PCI work since 2006
Vectra became Australia's first certified QSA Company in 2006. Our P2PE assessments sit inside the same PCI practice.
PCI point-to-point encryption assessments for solution providers, component providers and the merchants who rely on them.
A point-to-point encryption (P2PE) solution protects account data from the moment a merchant accepts a card to the secure point where it is decrypted. The PCI P2PE Standard sets the security requirements and testing procedures for P2PE solutions, components and applications. Merchants that use a P2PE solution listed by the PCI Security Standards Council have fewer PCI DSS requirements to meet. Vectra runs PCI P2PE assessments. We help solution providers, component providers and application vendors define their scope, prepare evidence, close gaps and complete the assessment. For merchants, we explain what a listed solution changes in your PCI DSS scope.
P2PE v3.2 is the version for new assessments. PCI SSC released it in June 2025, and every new submission since 1 January 2026 must use it.
The standard follows card data from the device where it is captured to the environment where it is decrypted. Each part of that path has its own requirements.
How approved payment devices are managed, tracked, installed and protected before they reach the merchant and while they are in use.
How the environment that decrypts account data is secured, monitored and kept separate.
How the cryptographic keys that protect account data are created, loaded, distributed and controlled.
How software on the payment device that can access account data is developed and controlled.
How the P2PE Instruction Manual tells merchants to install, use and protect the solution.
Vectra became Australia's first certified QSA Company in 2006. Our P2PE assessments sit inside the same PCI practice.
We run assessments for PCI DSS, PCI PIN, PCI P2PE and the Software Security Framework, so we can identify where key management and device controls overlap and plan the work together.
We work with the providers that build P2PE solutions and with the merchants that deploy them, so advice on scope is consistent across both.
Each step is based on evidence of the controls operating today.
Define the solution or component, the devices, the decryption environment, the key management services and any third parties involved.
Check your device management, key management and decryption controls against the P2PE requirements, and prioritise the gaps by risk.
Help your team update procedures, device records and the P2PE Instruction Manual, and gather the evidence the assessment needs.
Review documentation and records, interview staff, examine devices and facilities, and test the controls that apply.
Prepare the P2PE Report on Validation and Attestation of Validation, with clear findings and supporting evidence.
Assess the impact of new devices, software, facilities and providers, so changes are documented before they reach merchants.
A review of your solution or component against the P2PE Standard, with a ranked plan to close the gaps.
An assessment of a complete P2PE solution, from device handling and encryption through to decryption and key management.
An assessment of a single component, such as encryption management, decryption management or key management services.
A review of the changes in P2PE v3.2, including device testing and sampling, and the management of whitelists and non-payment software.
Advice for merchants on how a listed P2PE solution affects their PCI DSS validation, and the instructions they must follow.
A clear scope for your P2PE solution or component, agreed before the assessment starts.
Device, key and decryption procedures that match the current P2PE requirements.
A P2PE Instruction Manual that tells merchants how to use the solution safely.
A ranked list of any gaps, with owners and next steps.
A solution provider is responsible for the complete P2PE solution that a merchant uses. A component provider delivers one part of it, such as encryption management, decryption management or key management, which a solution provider can then include in its solution.
PCI SSC released P2PE v3.2 in June 2025. Since 1 January 2026, all new submissions must use v3.2. Solutions, components and applications already validated to v3.0 or v3.1 are not affected by the release.
No. A merchant using a listed P2PE solution has fewer PCI DSS requirements to meet, but still validates compliance. The merchant must also follow the solution's P2PE Instruction Manual.
The reduced scope applies to solutions on the PCI SSC list. An encryption solution that is not listed is reviewed as part of the merchant's PCI DSS assessment instead.
Yes. Most engagements begin with a gap assessment that shows what to fix first.
Speak to us about your cyber governance and compliance requirements.