Frequently Asked Questions

< Back to search page

Can a QSA that is not also a P2PE Assessor validate an encryption solution meets P2PE Requirements?

FAQ Response

No. Only P2PE Assessors are qualified by the PCI Council to evaluate P2PE Solutions, P2PE Components and P2PE Applications. Note that only a QSA (P2PE) is qualified to evaluate P2PE Solutions (including Merchant-Managed Solutions) and P2PE Components, while a PA-QSA (P2PE) is additionally qualified to evaluate P2PE Applications.

June 2016
Article Number 1246