SAQ P2PE

PCIComplianceHubLast updated

The Self-Assessment Questionnaire for merchants using only hardware payment terminals that form part of a PCI SSC listed Point-to-Point Encryption solution, with no account data stored electronically. It is the shortest of all the questionnaires, because a validated P2PE solution removes most of the cardholder data environment from scope. The solution must appear on the council listing; encryption alone, however strong, does not qualify.

Applies to. Merchants using only a validated, PCI-listed point-to-point encryption solution, with no access to clear-text account data and no electronic storage. Card-present and mail and telephone order only.
Limits. The solution must be on the Council's P2PE list; a terminal that encrypts with strong cryptography but is not part of a listed solution does not qualify. The merchant follows the solution's instruction manual, and any path by which clear-text account data could reach the merchant removes eligibility.