P2PE (Point-to-Point Encryption)

P2PE (Point-to-Point Encryption) is encrypting of the cardholder’s information from the point of collection at the business to the point of receipt by the payment processor.
« Back to Glossary Index

P2PE (Point-to-Point Encryption)

Point-to-Point Encryption refers to a standard commonly used to safeguard the information of credit cardholders. P2PE occurs when the cardholder information is encrypted at the point of sale and is not decrypted until it is processed by the payment processor. 

The Payment Card Industry Security Standards Council sets minimum security standards that businesses and payment processors must abide by to properly secure customer information. 

There are 12 recommended practices that relate to credit card processing. 

If a processor implements the measures set forth, they can apply to be evaluated by a PCI Quality Security Assessor (QSA). These are individuals that undergo intensive training and receive certification to act as QSAs. 

How Does P2PE Work? 

When a sale occurs, either in person or over the internet, the payment processing system converts the data to an unreadable code.

From the time a business collects the information, the information becomes unusable to a potential cyberthief.

In this way, if a business is breached, business owners can rest assured that their customers’ sensitive card information is protected. 

Once received by the payment processor, a secure key is used to decrypt the data. 

Why Use P2PE? 

Using technology like this alongside the other recommended practices greatly reduces the likelihood of a data breach.

This type of event can damage a business’ reputation. If customers are notified of a data breach, they may lose confidence and cease to patronize your business.

By using a PCI validated P2PE solution, a business eliminates its liability in the event of a data breach. 

If this does occur, the responsibility lies with the P2PE provider. It is possible that the PCI Security Standards Council can implement penalties for the payment processor if it is found they were not in compliance.

These penalties can include fines or suspension of credit card processing privileges. 

The bottom line is utilizing a P2PE PCI validated system helps protect both your business and your customers. 

« Back to Glossary Index

Related Terms:

CTA Title

Sed ut ullamcorper nulla, eu consequat turpis. Duis ac molestie orci. Suspendisse blandit ullamcorper eros

CTA Button