Skip to main content
Framework library
Framework module · pci-p2pe-3-2

PCI Point-to-Point Encryption

PCI SSC's standard for validated point-to-point encryption solutions that can reduce a merchant's PCI DSS scope. Part of the payments family beyond bare PCI DSS.

v3.2 · PCI Security Standards Council — P2PE

Standing today
Directory entry

00Answer

from the registry record
What is PCI Point-to-Point Encryption?
PCI SSC's standard for validated point-to-point encryption solutions that can reduce a merchant's PCI DSS scope. Part of the payments family beyond bare PCI DSS.
Who does PCI Point-to-Point Encryption apply to?
PCI Point-to-Point Encryption applies to payments, global, per PCI Security Standards Council — P2PE.
What is the current version of PCI Point-to-Point Encryption?
The current edition is v3.2, issued by PCI Security Standards Council — P2PE. Source: https://www.pcisecuritystandards.org/standards/point-to-point-encryption-p2pe/.
What does an assessment under PCI Point-to-Point Encryption require?
No control catalog has been ingested for PCI Point-to-Point Encryption yet — the registry tracks it as planned (Tracked metadata: we name the regime and monitor its issuing authority. No control or requirement model is implemented), so an assessment under this framework currently requires the authority's own catalog rather than a ControlFrame-parsed one.

01Standing

Directory entry

Authority and version facts, with a parsed public catalog when available; no tenant blueprint or executable evidence method is activated.

PCI Point-to-Point Encryption is tracked in the registry — authority, version ledger, verification — and nothing else is modelled for it yet. Import its catalog to begin.

Freely downloadable from PCI SSC; PCI SSC's terms permit identifiers and structure, not verbatim requirement text, without a separate license.

02Registry record

checked 2026-09-06
Registry status
Planned · namedTracked metadata: we name the regime and monitor its issuing authority. No control or requirement model is implemented.
Control units
Not on record — no catalog ingested and no authority-published count cited.
Control families
Encryption device management · Application security · Decryption environment · P2PE solution management
Applies to
payments · global
Verification
Secondary — corroborated across independent sources; the authority blocks automated fetch or does not state it plainly. checked 2026-09-06
Pending change
PCI SSC closed v3.1 solution submissions 2026-03-31. A v4.0 revision is in development; no publication date has been announced.Expected: v4.0 in development; unannounced

03Version ledger

2 editions
v3.1Supersededdate not published
v3.2Current edition · supersedes v3.1date not published

06Related frameworks

scored from registry facts
  1. PCI DSSv4.0.1

    Also applies to payments · The cardholder-data standard every merchant and service provider that touches payment card data is measured against. v4.0 retired 2024-12-31; the 51 future-dated v4.x requirements became mandatory 2025-03-31.

  2. Also applies to payments · PCI SSC's standard for accepting PINs on commercial off-the-shelf mobile devices via a software-based PIN-entry application. In its formal sunset window now, with MPoC as the designated successor.

  3. Also applies to payments · PCI SSC's standard for accepting contactless card payments on a commercial off-the-shelf mobile device without a separate secure card reader. In its formal sunset window now, with MPoC as the designated successor.

  4. Also applies to payments · PCI SSC's security requirements for 3-D Secure environments (issuer/ACS, 3DS Server, and DS components) that support cardholder authentication.

PCI Point-to-Point Encryption | ControlFrame