3.2.1 P2PE

P2PE (Point-to-Point Encryption) is a methodology for securing credit card data by encrypting it from the time a card is input through a secure device (by card swipe or manual account entry) until it reaches the payment processor where it is decrypted. When implemented properly, these types of solutions make payment card transactions more secure by preventing the theft of credit card data while unencrypted on a POS device, or in transit.

By using P2PE, card data is unreadable until it reaches the secure decryption environment, which makes it less valuable if the data is stolen in a breach.

By encrypting cardholder data at the Point of Sale or Point of Entry, merchants can significantly reduce the risk of a data breach and the scope of PCI DSS compliance requirements.


