Which SAQ would apply to a merchant using end-to-end encryption with PCI PTS POI devices and IP network communication?

Prepare for the PCI Approved Scanning Vendor (ASV) Test. Study with flashcards, multiple choice questions, hints, and explanations. Get exam ready!

Multiple Choice

Which SAQ would apply to a merchant using end-to-end encryption with PCI PTS POI devices and IP network communication?

Explanation:
End-to-end encryption with PCI PTS POI devices and an IP network means card data is encrypted at the moment of capture and never exposed in clear on the merchant’s systems—the data path from capture to the processor stays encrypted. That deployment aligns with SAQ B-IP, which covers merchants using standalone PCI-PTS approved POI devices connected over an IP network and that do not store cardholder data on the merchant’s systems. If you were using a fully validated P2PE solution that removes all merchant scope, SAQ P2PE would apply, but with the described setup, SAQ B-IP is the appropriate fit. SAQ C would apply if a payment application on the merchant network handled card data, and SAQ A-EP is for certain hosted e-commerce/payment-page scenarios, not this POS/IP device scenario.

End-to-end encryption with PCI PTS POI devices and an IP network means card data is encrypted at the moment of capture and never exposed in clear on the merchant’s systems—the data path from capture to the processor stays encrypted. That deployment aligns with SAQ B-IP, which covers merchants using standalone PCI-PTS approved POI devices connected over an IP network and that do not store cardholder data on the merchant’s systems. If you were using a fully validated P2PE solution that removes all merchant scope, SAQ P2PE would apply, but with the described setup, SAQ B-IP is the appropriate fit. SAQ C would apply if a payment application on the merchant network handled card data, and SAQ A-EP is for certain hosted e-commerce/payment-page scenarios, not this POS/IP device scenario.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy