Frequently Asked Questions

< Back to search page

Does PCI P2PE v2 allow for partial assessments of third parties with services that will be used in one or more P2PE solutions?

FAQ Response

No. PCI P2PE v2 introduced the concept of P2PE component providers to formalize the process of assessing third parties, in both the P2PE v2 Standard and Program Guide. Therefore, it is not allowable to perform partial P2PE assessments and reuse (for example, via a partial P-ROV) those partial assessments for either P2PE v2 component provider and/or solution provider assessments. In addition, please note that any third party assessments completed using v1.1 of the P2PE standards (with the exception of PCI-listed v1.x P2PE Applications – see Can PCI-listed P2PE v1.1 applications be used in PCI P2PE v2 solutions?) are not eligible for use in P2PE v2 solutions. All third parties providing services to P2PE v2 solution providers must be assessed against the P2PE v2 standard. As stated in v2 of the PCI P2PE standard:
“There are two options for third-party entities performing functions on behalf of solution providers to validate compliance:

    1. Undergo a P2PE assessment of relevant P2PE requirements on their own and submit the applicable P2PE Report of Validation (P-ROV) to PCI SSC for           review and acceptance. Upon acceptance, the P2PE component is listed on PCI SSC’s list of Validated P2PE Components.    
                                                                                                                 
    Or:

    2. Have their services reviewed during the course of each of their solution-provider customers’ P2PE assessments. “

There is considerable information regarding component providers and third parties in the standard, specifically in the section “P2PE Solutions and Use of Third Parties and/or P2PE Component Providers”.  


 

June 2016
Article Number 1369