ℹ️
Reference Content: This is a copy of content from the PCI Security Standards Council FAQ database, preserved for tracking changes over time.
View Original →
FAQ #1246 Published

Can a QSA that is not also a P2PE Assessor validate an encryption solution meets P2PE Requirements?

No. Only P2PE Assessors are qualified by the PCI Council to evaluate P2PE Solutions, P2PE Components and P2PE Applications. Note that only a QSA (P2PE) is qualified to evaluate P2PE Solutions (including Merchant-Managed Solutions) and P2PE Components, while a PA-QSA (P2PE) is additionally qualified to evaluate P2PE Applications.

Disclaimer: This FAQ has been processed for display on this website and may contain errors. Please check the original FAQ on the PCI SSC website for the authoritative version.