PCI P2PE Requirements, SAQ P2PE Eligibility, and Compliance

You can use the SAQ P2PE self-assessment questionnaire only if every card payment you take runs through a PCI-listed Point-to-Point Encryption solution, your own systems never see readable cardholder data, you retain no electronic account data, and you follow every procedure in the P2PE Instruction Manual your vendor supplies. Meeting SAQ P2PE eligibility trims your annual PCI DSS assessment from the hundreds of controls on SAQ D to roughly two dozen focused on the physical terminals and the people who handle them.

The Four Conditions You Must Meet

Eligibility is strict, and missing any one of these pushes you to a broader questionnaire, most likely SAQ D:1PCI Security Standards Council. PCI DSS v4.0 Self-Assessment Questionnaire P2PE

  • All payment processing goes through a PCI-listed P2PE solution. No side channels. No fallback manual-entry terminals running different software.
  • Your systems never see, store, or transmit readable cardholder data. The only systems that touch account data are the P2PE terminals themselves.
  • Any account data you retain is on paper, such as printed receipts or reports. Nothing sits in logs, databases, or temporary files on a computer.
  • You have implemented every control spelled out in the P2PE Instruction Manual provided by your solution vendor.

The single most common disqualifier is processing payments through any channel the validated solution does not cover.

What “PCI-Listed” Really Means

Many payment processors advertise “end-to-end encryption,” but that phrase alone does not reduce your PCI scope. The difference is validation. A PCI-listed P2PE solution has been independently assessed against the PCI P2PE Standard, with every component reviewed and approved by the PCI Security Standards Council: the terminal hardware, the encryption application, the key management process, and the decryption environment. Generic end-to-end encryption may use strong cryptography, but because it has not undergone that formal assessment, your acquiring bank and card brands have no standardized way to verify its security. Merchants using a non-validated encryption setup still face the full weight of PCI DSS during their annual assessment, even if the underlying technology looks similar.

Only solutions appearing on the PCI SSC’s validated P2PE list qualify for the SAQ P2PE scope reduction. That list is maintained on the Council’s website, where you can search by solution provider name or product.2PCI Security Standards Council. PCI Point-to-Point Encryption (P2PE) Solutions If your provider’s product is not on that list, you are not eligible regardless of what marketing materials claim. Before anything else, look up your solution by name.

Channels the Questionnaire Does Not Cover

SAQ P2PE is not available for e-commerce. If you run an online store that accepts card payments, those transactions cannot be assessed under SAQ P2PE, period. The questionnaire is designed for card-present (brick-and-mortar) and card-not-present (mail or telephone order) environments where the terminal hardware handles all encryption.1PCI Security Standards Council. PCI DSS v4.0 Self-Assessment Questionnaire P2PE

Multi-channel merchants need to pay close attention here. If you have a physical storefront using a validated P2PE solution and also operate a website that accepts card payments, you would use SAQ P2PE only for the in-store channel. The e-commerce channel requires a separate SAQ, typically SAQ A or SAQ A-EP depending on how web payments are handled. Assuming P2PE covers everything is where merchants get into trouble.

Other Things That Disqualify You

Software-based encryption that is not part of a validated P2PE solution disqualifies you immediately. So does managing your own encryption keys, storing card data electronically for any reason, or using terminals not specifically approved within your vendor’s validated product listing.3PCI Security Standards Council. Point-to-Point Encryption (P2PE)

What the SAQ P2PE Will Ask You to Confirm

Because a validated P2PE solution handles encryption, key management, and decryption outside your environment, the questionnaire focuses almost entirely on what you physically control: the terminals and the people who touch them. The core requirements fall under PCI DSS Requirement 9 (physical security) and Requirement 12 (policies and procedures).1PCI Security Standards Council. PCI DSS v4.0 Self-Assessment Questionnaire P2PE

Device Inventory

You need an up-to-date list of every Point-of-Interaction (POI) device in your environment. Each entry must include the make and model, the physical location where it sits, and a unique identifier such as the device serial number. Cross-reference this list against the shipping manifest you received from your vendor. Devices that cannot be accounted for are a red flag during any review.

Tamper Inspections

Terminals must be periodically inspected for signs of tampering or unauthorized substitution, and you need a defined process for it. Inspections should look for obvious physical alterations, overlays on the card slot or PIN pad, and any signs that a device has been swapped for a lookalike. What “periodically” means in practice is dictated by your P2PE Instruction Manual.

Employee Training

Staff who work around payment terminals need training on recognizing suspicious behavior. Employees should know how to verify the identity of anyone claiming to be a repair technician, understand that devices should never be replaced without a verification procedure, and know how to report suspected tampering. This is targeted at the physical terminal environment, not generic security awareness.

The P2PE Instruction Manual

Your solution provider is required to give you a P2PE Instruction Manual (PIM), and this document essentially runs your compliance life. The PIM lays out every operational procedure you must follow to maintain the validated status of the solution in your environment: how to receive and set up new terminals, how often to inspect them, how to handle a device you suspect has been compromised, and what to do when decommissioning old hardware.4PCI Security Standards Council. PCI P2PE Program Guide v3.0

When you fill out the SAQ P2PE, you are essentially confirming that you follow every instruction in the PIM. If it says to inspect devices weekly, your logs need to show weekly inspections. If it says to verify serial numbers against a manifest at delivery, you need documentation of that verification. Treat the PIM as the single source of truth.

Filling It Out and Filing It

Download the current version of SAQ P2PE directly from the PCI SSC document library. The form opens with identification fields: your business information, the name of your validated P2PE solution provider as it appears in the PCI SSC registry, and a description of how payment data flows through your environment. Work through each requirement, marking it “In Place,” “Not Applicable,” “Not Tested,” or “Not in Place.” Anything not in place needs a remediation plan with target dates.

At the end of the questionnaire is the Attestation of Compliance (AOC), a binding declaration that everything you reported is accurate. It requires a signature from a senior company officer authorized to represent the organization’s compliance status.

The completed SAQ and AOC do not go to the PCI Security Standards Council. You submit them to your acquiring bank or payment processor, which enforces compliance within your merchant relationship. Deadlines vary by acquirer; contact yours directly to confirm your due date and submission method.1PCI Security Standards Council. PCI DSS v4.0 Self-Assessment Questionnaire P2PE Keep a copy of the signed AOC and the full questionnaire on file. PCI DSS requires audit trail history to be retained for at least one year, and many acquiring banks expect compliance documentation to be available for longer.

SAQ P2PE is a self-assessment, so there is no blanket requirement to hire a Qualified Security Assessor. The AOC does include an optional QSA acknowledgment section for situations where an assessor assisted with or reviewed the self-assessment, and your acquiring bank may require a QSA review depending on your merchant level, transaction volume, or prior compliance history. That is an acquirer decision, not a PCI SSC mandate.

What Eligibility Buys You Beyond the Shorter Form

The compliance workload drops substantially, but the more consequential benefit shows up if a breach ever happens. Mastercard’s rules explicitly allow the use of a PCI-listed P2PE solution to be considered as a factor that may partially or fully relieve a compromised merchant of financial responsibility for assessments, breach reimbursement costs, and investigative expenses. Merchants using validated P2PE may also qualify for Mastercard’s PCI DSS Compliance Validation Exemption Program, which waives the annual validation requirement, though you still must maintain ongoing compliance.5Mastercard. Security Rules and Procedures – Merchant Edition

Staying Eligible Year to Year

PCI DSS v3.2.1 was retired on March 31, 2024, and 51 future-dated requirements under v4.0 became mandatory on March 31, 2025.6PCI Security Standards Council. Now Is the Time for Organizations to Adopt the Future-Dated Requirements of PCI DSS v4.x The current SAQ P2PE reflects v4.0 requirements, and any new or renewed assessment must use the v4.0 form.

Compliance is an annual cycle. Your acquiring bank will expect a fresh SAQ and AOC each year, and the controls described in your PIM (device inspections, employee training, inventory updates) must be maintained continuously between filings. A common mistake is treating the SAQ as yearly paperwork while letting day-to-day procedures lapse. If a breach occurs ten months into your compliance year and your inspection logs have gaps, the completed SAQ from the prior year will not protect you.7Visa. Account Information Security (AIS) Program and PCI

Eligibility can also erode from the vendor side. P2PE solutions rely on components with their own validation lifecycles, and terminal hardware is validated separately under the PCI PTS (PIN Transaction Security) program. When a component expires, the entire P2PE solution is not automatically invalidated, but the solution provider is expected to remediate promptly.8PCI Security Standards Council. PCI P2PE v3.x Technical FAQs For terminal hardware specifically, PCI-listed P2PE solutions may continue using expired PTS POI devices for up to five years past the device’s PTS expiry date; beyond that window, the devices are no longer valid within the solution. If your provider notifies you of an expired component, take it seriously. Ignoring the notice can quietly cost you your SAQ P2PE eligibility.