PCI Assessments Center
Loading your workspace…
SAQ P2PE includes PCI DSS requirements applicable to merchants that process account data only via a validated PCI-listed Point-to-Point Encryption (P2PE) solution.
Merchants using a validated PCI-listed P2PE solution
card-present or MOTO (not e-commerce)
E-commerce channels; Service providers
PCI SSC SAQ Instructions and Guidelines v4.0.1 r1, page 21
Every criterion below must be true for SAQ P2PE to apply. A single false criterion removes eligibility.
The free PCI Assessments Center SAQ selector turns the official criteria into a fail-closed checklist. These are the exact items it verifies for SAQ P2PE:
Before any short-form SAQ can apply, the merchant must also satisfy these baseline checks:
An expired listing is not a validated solution. "Encrypting terminals" that are not PCI-listed P2PE do not qualify.
Run the free SAQ selector. It walks the official PCI SSC decision flow, records every answer, and re-derives the recommendation server-side with a confidence score — so you get a defensible record of why a given SAQ was chosen.
Source: PCI Security Standards Council, Self-Assessment Questionnaire Instructions and Guidelines for PCI DSS v4.0.1 r1. This guide is an independent summary and is not endorsed by PCI SSC.