How to Complete Your P2PE Self-Assessment Questionnaire

Similar documents
Payment Card Industry (PCI) Data Security Standard

PDQ Guide for the PCI Data Security Standard Self-Assessment Questionnaire C (Version 1.2)

PCI COMPLIANCE IS NO LONGER OPTIONAL

Payment Card Industry (PCI) Data Security Standard

Merchant Guide to PCI DSS

Navigating the PCI DSS Challenge. 29 April 2011

Payment Card Industry (PCI) Data Security Standard

Section 1: Assessment Information

June 2013 PCI DSS COMPLIANCE GUIDE. Look out for the tips in the blue boxes if you use Fetch TM payment solutions.

Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire A and Attestation of Compliance

PCI DSS 3.2 AWARENESS NOVEMBER 2017

Webinar: How to keep your hotel guest data secure

PCI Compliance. Network Scanning. Getting Started Guide

PCI DSS COMPLIANCE 101

UC SAN DIEGO 2018 MERCHANT PCI DSS CYCLE

Advanced Certifications PA-DSS and P2PE. Erik Winkler, VP, ControlCase

GUIDE TO STAYING OUT OF PCI SCOPE

Evolution of Cyber Attacks

SAQ A AOC v3.2 Faria Systems LLC

Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire P2PE and Attestation of Compliance

Customer Compliance Portal. User Guide V2.0

Section 1: Assessment Information

Security Requirements and Assessment Procedures for EMV 3-D Secure Core Components: ACS, DS, and 3DS Server

Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire A and Attestation of Compliance

Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire P2PE and Attestation of Compliance

Understanding PCI DSS Compliance from an Acquirer s Perspective

PCI DSS. Compliance and Validation Guide VERSION PCI DSS. Compliance and Validation Guide

Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire B and Attestation of Compliance

Payment Card Industry (PCI) Data Security Standard

2012PHILIPPINES ECC International :: MALAYSIA :: VIETNAM :: INDONESIA :: INDIA :: CHINA

Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire A and Attestation of Compliance

FAQs. The Worldpay PCI Program. Help protect your business and your customers from data theft

Transactional Security Setup Guide

Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire A and Attestation of Compliance

Comodo HackerGuardian. PCI Security Compliance The Facts. What PCI security means for your business

Payment Card Industry Internal Security Assessor: Quick Reference V1.0

Donor Credit Card Security Policy

PCI DSS 3.1 is here. Are you ready? Mike Goldgof Sr. Director Product Marketing

Virtual Terminal User Guide

Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire A and Attestation of Compliance

June 2012 First Data PCI RAPID COMPLY SM Solution

Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire P2PE-HW and Attestation of Compliance

Payment Card Industry (PCI) Compliance

How to Take your Contact Centre Out of Scope for PCI DSS. Reducing Cost and Risk in Credit Card Transactions for Contact Centres

Self-Assessment Questionnaire A

User Guide. mpos Readers RP350x & RP457c Mobile Payment Acceptance User Guide for Android

Merchant Certificate of Compliance

Section 3.9 PCI DSS Information Security Policy Issued: November 2017 Replaces: June 2016

Merchant e-solutions Payment Acceptance User Guide for Magento (M1)

How PayPal can help colleges and universities reduce PCI DSS compliance scope. Prepared by PayPal and Sikich LLP.

Commerce PCI: A Four-Letter Word of E-Commerce

PCI DSS Q & A to get you started

Payment Card Industry (PCI) Data Security Standard

Payment Card Industry (PCI) Data Security Standard

Segmentation, Compensating Controls and P2PE Summary

The IT Search Company

Payment Card Industry (PCI) Qualified Integrator and Reseller (QIR)

Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire B and Attestation of Compliance

Processing Payments Securely in the Digital World

University of Sunderland Business Assurance PCI Security Policy

ethin Education Portal User Guide

PCI compliance the what and the why Executing through excellence

Best Practices (PDshop Security Tips)

Webinar Tokenization 101

Payment Card Industry (PCI) Data Security Standard

UCSB Audit and Advisory Services Internal Audit Report. Credit Cards PCI Compliance. July 1, 2016

PCI DSS v3. Justin

6 Vulnerabilities of the Retail Payment Ecosystem

University of Maine System Payment Card Industry Data Security Standard (PCI DSS) Guide for Completing Self Assessment Questionnaire (SAQ) SAQ C

IC L19 - Consolidate Information from across your Infrastructure to create a custom report for PCI DSS Hands-On Lab

Payment Card Acceptance - Exception Form

Payment Card Industry (PCI) Data Security Standard

Payment Card Industry - Data Security Standard (PCI-DSS)

PCI Compliance: It's Required, and It's Good for Your Business

Payment Card Industry (PCI) Data Security Standard

PCI DATA SECURITY STANDARDS VERSION 3.2. What's Next?

PCI Guidance Check-In Where are We Now? Diana

in PCI Regulated Environments

Merchant e-solutions Payment Acceptance User Guide for Magento version 2.x ( M2 )

PCI DSS Addressing Cyber-Security Threats. ETCAA June Gabriel Leperlier

First Data TransArmor VeriFone Edition Abbreviated Technical Assessment White Paper

Introduction to the PCI DSS: What Merchants Need to Know

Qualified Integrators and Resellers (QIR) TM. QIR Implementation Statement, v2.0

INSTRUCTIONS FOR COMPLETING YOUR FY15 SAQ S

Requirements & Potential Costs for SAQ D

Payment Card Industry (PCI) Data Security Standard

Payment Card Industry (PCI) Data Security Standard

Payment Card Industry (PCI) Data Security Standard

Payment Card Industry (PCI) Data Security Standard

Payment Card Industry (PCI) Point-to-Point Encryption

Payment Card Industry (PCI) Data Security Standard

ISACA Kansas City Chapter PCI Data Security Standard v2.0 Overview

The Devil is in the Details: The Secrets to Complying with PCI Requirements. Michelle Kaiser Bray Faegre Baker Daniels

Payment Card Industry Data Security Standards Version 1.1, September 2006

Payment Card Industry (PCI) Point-to-Point Encryption. Template for Report on Validation for use with P2PE v2.0 (Revision 1.1) for P2PE Solution

LiveEngage Secure Form. Document Version: 1.2 June 2018

Payment Card Industry (PCI) Data Security Standard

INFORMATION SUPPLEMENT. Use of SSL/Early TLS for POS POI Terminal Connections. Date: June 2018 Author: PCI Security Standards Council

TSSA PORTAL TRAINING GUIDE

PCI Data Security. Meeting the Challenges of PCI DSS Payment Card Security

Transcription:

How to Complete Your P2PE Self-Assessment Questionnaire Compliance with the Payment Card Industry Data Security Standards (PCI DSS) is one of the best ways to protect your business and your customers from a data breach. Our goal is to make compliance fast and easy. Because your credit card machine uses PCI-Validated Point-to-Point Encryption (P2PE), this process is even easier. P2PE is the most secure way to transfer data. Machines with P2PE encrypt sensitive card data as soon as a card is swiped, dipped, keyed or tapped (through contactless payments). From there, the data remains encrypted until it reaches Clearent s PCIcompliant data center. P2PE eliminates your exposure to sensitive information, significantly reducing your PCI scope. Because Clearent s P2PE solution is validated by the PCI Council, you no longer need to perform vulnerability scans and are eligible to take the shortest PCI questionnaire available the SAQ P2PE. Follow the steps below to take the P2PE questionnaire. 1. Log in to Compass Reporting Tool, Clearent s online reporting system. To access Compass, go to www.clearent.com and click on Client Login in the top right corner. 2. Click on the DataGuardian button on the left side of the page under Merchant Controls, as shown in the image on the right. 3. Verify that your information is correct. If you need to make changes, click on the Edit link on the right side of the screen. 4. Select the business type that best matches your company.

5. Confirm if your company has more than one third-party or merchant acquiring relationship. 6. Select the P2PE option. Next confirm if you store sensitive cardholder data electronically and accept chip cards. Check the box to agree to the site s terms and conditions and then hit Save & Continue. Note: If you are only using our P2PE solution for processing, then cardholder data is securely stored within our tokenized vault, and is NOT stored by you, the merchant. 7. You now need to provide the details for your P2PE solution. Click on the arrow on the right side of the P2PE Solution Provider field and scroll down to Clearent LLC. You can also type Clearent LLC directly into this field.

8. Once you select Clearent LLC the P2PE Solution and Reference Number fields will populate automatically. You now need to select your device. However, the narrow width of this field makes this tricky. We re working to change this, but in the meantime, put your cursor in the field and continue pressing the right arrow key until you can see the full name of the device. Once you locate your device, click on the row to note your selection and click Save. 9. If you are using more than one device, such as a PIN pad, you can add it by repeating this process as many times as necessary. 10. Once you have entered your device(s), click Save & Continue.

11. Check the box to confirm your eligibility to take the P2PE questionnaire. Then click Continue. 12. Click Start Questionnaire to begin. 13. Check the box to attest that you have read and adhere best practices for protecting cardholder data.

14. Check the box to attest that you have read and adhere best practices for restricting physical access to cardholder data. 15. Check the box to attest that you maintain an information security policy. (Sample security policies can be found in the Resources section.) 16. You will then be able to confirm your answers and see your results. Click Continue to proceed. 17. You must now electronically sign your questionnaire by entering your name, title and the last four digits of your Social Security Number. Click Submit to continue.

18. You will then be taken to an overview page where you can view, print and email copies of your answers, Attestation of Compliance and Certificate of Validation. Need More Information? If you need help completing your questionnaire, please contact our PCI Help Desk at 855.864.1732. If you need help accessing the DataGuardian portal within Compass, please contact Clearent Customer Support at 866.435.0666 or customersupport@clearent.com.