PCi

PCI Assessments Center

Loading your workspace…

PCiPCI Assessments Center
Free guide · PCI DSS v4.0.1

SAQ P2PE

SAQ P2PE includes PCI DSS requirements applicable to merchants that process account data only via a validated PCI-listed Point-to-Point Encryption (P2PE) solution.

SAQ P2PE at a glance

Who it is for

Merchants using a validated PCI-listed P2PE solution

Payment channels

card-present or MOTO (not e-commerce)

Not applicable to

E-commerce channels; Service providers

Official page

PCI SSC SAQ Instructions and Guidelines v4.0.1 r1, page 21

Eligibility criteria

Every criterion below must be true for SAQ P2PE to apply. A single false criterion removes eligibility.

All payment processing is via a validated PCI-listed P2PE solution.
The only systems in the merchant environment that store, process, or transmit account data are the payment terminals from a validated PCI-listed P2PE solution.
The merchant does not otherwise receive, transmit, or store account data electronically.
Any account data the merchant might retain is on paper (for example, printed reports or receipts), and these documents are not received electronically.
The merchant has implemented all controls in the P2PE Instruction Manual (PIM) provided by the P2PE Solution Provider.

What the selector checks

The free PCI Assessments Center SAQ selector turns the official criteria into a fail-closed checklist. These are the exact items it verifies for SAQ P2PE:

All payment processing is via a validated PCI-listed P2PE solution (a solution with an expired validation is not ‘validated’ — check with your acquirer).
The only systems in our environment that store, process, or transmit account data are the payment terminals from that validated PCI-listed P2PE solution.
We do not otherwise receive, transmit, or store account data electronically.
Any account data we retain is on paper only (printed reports/receipts) and is not received electronically.
We have implemented all controls in the P2PE Instruction Manual (PIM) provided by the P2PE Solution Provider.

Baseline disqualifiers

Before any short-form SAQ can apply, the merchant must also satisfy these baseline checks:

We do NOT store any account data in electronic format on our systems, including legacy data (PAN, cardholder name, service code, expiration date, or sensitive authentication data). Paper-only receipts or reports are fine.
We are NOT a designated entity that our acquirer or payment brand has required to complete PCI DSS Appendix A3 / DESV.
Our acquirer or payment brand has NOT required us to complete a full Report on Compliance (ROC).
We have NOT experienced a confirmed account-data breach in the last 12 months that our acquirer has told us to escalate.

Common mistake

An expired listing is not a validated solution. "Encrypting terminals" that are not PCI-listed P2PE do not qualify.

Not sure if SAQ P2PE applies?

Run the free SAQ selector. It walks the official PCI SSC decision flow, records every answer, and re-derives the recommendation server-side with a confidence score — so you get a defensible record of why a given SAQ was chosen.

Source: PCI Security Standards Council, Self-Assessment Questionnaire Instructions and Guidelines for PCI DSS v4.0.1 r1. This guide is an independent summary and is not endorsed by PCI SSC.