One year after transitioning to version 3.1, we are back to talk about P2PE: we have renewed our Point-to-Point Encryption certification, expanding the scope of supported terminals.
P2PE is the standard by which the PCI Security Standards Council defines the encryption requirements for payment data starting right from the terminal. In practice, card data is protected the exact instant it is read and remains encrypted until it reaches the authorized decryption environment, never passing through the merchant’s systems in clear text.
Maintaining the certification requires periodic, independent audits of cryptographic keys, devices, installation procedures, and chain of custody. Extending its coverage means guaranteeing the same high standard across an ever-wider scope.
For our clients, this translates into two things: a reduced risk surface on transactions and a streamlined PCI DSS compliance process.
Security and ease of use remain two requirements of the same project for us, not two competing priorities.