Global (PCI Security Standards Council; P2PE solution providers, component providers, application vendors and merchants operating merchant-managed solutions)

PCI P2PE

407 controls. 196 other frameworks in our corpus share controls with it. Here is all of it, and how much of it you are already doing.

Page built . This page is derived from the framework corpus, which changes when the corpus is extended rather than daily.

407 controls 196 frameworks share controls with it Global (PCI Security Standards Council; P2PE solution providers, component providers, application vendors and merchants operating merchant-managed solutions) verified against its source document

Every control below is one this framework asks for. The right hand column counts how many other frameworks in our corpus carry the same control, which is the difference between doing this work once and doing it again for the next standard.

There is no implementation kit for this framework yet. The control list and the overlap above are free and complete.

What you already have

Frameworks whose controls overlap this one, most first. If you run any of them, the count is roughly what you have already evidenced.

Every control

Showing 400 of 407. The kit carries all of them.

CodeControlAlso in
Annex-ASymmetric Key Distribution Using Asymmetric Techniques0
Annex-BKey Injection Facility Requirements0
Domain-1.1POI Device Approval Status0
Domain-1.2Account Data Encryption at POI0
Domain-1.3POI Device Tampering Protection0
Domain-2.1POI Application Security0
Domain-2.2POI Device Authentication0
Domain-3.1POI Device Management0
Domain-3.2Merchant POI Device Deployment0
Domain-4.1Decryption Environment Logical Security0
Domain-4.2Decryption Environment Physical Security0
Domain-5.1Key Generation0
Domain-5.2Key Distribution and Injection0
Domain-5.3Key Storage0
Domain-5.4Key Usage and Cryptoperiods0
Domain-5.5Key Destruction0
Domain-6.1P2PE Solution Documentation0
Domain-6.2Annual Reassessment and Change Management0
Domain-6.3Merchant Self-Assessment Support0
PCI-P2PE-01Information security program management0
PCI-P2PE-02Board and management oversight0
PCI-P2PE-03Risk appetite and tolerance for IT risk0
PCI-P2PE-04Security policy framework0
PCI-P2PE-05Roles and responsibilities definition110
PCI-P2PE-06Network security and segmentation31
PCI-P2PE-07Endpoint protection and detection10
PCI-P2PE-08Application security controls26
PCI-P2PE-09Encryption and key management62
PCI-P2PE-10Secure configuration standards32
PCI-P2PE-11Business continuity planning and testing43
PCI-P2PE-12Disaster recovery procedures66
PCI-P2PE-13Third-party dependency management0
PCI-P2PE-14Critical service identification32
PCI-P2PE-15Communication and escalation procedures13
PCI-P2PE-16Due diligence and onboarding56
PCI-P2PE-17Contractual security requirements0
PCI-P2PE-18Ongoing monitoring and assessment55
PCI-P2PE-19Concentration risk management55
PCI-P2PE-20Exit strategy and transition planning0
PCI-P2PE-21Incident detection and classification72
PCI-P2PE-22Incident response and containment72
PCI-P2PE-23Regulatory reporting requirements0
PCI-P2PE-24Customer notification procedures0
PCI-P2PE-25Post-incident review and improvement72
1-2PCI P2PE 1-20
1-3PCI P2PE 1-30
1-4PCI P2PE 1-40
1-5PCI P2PE 1-50
10-1PCI P2PE 10-10
11-1PCI P2PE 11-10
11-2PCI P2PE 11-20
12-1PCI P2PE 12-10
12-2PCI P2PE 12-20
12-3PCI P2PE 12-30
12-4PCI P2PE 12-40
12-5PCI P2PE 12-50
12-6PCI P2PE 12-60
12-7PCI P2PE 12-70
12-8PCI P2PE 12-80
12-9PCI P2PE 12-90
13-1PCI P2PE 13-10
13-2PCI P2PE 13-20
13-3PCI P2PE 13-30
13-4PCI P2PE 13-40
13-5PCI P2PE 13-50
13-6PCI P2PE 13-60
13-7PCI P2PE 13-70
13-8PCI P2PE 13-80
13-9PCI P2PE 13-90
14-1PCI P2PE 14-10
14-2PCI P2PE 14-20
14-3PCI P2PE 14-30
14-4PCI P2PE 14-40
14-5PCI P2PE 14-50
15-1PCI P2PE 15-10
15-2PCI P2PE 15-20
15-3PCI P2PE 15-30
15-4PCI P2PE 15-40
15-5PCI P2PE 15-50
16-1PCI P2PE 16-10
16-2PCI P2PE 16-20
17-1PCI P2PE 17-10
18-1PCI P2PE 18-10
18-2PCI P2PE 18-20
18-3PCI P2PE 18-30
18-4PCI P2PE 18-40
18-5PCI P2PE 18-50
18-6PCI P2PE 18-60
18-7PCI P2PE 18-70
19-1PCI P2PE 19-10
19-10PCI P2PE 19-100
19-11PCI P2PE 19-110
19-12PCI P2PE 19-120
19-2PCI P2PE 19-20
19-3PCI P2PE 19-30
19-4PCI P2PE 19-40
19-5PCI P2PE 19-50
19-6PCI P2PE 19-60
19-7PCI P2PE 19-70
19-8PCI P2PE 19-80
19-9PCI P2PE 19-90
1A-1.1PCI P2PE 1A-1.10
1A-1.2PCI P2PE 1A-1.20
1A-1.3PCI P2PE 1A-1.30
1A-1.4PCI P2PE 1A-1.40
1A-2.1PCI P2PE 1A-2.10
1A-2.2PCI P2PE 1A-2.20
1B-1.1PCI P2PE 1B-1.10
1B-1.2PCI P2PE 1B-1.20
1B-2.1PCI P2PE 1B-2.10
1B-2.2PCI P2PE 1B-2.20
1B-2.3PCI P2PE 1B-2.30
1B-2.4PCI P2PE 1B-2.40
1B-2.5PCI P2PE 1B-2.50
1B-3.1PCI P2PE 1B-3.10
1B-3.2PCI P2PE 1B-3.20
1B-3.3PCI P2PE 1B-3.30
1B-3.4PCI P2PE 1B-3.40
1B-4.1PCI P2PE 1B-4.10
1B-5.1PCI P2PE 1B-5.10
1C-1.1PCI P2PE 1C-1.10
1C-2.1PCI P2PE 1C-2.10
1D-1.1PCI P2PE 1D-1.10
1D-1.2PCI P2PE 1D-1.20
1D-1.3PCI P2PE 1D-1.30
1D-2.1PCI P2PE 1D-2.10
1E-1.1PCI P2PE 1E-1.10
1E-1.2PCI P2PE 1E-1.20
20-1PCI P2PE 20-10
20-2PCI P2PE 20-20
20-3PCI P2PE 20-30
20-4PCI P2PE 20-40
20-5PCI P2PE 20-50
20-6PCI P2PE 20-60
21-1PCI P2PE 21-10
21-2PCI P2PE 21-20
21-3PCI P2PE 21-30
21-4PCI P2PE 21-40
22-1PCI P2PE 22-10
22-2PCI P2PE 22-20
22-3PCI P2PE 22-30
22-4PCI P2PE 22-40
22-5PCI P2PE 22-50
23-1PCI P2PE 23-10
23-2PCI P2PE 23-20
23-3PCI P2PE 23-30
24-1PCI P2PE 24-10
24-2PCI P2PE 24-20
25-1PCI P2PE 25-10
25-2PCI P2PE 25-20
25-3PCI P2PE 25-30
25-4PCI P2PE 25-40
25-5PCI P2PE 25-50
25-6PCI P2PE 25-60
25-7PCI P2PE 25-70
25-8PCI P2PE 25-80
26-1PCI P2PE 26-10
27-1PCI P2PE 27-10
27-2PCI P2PE 27-20
28-1PCI P2PE 28-10
28-2PCI P2PE 28-20
28-3PCI P2PE 28-30
28-4PCI P2PE 28-40
28-5PCI P2PE 28-50
29-1PCI P2PE 29-10
29-2PCI P2PE 29-20
29-3PCI P2PE 29-30
29-4PCI P2PE 29-40
29-5PCI P2PE 29-50
2A-1.1PCI P2PE 2A-1.10
2A-1.2PCI P2PE 2A-1.20
2A-2.1PCI P2PE 2A-2.10
2A-2.2PCI P2PE 2A-2.20
2A-2.3PCI P2PE 2A-2.30
2A-2.4PCI P2PE 2A-2.40
2A-3.1PCI P2PE 2A-3.10
2A-3.2PCI P2PE 2A-3.20
2A-3.3PCI P2PE 2A-3.30
2A-3.4PCI P2PE 2A-3.40
2B-1.1PCI P2PE 2B-1.10
2B-1.10PCI P2PE 2B-1.100
2B-1.11PCI P2PE 2B-1.110
2B-1.12PCI P2PE 2B-1.120
2B-1.13PCI P2PE 2B-1.130
2B-1.2PCI P2PE 2B-1.20
2B-1.3PCI P2PE 2B-1.30
2B-1.4PCI P2PE 2B-1.40
2B-1.5PCI P2PE 2B-1.50
2B-1.6PCI P2PE 2B-1.60
2B-1.7PCI P2PE 2B-1.70
2B-1.8PCI P2PE 2B-1.80
2B-1.9PCI P2PE 2B-1.90
2B-2.1PCI P2PE 2B-2.10
2B-2.2PCI P2PE 2B-2.20
2B-2.3PCI P2PE 2B-2.30
2B-2.4PCI P2PE 2B-2.40
2B-2.5PCI P2PE 2B-2.50
2B-2.6PCI P2PE 2B-2.60
2B-3.1PCI P2PE 2B-3.10
2B-4.1PCI P2PE 2B-4.10
2B-4.2PCI P2PE 2B-4.20
2C-1.1PCI P2PE 2C-1.10
2C-1.2PCI P2PE 2C-1.20
2C-2.1PCI P2PE 2C-2.10
2C-3.1PCI P2PE 2C-3.10
2C-3.2PCI P2PE 2C-3.20
30-3PCI P2PE 30-30
31-1PCI P2PE 31-10
32-1PCI P2PE 32-10
32-3PCI P2PE 32-30
32-4PCI P2PE 32-40
32-5PCI P2PE 32-50
32-6PCI P2PE 32-60
32-7PCI P2PE 32-70
32-8PCI P2PE 32-80
32-9PCI P2PE 32-90
33-1PCI P2PE 33-10
3A-1.1PCI P2PE 3A-1.10
3A-1.2PCI P2PE 3A-1.20
3A-1.3PCI P2PE 3A-1.30
3A-2.1PCI P2PE 3A-2.10
3A-2.2PCI P2PE 3A-2.20
3A-3.1PCI P2PE 3A-3.10
3A-3.2PCI P2PE 3A-3.20
3A-3.3PCI P2PE 3A-3.30
3A-3.4PCI P2PE 3A-3.40
3A-3.5PCI P2PE 3A-3.50
3B-1.1PCI P2PE 3B-1.10
3C-1.1PCI P2PE 3C-1.10
3C-1.2.1PCI P2PE 3C-1.2.10
4A-1.1PCI P2PE 4A-1.10
4B-1.1PCI P2PE 4B-1.10
4B-1.2PCI P2PE 4B-1.20
4B-1.3PCI P2PE 4B-1.30
4B-1.4PCI P2PE 4B-1.40
4B-1.5PCI P2PE 4B-1.50
4B-1.6PCI P2PE 4B-1.60
4B-1.7PCI P2PE 4B-1.70
4B-1.8PCI P2PE 4B-1.80
4B-1.9PCI P2PE 4B-1.90
4C-1.1PCI P2PE 4C-1.10
4C-1.2PCI P2PE 4C-1.20
4C-1.3PCI P2PE 4C-1.30
4C-1.4PCI P2PE 4C-1.40
4C-1.5PCI P2PE 4C-1.50
4D-1.1PCI P2PE 4D-1.10
4D-1.10PCI P2PE 4D-1.100
4D-1.11PCI P2PE 4D-1.110
4D-1.12PCI P2PE 4D-1.120
4D-1.13PCI P2PE 4D-1.130
4D-1.14PCI P2PE 4D-1.140
4D-1.2PCI P2PE 4D-1.20
4D-1.3PCI P2PE 4D-1.30
4D-1.4PCI P2PE 4D-1.40
4D-1.5PCI P2PE 4D-1.50
4D-1.6PCI P2PE 4D-1.60
4D-1.7PCI P2PE 4D-1.70
4D-1.8PCI P2PE 4D-1.80
4D-1.9PCI P2PE 4D-1.90
4D-2.1PCI P2PE 4D-2.10
4D-2.2PCI P2PE 4D-2.20
4D-2.3PCI P2PE 4D-2.30
4D-2.4PCI P2PE 4D-2.40
4D-2.5PCI P2PE 4D-2.50
4D-2.6PCI P2PE 4D-2.60
4D-2.7PCI P2PE 4D-2.70
4D-2.8PCI P2PE 4D-2.80
4D-2.9PCI P2PE 4D-2.90
4D-3.1PCI P2PE 4D-3.10
4D-3.2PCI P2PE 4D-3.20
4D-3.3PCI P2PE 4D-3.30
4D-3.4PCI P2PE 4D-3.40
4D-3.5PCI P2PE 4D-3.50
4D-3.6PCI P2PE 4D-3.60
4D-3.7PCI P2PE 4D-3.70
4D-4.1PCI P2PE 4D-4.10
4D-4.10PCI P2PE 4D-4.100
4D-4.11PCI P2PE 4D-4.110
4D-4.12PCI P2PE 4D-4.120
4D-4.13PCI P2PE 4D-4.130
4D-4.14PCI P2PE 4D-4.140
4D-4.15PCI P2PE 4D-4.150
4D-4.16PCI P2PE 4D-4.160
4D-4.17PCI P2PE 4D-4.170
4D-4.18PCI P2PE 4D-4.180
4D-4.19PCI P2PE 4D-4.190
4D-4.2PCI P2PE 4D-4.20
4D-4.20PCI P2PE 4D-4.200
4D-4.21PCI P2PE 4D-4.210
4D-4.3PCI P2PE 4D-4.30
4D-4.4PCI P2PE 4D-4.40
4D-4.5PCI P2PE 4D-4.50
4D-4.6PCI P2PE 4D-4.60
4D-4.7PCI P2PE 4D-4.70
4D-4.8PCI P2PE 4D-4.80
4D-4.9PCI P2PE 4D-4.90
4E-1.1PCI P2PE 4E-1.10
4E-1.2PCI P2PE 4E-1.20
5-1PCI P2PE 5-10
5A-1.1PCI P2PE 5A-1.10
5A-1.2PCI P2PE 5A-1.20
5A-1.3PCI P2PE 5A-1.30
5H-1.1PCI P2PE 5H-1.10
5H-1.2PCI P2PE 5H-1.20
5H-1.3PCI P2PE 5H-1.30
5H-1.4PCI P2PE 5H-1.40
5H-1.5PCI P2PE 5H-1.50
5I-1.1PCI P2PE 5I-1.10
6-1PCI P2PE 6-10
6-2PCI P2PE 6-20
6-3PCI P2PE 6-30
6-4PCI P2PE 6-40
6-5PCI P2PE 6-50
6-6PCI P2PE 6-60
7-1PCI P2PE 7-10
7-2PCI P2PE 7-20
8-1PCI P2PE 8-10
8-2PCI P2PE 8-20
8-3PCI P2PE 8-30
8-4PCI P2PE 8-40
9-1PCI P2PE 9-10
9-2PCI P2PE 9-20
9-3PCI P2PE 9-30
9-4PCI P2PE 9-40
9-5PCI P2PE 9-50
9-6PCI P2PE 9-60
CO-1Domain 5 Control Objective 1: Account data is processed using equipment and methodologies that ensure they are kept secure0
CO-2Domain 5 Control Objective 2: Cryptographic keys used for account-data encryption and decryption and related key management are created using processes that ensure it is not possib0
CO-3Domain 5 Control Objective 3: Keys are conveyed or transmitted in a secure manner0
CO-4Domain 5 Control Objective 4: Key loading to HSMs and POI devices is handled in a secure manner0
CO-5Domain 5 Control Objective 5: Keys are used in a manner that prevents or detects their unauthorized usage0
CO-6Domain 5 Control Objective 6: Keys are administered in a secure manner0
CO-7Domain 5 Control Objective 7: Equipment used to process account data and keys is managed in a secure manner0
D5-R1Domain 5 Requirement 10
D5-R10Domain 5 Requirement 100
D5-R11Domain 5 Requirement 110
D5-R12Domain 5 Requirement 120
D5-R13Domain 5 Requirement 130
D5-R14Domain 5 Requirement 140
D5-R15Domain 5 Requirement 150
D5-R16Domain 5 Requirement 160
D5-R17Domain 5 Requirement 170
D5-R18Domain 5 Requirement 180
D5-R19Domain 5 Requirement 190
D5-R20Domain 5 Requirement 200
D5-R21Domain 5 Requirement 210
D5-R22Domain 5 Requirement 220
D5-R23Domain 5 Requirement 230
D5-R24Domain 5 Requirement 240
D5-R25Domain 5 Requirement 250
D5-R26Domain 5 Requirement 260
D5-R27Domain 5 Requirement 270
D5-R28Domain 5 Requirement 280
D5-R29Domain 5 Requirement 290
D5-R30Domain 5 Requirement 300
D5-R31Domain 5 Requirement 310
D5-R32Domain 5 Requirement 320
D5-R33Domain 5 Requirement 330
D5-R5Domain 5 Requirement 50
D5-R6Domain 5 Requirement 60
D5-R7Domain 5 Requirement 70
D5-R8Domain 5 Requirement 80
D5-R9Domain 5 Requirement 90
DOMAIN-1Domain 1: Encryption Device and Application Management0
DOMAIN-2Domain 2: Application Security0
DOMAIN-3Domain 3: P2PE Solution Management0
DOMAIN-4Domain 4: Decryption Environment0
DOMAIN-5Domain 5: P2PE Cryptographic Key Operations and Device Management0
DOMAIN-MMAppendix A: Merchant-Managed Solutions (separation of encryption and decryption environments)0
MM-A-1.1PCI P2PE MM-A-1.10
MM-A-1.2PCI P2PE MM-A-1.20
MM-A-1.3PCI P2PE MM-A-1.30
MM-A-1.4PCI P2PE MM-A-1.40
MM-A-1.5PCI P2PE MM-A-1.50
MM-A-1.6PCI P2PE MM-A-1.60
MM-A-1.7PCI P2PE MM-A-1.70
MM-A-2.1PCI P2PE MM-A-2.10
MM-A-2.2PCI P2PE MM-A-2.20
MM-A-2.3PCI P2PE MM-A-2.30
MM-B-1.1PCI P2PE MM-B-1.10
MM-B-1.2PCI P2PE MM-B-1.20
MM-C-1.1PCI P2PE MM-C-1.10
PROGRAMMEThe P2PE Program: assessment by a P2PE QSA, the ROV and AOV, listing, and delta and designated changes0
REQ-1ARequirement 1A: Account data must be encrypted in equipment that is resistant to physical and logical compromise0
REQ-1BRequirement 1B: Secure logical access to POI devices0
REQ-1CRequirement 1C: Use applications that protect PAN and SAD0
REQ-1DRequirement 1D: Implement secure application-management processes0
REQ-1ERequirement 1E: Component providers only: report status to solution providers0
REQ-2ARequirement 2A: Protect PAN and SAD0
REQ-2BRequirement 2B: Develop and maintain secure applications0
REQ-2CRequirement 2C: Implement secure application-management processes0
REQ-3ARequirement 3A: P2PE solution management0
REQ-3BRequirement 3B: Third-party management0
REQ-3CRequirement 3C: Creation and maintenance of the P2PE Instruction Manual for merchants0
REQ-4ARequirement 4A: Use approved decryption devices0
REQ-4BRequirement 4B: Secure the decryption environment0
REQ-4CRequirement 4C: Monitor the decryption environment and respond to incidents0
REQ-4DRequirement 4D: Implement secure hybrid decryption process (hybrid decryption environments only)0
REQ-4ERequirement 4E: Component providers only: report status to solution providers0
REQ-5ARequirement 5A: Account data is processed using algorithms and methodologies that ensure they are kept secure0

Tell me when PCI P2PE files something new

One email when a public company newly discloses something this framework governs, naming the company and what our corpus says it puts in scope. Nothing else, and one click to stop.

What an auditor will ask you to produce

The artefacts named on the failure modes this framework speaks to.

  • TPSP register
  • AOC collection log
  • contractual responsibility matrix
  • monitoring cadence
  • vendor monitoring schedule
  • annual review reports
  • security charter
  • board reporting pack
  • risk register
  • policy library

How programmes fail on this

Failure modes named by this framework and others. Each opens the full record.

What this page is

A control-level reference for PCI P2PE, drawn from our framework corpus. Control codes and titles are references to the standard, not reproductions of it. The overlap counts and the auditor artefacts are our own work and are the part you will not find elsewhere.

Measure this against what you already run · All frameworks · Today's edition