Advisory

PCI P2PE Assessments

PCI point-to-point encryption assessments for solution providers, component providers and the merchants who rely on them.

Encrypt card data at the terminal. Show that it holds.

A point-to-point encryption (P2PE) solution protects account data from the moment a merchant accepts a card to the secure point where it is decrypted. The PCI P2PE Standard sets the security requirements and testing procedures for P2PE solutions, components and applications. Merchants that use a P2PE solution listed by the PCI Security Standards Council have fewer PCI DSS requirements to meet. Vectra runs PCI P2PE assessments. We help solution providers, component providers and application vendors define their scope, prepare evidence, close gaps and complete the assessment. For merchants, we explain what a listed solution changes in your PCI DSS scope.

PCI P2PE Assessments

What a P2PE assessment looks at.

P2PE v3.2 is the version for new assessments. PCI SSC released it in June 2025, and every new submission since 1 January 2026 must use it.

The standard follows card data from the device where it is captured to the environment where it is decrypted. Each part of that path has its own requirements.

  • Encryption devices

    How approved payment devices are managed, tracked, installed and protected before they reach the merchant and while they are in use.

  • Decryption environment

    How the environment that decrypts account data is secured, monitored and kept separate.

  • Key management

    How the cryptographic keys that protect account data are created, loaded, distributed and controlled.

  • P2PE applications

    How software on the payment device that can access account data is developed and controlled.

  • Merchant instructions

    How the P2PE Instruction Manual tells merchants to install, use and protect the solution.

P2PE inside one PCI practice.

PCI work since 2006

Vectra became Australia's first certified QSA Company in 2006. Our P2PE assessments sit inside the same PCI practice.

Across the PCI standards

We run assessments for PCI DSS, PCI PIN, PCI P2PE and the Software Security Framework, so we can identify where key management and device controls overlap and plan the work together.

Both sides of the solution

We work with the providers that build P2PE solutions and with the merchants that deploy them, so advice on scope is consistent across both.

From solution design to validation.

Each step is based on evidence of the controls operating today.

  1. Step 1: Scope

    Define the solution or component, the devices, the decryption environment, the key management services and any third parties involved.

  2. Step 2: Readiness review

    Check your device management, key management and decryption controls against the P2PE requirements, and prioritise the gaps by risk.

  3. Step 3: Fix the gaps

    Help your team update procedures, device records and the P2PE Instruction Manual, and gather the evidence the assessment needs.

  4. Step 4: Assess

    Review documentation and records, interview staff, examine devices and facilities, and test the controls that apply.

  5. Step 5: Report

    Prepare the P2PE Report on Validation and Attestation of Validation, with clear findings and supporting evidence.

  6. Step 6: Manage change

    Assess the impact of new devices, software, facilities and providers, so changes are documented before they reach merchants.

P2PE work we run.

P2PE gap assessment

A review of your solution or component against the P2PE Standard, with a ranked plan to close the gaps.

Solution assessments

An assessment of a complete P2PE solution, from device handling and encryption through to decryption and key management.

Component assessments

An assessment of a single component, such as encryption management, decryption management or key management services.

Version 3.2 readiness

A review of the changes in P2PE v3.2, including device testing and sampling, and the management of whitelists and non-payment software.

Merchant scope advice

Advice for merchants on how a listed P2PE solution affects their PCI DSS validation, and the instructions they must follow.

What you have at the end.

  • A clear scope for your P2PE solution or component, agreed before the assessment starts.

  • Device, key and decryption procedures that match the current P2PE requirements.

  • A P2PE Instruction Manual that tells merchants how to use the solution safely.

  • A ranked list of any gaps, with owners and next steps.

PCI P2PE questions.

What is the difference between a P2PE solution and a component?

A solution provider is responsible for the complete P2PE solution that a merchant uses. A component provider delivers one part of it, such as encryption management, decryption management or key management, which a solution provider can then include in its solution.

Which version of the P2PE Standard applies?

PCI SSC released P2PE v3.2 in June 2025. Since 1 January 2026, all new submissions must use v3.2. Solutions, components and applications already validated to v3.0 or v3.1 are not affected by the release.

Does a P2PE solution remove the need for PCI DSS?

No. A merchant using a listed P2PE solution has fewer PCI DSS requirements to meet, but still validates compliance. The merchant must also follow the solution's P2PE Instruction Manual.

What about encryption solutions that are not listed?

The reduced scope applies to solutions on the PCI SSC list. An encryption solution that is not listed is reviewed as part of the merchant's PCI DSS assessment instead.

Can you help before a formal assessment?

Yes. Most engagements begin with a gap assessment that shows what to fix first.

Start with a conversation.

Speak to us about your cyber governance and compliance requirements.