In addition to the security benefits to the business, P2PE also reduces the scope, complexity and administration costs of Payment Card Industry Data Security Standard (PCI DSS) compliance for payment solutions. As the gateway is the only holder of the decryption key, and sensitive card data is kept out of the POS environment, the scope is greatly reduced for PCI DSS certification. This saves the merchants a lot of time and money.
There’s a few ways businesses have implemented P2PE into their security strategy. Some large merchants with dedicated security resources and a quality security assessor build their own P2PE strategy from scratch. Internally-built solutions such as those might work for larger merchants but are less accessible for smaller merchants with fewer resources. Oftentimes, building a custom P2PE solution can create more complexities, require long and costly certifications and prove to be an immense challenge.
In the past, many have opted to pair together different parts of P2PE solutions from different vendors, which requires trusting both the service provider and a third-party entity that validated all of these pieces independently. To avoid the headache associated with this, many smaller merchants should invest in validated solutions.
Vendors with validated-P2PE solutions can properly implement all parts of the technology into your systems with assurance of full PCI DSS compliance. What is equally important, is that they can eliminate the need for security experts within your business. These providers can greatly simplify the process of implementation and are trained to correctly implement people, process and technology in five domains:
With all the benefits of P2PE, both in securing payment data and cutting down on the scope of PCI DSS compliance, many merchants are realizing the value of integrating this technology into their security strategy. How they choose to implement all of the elements of a P2PE solution is the second step.
In the age of open source solutions, creating your own P2PE solution can be tempting. Choosing to do this without an in-house specialist, however, can pose a challenge. With complex implementation and certification costs for payment security, working with an expert will save you time, money and effort in the long run. Investing in a validated solution ensures that most of the heavy lifting is already done for you - and your customers’ data will stay secure.
The PCI SSC maintains an updated authoritative list of validated components and solutions on their website. To learn more visit this page.
If you would like to learn more about a validated- P2PE solution, drop us a line and speak with our security experts!
Steven Bowles is the Regional Security Officer & Director of Security Solutions at Ingenico Group, North America