Skip to content

SAQ P2PE walkthrough: validated point-to-point encryption

By Sam Rivera, Founder, SentinelPanda · June 3, 2026 · 3 min read · PCI DSS

SAQ P2PE is the shortest SAQ and the most attractive — but only if you use a PCI-listed P2PE solution. Self-built "encryption" does not qualify.

Who SAQ P2PE is for

SAQ P2PE applies to merchants using a PCI-listed P2PE solution to accept card payments, where cardholder data is encrypted at the point of interaction by tamper-resistant hardware and decrypted only by the P2PE provider. The merchant's environment never sees clear-text card data, by hardware design.

The phrase "PCI-listed" is critical. The PCI Council maintains an official list of validated P2PE solutions. A vendor saying "our terminals encrypt to the gateway" is not equivalent. Only solutions on the official list qualify the merchant for SAQ P2PE.

The eligibility checklist

  • You use a P2PE solution from the PCI Council's official Validated P2PE Solutions list.
  • All card acceptance goes through the listed P2PE solution.
  • You follow the solution's PCI P2PE Instructions for Use (PIM) — covering device handling, deployment, and operations.
  • You do not store cardholder data on any merchant system.
  • No e-commerce or any channel that does not use the listed P2PE solution.

The requirement subset

SAQ P2PE has about 35 control questions, concentrated in Req 3 (storage — minimal because there is none), Req 9 (physical security of the P2PE devices — this is the load-bearing block), and Req 12 (programme management). Most of the network and cryptography requirements are not applicable because clear-text data never enters the merchant environment.

The Req 9 controls around device handling are the centre of gravity: a documented inventory of every P2PE device with serial numbers and location, periodic inspection for tampering or substitution, training of personnel to identify tampering, and the deployment procedures from the solution's PIM.

Common SAQ P2PE pitfalls

  • Using a vendor's "encryption" or "tokenisation" that is not a PCI-listed P2PE solution — you cannot use SAQ P2PE.
  • Following the solution's PIM partially — for SAQ P2PE eligibility you must follow the PIM in full.
  • Storing card data on a back-office system "for chargeback handling" — disqualifies SAQ P2PE.
  • Mixed channels — operating both P2PE devices and another acceptance method (e.g., e-commerce) means you fill two SAQs or fall back to D.

A worked example

A retail chain uses a PCI-listed P2PE solution from its payment processor. Every terminal is recorded by serial number in a device inventory; staff inspect terminals daily for tampering signs; the solution's PIM is followed for receiving, deployment, decommissioning. The merchant has no other acceptance channel; no card data ever lives in merchant systems.

SAQ P2PE walks the Req 9 device controls in detail, the Req 12 programme, and the TPSP/P2PE-solution attestations. Total: 3-5 weeks first time, 1-2 weeks revalidation. Significantly shorter than SAQ C with comparable activity volume.

SAQ B-IP walkthrough Which PCI SAQ type applies to you?

Run your compliance program in one workspace.