PCI Point-to-Point Encryption
PCI SSC's standard for validated point-to-point encryption solutions that can reduce a merchant's PCI DSS scope. Part of the payments family beyond bare PCI DSS.
v3.2 · PCI Security Standards Council — P2PE
00Answer
01Standing
Authority and version facts, with a parsed public catalog when available; no tenant blueprint or executable evidence method is activated.
PCI Point-to-Point Encryption is tracked in the registry — authority, version ledger, verification — and nothing else is modelled for it yet. Import its catalog to begin.
Freely downloadable from PCI SSC; PCI SSC's terms permit identifiers and structure, not verbatim requirement text, without a separate license.
02Registry record
- Registry status
- Planned · namedTracked metadata: we name the regime and monitor its issuing authority. No control or requirement model is implemented.
- Control units
- Not on record — no catalog ingested and no authority-published count cited.
- Control families
- Encryption device management · Application security · Decryption environment · P2PE solution management
- Applies to
- payments · global
- Verification
- Secondary — corroborated across independent sources; the authority blocks automated fetch or does not state it plainly. checked 2026-09-06
- Pending change
- PCI SSC closed v3.1 solution submissions 2026-03-31. A v4.0 revision is in development; no publication date has been announced.Expected: v4.0 in development; unannounced
03Version ledger
| v3.1 | Superseded | date not published |
| v3.2 | Current edition · supersedes v3.1 | date not published |
06Related frameworks
- PCI DSSv4.0.1
Also applies to payments · The cardholder-data standard every merchant and service provider that touches payment card data is measured against. v4.0 retired 2024-12-31; the 51 future-dated v4.x requirements became mandatory 2025-03-31.
Also applies to payments · PCI SSC's standard for accepting PINs on commercial off-the-shelf mobile devices via a software-based PIN-entry application. In its formal sunset window now, with MPoC as the designated successor.
Also applies to payments · PCI SSC's standard for accepting contactless card payments on a commercial off-the-shelf mobile device without a separate secure card reader. In its formal sunset window now, with MPoC as the designated successor.
Also applies to payments · PCI SSC's security requirements for 3-D Secure environments (issuer/ACS, 3DS Server, and DS components) that support cardholder authentication.