This increasing threat has led the Payment Security Council (PCI) to develop a higher level of payment security called Validated Point-to-Point Encryption (P2PE). The requirements set by the Point-to-Point Encryption (P2PE) Standard are designed not only to keep payment data in transit secure, but also to thwart potential tampering with the point-of-sale (POS) payment devices. The standard requires special packaging and a clear, trackable chain of custody for every payment device shipped from manufacturer to merchant.
If payment security were cars, PCI DSS would be the basic sedan and P2PE would be the armored tank. The PCI DSS framework is a list of technical, physical, and process controls that are required to address security threats that could compromise cardholder data within the merchant environment. Throughout PCI DSS, different forms of encryption are required.
However, the PCI Council recognized the need for additional guidance regarding the proper implementation of transaction encryption. Hence, PCI P2PE was born. The Council also recognized that solution providers and merchants that adhered to the PCI P2PE would reduce the PCI DSS compliance scope in the merchant environment.
A PCI-validated P2PE solution has two parts: 1) security of the payment device hardware and 2) encryption of payment data starting at the Point-of-Interaction (POI).
For any organization that accepts credit cards at point-of-sale (or for healthcare organizations, at point-of-care), a validated P2PE solution enables them to go “above and beyond” to achieve the highest standard for securing cardholder financial data.
Not only does this reduce the threat of a data breach, it can also significantly lessen the scope, complexity, and administration costs of PCI compliance.
Less than 50 companies worldwide have been validated as PCI-listed P2PE Solutions Providers. A complete list can be found on the PCI Security Standards Council website at: https://www.pcisecuritystandards.org/assessors_and_solutions/point_to_point_encryption_solutions .
If you would like to learn more about AxiaMed’s Payment Fusion PCI P2PE Validated Solution, click here.
Dan Berger is the Director of Sales at AxiaMed
(AxiaMed as a division of Axia Technologies, LLC)