Diff: FAQ #1369

Does PCI P2PE v2 allow for partial assessments of third parties with services that will be used in one or more P2PE solutions?

Earlier Version
Later Version
Removed
Added
No.   PCI P2PE v2 introduced the concept ofallows for P2PE component providers to formalize the process of assessing third parties,parties.  Therefore, it is not allowable to perform partial P2PE assessments and reuse (for example, via a partial P-ROV) those partial assessments for either P2PE component provider and/or solution provider assessments.

All third parties providing services to P2PE solution providers must be assessed against the P2PE standard.  As stated
in both the P2PE v2 Standard and Program Guide. Therefore, itthe PCI P2PE standard:  There are two options for third-party entities performing functions on behalf of solution providers to validate compliance:    

Undergo a P2PE assessment of relevant P2PE requirements on their own and submit the applicable P2PE Report of Validation (P-ROV) to PCI SSC for review and acceptance. Upon acceptance, the P2PE component
is not allowable to perform partial P2PE assessments and reuse (for example, via a partial P-ROV) those partial assessments for either P2PE v2 component provider and/or solution provider assessments. In addition, please note that any third party assessments completed using v1.1 of the P2PE standards (with the exception of PCI-listed v1.x P2PE Applications ? see Can PCI-listed P2PE v1.1 applications be used inlisted on PCI P2PE v2 solutions?) are not eligible for use in P2PE v2 solutions. All third parties providing services to P2PE v2 solution providers must be assessed against the P2PE v2 standard. As stated in v2 of the PCI P2PE standard:
?There are two options for third-party entities performing functions on behalf of solution providers to validate compliance:

Undergo a P2PE assessment of relevant P2PE requirements on their own and submit the applicable P2PE Report of Validation (P-ROV) to PCI SSC for review and acceptance. Upon acceptance, the P2PE component is listed on PCI SSC?s
SSCs list of Validated P2PE Components.

Or:



Have their services reviewed during the course of each of their solution-provider customers?customers P2PE assessments. ?

There is considerable information regarding component providers and third parties in the standard, specifically in the section ?P2PE'P2PE Solutions and Use of Third Parties and/or P2PE Component Providers?.Providers'.

Disclaimer: This FAQ has been processed for display on this website and may contain errors. Please check the original FAQ on the PCI SSC website for the authoritative version.