PCI

Blog space

P2PE (Point-to-Point Encryption) – How Payment Encryption Reduces PCI DSS Scope

Inside this article:

  • How P2PE differs from standard TLS encryption
  • When a merchant can use SAQ P2PE
  • How to check a P2PE provider on the PCI SSC list
P2PE Payment Encryption

Updated: 5 lipca 2026

What is P2PE and why does it matter for merchants? Point-to-Point Encryption (P2PE) is a PCI SSC standard defining the encryption of cardholder data from the moment it enters the payment terminal through to decryption in the payment processor’s secure environment – outside the merchant’s own infrastructure. A PCI SSC-validated P2PE solution eliminates the Cardholder Data Environment (CDE) on the merchant side, qualifying the merchant for SAQ P2PE – the shortest self-assessment questionnaire (33 questions, versus over 300 in SAQ D). For retailers, restaurants, and any merchant handling card payments at physical locations, implementing P2PE is one of the most effective methods of reducing the cost and scope of PCI DSS compliance.

P2PE Payment Encryption and PCI DSS certification – at a glance:

  1. A PCI SSC-validated P2PE solution encrypts CHD at the card reader before any contact with merchant systems – cardholder data never exists in plaintext anywhere in the merchant environment
  2. A merchant using a validated P2PE solution qualifies for SAQ P2PE (33 questions) instead of SAQ D (300+ questions) or a full ROC – a dramatic reduction in compliance cost and scope
  3. The list of validated P2PE solutions is available in the PCI SSC database – only solutions from this list allow merchants to qualify for SAQ P2PE.
  4. P2PE protects only the physical channel (the terminal) – a merchant that also processes e-commerce or card-not-present payments remains subject to the full PCI DSS scope for those channels
  5. A merchant using P2PE remains responsible for terminal physical security and TPSP management – P2PE does not eliminate all PCI DSS requirements
  6. Patronusec as an accredited QSA verifies correct P2PE implementation and helps multi-location merchants structure their compliance programme to minimise costs



How does P2PE encryption work – and how does it differ from TLS?

This is a common source of confusion – merchants often assume that because their payments travel over HTTPS (TLS), they already have P2PE. They do not, and the difference has certification consequences.

TLS (Transport Layer Security):

TLS encrypts data in transit between two network endpoints – for example, between a customer’s browser and an e-commerce server, or between a terminal and a payment gateway server. TLS protects data in transit, but the data exists in unencrypted form at both endpoints. A merchant using terminals that communicate via TLS still has cardholder data within their network – in plaintext on the terminal before encryption and potentially on terminal management servers.

P2PE (Point-to-Point Encryption):

P2PE encrypts cardholder data directly at the card reader head (hardware encryption) – before the data reaches the terminal processor, merchant network, or any merchant IT system. Encryption keys are managed exclusively by the certified P2PE solution provider, not by the merchant. The merchant never has access to decryption keys – even if someone intercepts data within the merchant’s network, they see only an encrypted string that cannot be decrypted.

P2PE versus a standard terminal:

StageStandard terminalP2PE terminal
Card contacts readerCard data in plaintextData encrypted immediately in hardware
Data in terminalPAN visibleEncrypted string only
Data in merchant networkPAN may be visibleEncrypted string only
Data in merchant systems (POS, ERP)PAN may be storedEncrypted string only
DecryptionBy merchant or gatewayOnly in the P2PE provider’s secure environment
Decryption keysHeld by merchant or gatewayHeld exclusively by P2PE provider

Patronusec Insight: The most common mistake among merchants considering P2PE is purchasing “terminals with encryption” without verifying that the solution is PCI SSC-validated. Many terminals encrypt data, but these are not PCI SSC-validated P2PE solutions – and therefore do not qualify the merchant for SAQ P2PE. The validated solution list is at pcisecuritystandards.org and should be verified with a QSA before deployment. We verify correct P2PE implementation as part of our PCI DSS scope assessment.

How does P2PE reduce PCI DSS scope – and when can SAQ P2PE be used?

The rule is clear, but has important boundary conditions.

Conditions for SAQ P2PE:

A merchant may use SAQ P2PE if:

  1. They use a P2PE solution from the PCI SSC validated list
  2. They make no customisation to P2PE terminals
  3. They do not store, process, or transmit CHD in any IT system
  4. They do not accept card-not-present payments (e-commerce requires a separate assessment)

What P2PE removes from scope:

With a correctly implemented P2PE solution, the following exit the PCI DSS certification scope:

  • POS servers, ERP systems, back-office systems (because they never see CHD)
  • Merchant networks (because even if traffic is intercepted, only an encrypted string is visible)
  • Staff management, loyalty, and reporting systems (if they do not store CHD)

What P2PE does NOT remove:

  • P2PE terminal providers (TPSPs) must hold a current P2PE certificate on the PCI SSC list
  • Terminal management procedures (physical security, tamper-evident seals)
  • E-commerce or MOTO (mail/phone order) channels if the merchant operates them
  • General PCI DSS TPSP management requirements (Requirement 12.8)


Considering P2PE implementation to reduce PCI DSS scope before certification?

Patronusec as an accredited QSA will assess whether your current or planned P2PE implementation qualifies for SAQ P2PE. A free initial call establishes the scope with and without P2PE so you can compare costs and decide.

Discuss P2PE with a QSA


How do you choose a P2PE provider – and what to verify before deployment?

Choosing a P2PE provider is more constrained than selecting a standard terminal supplier – only the PCI SSC list matters.

Step 1: Check the PCI SSC list

Start with the Validated Point-to-Point Encryption Solutions list at pcisecuritystandards.org. The list shows the provider name, solution name, and scope (Contact Payments, Contactless, Manual Key Entry). Verify that your prospective provider’s solution appears on the list and covers the payment types you need.

Step 2: Match to your business model

Different P2PE solutions cover different payment types and terminal hardware. Confirm that the solution covers the card schemes (Visa, Mastercard, Amex) and transaction types (contact, contactless, manual key entry) you need, and that it integrates with your POS system.

Step 3: Commercial terms and SLA

The P2PE provider manages the encryption keys and is responsible for the decryption process security. Verify: replacement timelines for terminals in the event of a security compromise, liability terms for incidents, and whether the provider supplies a Responsibility Matrix for your auditor.

Step 4: Terminal management procedures

Your responsibility as a merchant is correct management of P2PE terminals: verifying terminal authenticity before deployment (tamper-evident seal inspection), procedures for inspecting terminals for skimming devices, procedures for reporting suspected physical terminal compromise, and procedures for replacing a terminal where compromise is suspected.

Patronusec Insight: Merchants with multiple locations often find that P2PE deployment requires changes not only to terminal hardware but also to logistics processes, staff training, and device management procedures. Firms that treat P2PE as “we buy new terminals and the problem is solved” frequently have informal terminal management processes that the QSA challenges during the assessment. A scope assessment before P2PE deployment avoids these surprises.

FAQ – P2PE payment encryption

Does P2PE eliminate the entire PCI DSS scope?

No – P2PE eliminates requirements relating to CHD protection in merchant IT systems, but not all PCI DSS requirements. A merchant using P2PE still needs to: manage P2PE terminals securely (physical), manage TPSP suppliers (Requirement 12.8), and comply with any requirements for e-commerce or MOTO channels if operated.

Does any terminal encryption count as P2PE?

No – only solutions validated by PCI SSC and appearing on their Validated P2PE Solutions list constitute P2PE in the PCI DSS sense. Many terminals encrypt data, but do not meet the P2PE programme requirements – a merchant using such a terminal cannot use SAQ P2PE.

How much does P2PE implementation cost?

Costs include: terminal purchase or lease (typically £300 to £1,500 per terminal depending on model), P2PE service provider fees (usually incorporated into transaction processing rates), and implementation costs (configuration, training, procedures). Savings from reduced PCI DSS scope (SAQ P2PE instead of ROC or SAQ D) typically offset the implementation cost within 1 to 3 years.

What is “implemented P2PE” in the context of SAQ P2PE?

SAQ P2PE is available only when the merchant uses a PCI SSC-listed P2PE solution WITHOUT any customisation. Terminal customisation – for example, installing custom software on the terminal or integrating with a POS system through a method other than one provided by the P2PE solution provider – may disqualify the merchant from SAQ P2PE and require a more extensive assessment.

Does P2PE protect against skimming attacks?

P2PE protects against software skimming (malware intercepting data from the terminal or POS system), because data is encrypted immediately in the terminal hardware. P2PE does not protect against physical skimming (a device overlaid on the card reader) – which is why physical terminal inspection procedures are part of P2PE requirements for merchants.

How does Patronusec verify that a P2PE implementation qualifies for SAQ P2PE?

In a scope assessment, we verify: that the solution appears on the PCI SSC list, that the deployment includes no customisation that would disqualify SAQ P2PE, that terminal management procedures are documented and implemented, and that the merchant does not operate e-commerce or MOTO channels requiring a separate assessment. The output: confirmation that SAQ P2PE is available, or a list of requirements to satisfy.


P2PE and PCI DSS certification – free consultation

Patronusec as an accredited QSA verifies P2PE implementation and helps multi-location merchants build compliance programmes based on SAQ P2PE. We work with retailers, restaurant chains, and hospitality operators across the UK and EU.

In a free 30-minute consultation we will help you:

  • Compare PCI DSS certification scope with and without P2PE for your business model
  • Verify whether your current or prospective terminal provider is on the PCI SSC validated list
  • Assess whether your terminal management procedures satisfy SAQ P2PE requirements
  • Plan the SAQ P2PE or ROC certification path for a multi-location estate

Free consultation | PCI DSS certification | Gap analysis PCI DSS | Penetration testing | PCI P2PE certification

Don't buy a pig in a poke -
request a free consultation and check how we can assist you.

Free consultation
Contact form

Use the contact form or contact us directly.

Patronusec Sp z o. o.

Head Office:
ul. Święty Marcin 29/8
61-806 Poznań, Polska

KRS: 0001039087
REGON: 525433988
NIP: 7831881739
D-U-N-S: 989454390
LEI: 259400NAR8ZOX1O66C64

To top