Diff: FAQ #1251
What is the process to use previously-deployed POI devices in a PCI P2PE solution?
Earlier Version
Later Version
Removed
Added
Please refer to the latest P2PE glossary for definitions of terms used in this FAQ.
The P2PE standard contains various requirements regarding the establishment and enablement of POI devices in merchant locations for use in a validated P2PE solution. If these requirements are not specifically adhered to, it may be difficult or impossible for a P2PE Assessor to verify the applicable requirements in P2PE Domains 1, 2, and 6 have been satisfied, especially when the POI devices were deployed either without knowledge of the requirements and/or prior to a P2PE assessment. POI devices already deployed as part of a PCI-listed P2PE v1 solution that are being assessed to the current P2PE Standard should still adhere to this guidance, though, the effort and/or concern is likely minimal.
P2PE solution providers should engage a P2PE Assessor as soon as possible to assess the status of the previously-deployed POI devices. The P2PE Assessor can assess the solution provider?s documented processes for POI deployment and note any potential deficiencies requiring remediation.
The following table depicts various scenarios
(Note that,
|
| SCENARIO | PROCESS |
|
A P2PE
|
- If the P2PE Assessor determines the applicable P2PE requirements regarding the previously-deployed POI devices have been satisfied, the P2PE Assessor will document
If the solution provider lacks sufficient evidence to verify the applicable P2PE requirements have been satisfied (as determined by a P2PE Assessor during the course of a P2PE assessment), then all firmware, cryptographic keys NOTE , configurations, and software must be reloaded into the POI devices in
|
|
A solution provider with a
|
- If the applicable P2PE requirements regarding the previously-deployed POI devices have been satisfied, the results must be documented by the solution provider and
If the solution provider lacks sufficient evidence to verify the applicable P2PE requirements have been satisfied, then all firmware, cryptographic keys NOTE , configurations, and software must be reloaded into the POI devices in accordance with applicable P2PE requirements.
|
|
A solution provider with a
P2PE Solution Provider: Follow the FAQ assessment process detailed below, including documenting and retaining the results for future review.
The solution provider with previously-deployed POI devices meeting one of the above scenarios must adhere to at least one of the two options below:
-
The P2PE solution provider follows their documented processes that were assessed previously as part of their P2PE solution assessment.
If the applicable P2PE requirements regarding the previously-deployed POI devices have been satisfied, the results must be documented by the solution provider and retained for future review.
If the solution provider lacks sufficient evidence to
- Option 2: If there is insufficient evidence to support Option 1 (and therefore it is impossible to meet and/or verify all applicable P2PE requirements), the previously-deployed POI devices must be reset and all firmware, cryptographic keys, configurations, and software must be reloaded in accordance with all applicable P2PE requirements.
Disclaimer: This FAQ has been processed for display on this website and may contain errors. Please check the original FAQ on the PCI SSC website for the authoritative version.