclaimer gate; list content not verified this round) ↗ — accessed
- PCI SSC official document-library endpoint — confirms P2PE Standard v3.2 (last updated 2025-06-30) is the current non-archived version (v3.1, last updated 2021-09-30, also in effect in parallel) ↗ — accessed
Last verified:
This page is for information only; it does not accredit, certify or endorse any organisation. Requirements and programs change — always confirm against the primary source linked above.