An Introduction to P2PE Credit and debit cards are becoming increasingly popular methods of payment in South Africa, with consumers of all income levels finding them easier and more convenient than carrying cash. According to Euromonitor there are currently over 47 million debit and credit cards in circulation in South Africa, with an expectation of 35% growth over the next five years[1]. Retailers are therefore accepting an increasing number of credit and debit cards as a primary payment method, as more consumers begin using cards for everyday payments. In order to enjoy the benefits of these cards however, consumers must trust that they are safe and secure from fraud. The banks that issue these cards therefore have a responsibility to protect their cardholders. In order to do so banks require that all retailers be accredited with the Payment Card Industry Data Security Standard (PCI-DSS). This accreditation makes it very difficult for thieves to steal cardholder data and hack into their accounts, but attaining this approval is an extremely arduous task for the retailer. A new solution called Point-to-Point encryption (P2PE) has been developed that considerably reduces the burden of PCI-DSS for the retailer. This technology ensures that the cardholder’s account data is protected from the point that the card is swiped or inserted at the checkout, until the bank processes the transaction and returns the response to the checkout. This makes it impossible for thieves to capture any cardholder data during the transaction. According to the PCI Security Standards Council, PCI-compatible P2PE solutions must include all of the following elements:
- Secure encryption of payment card data at the point-of-interaction (POI)
- P2PE-validated applications at the point-of-interaction
- Secure management of encryption and decryption devices
- Management of the decryption environment and all decrypted account data
- Use of secure encryption methodologies and cryptographic key operations, including key generation, distribution, loading/injection, administration and usage
- Takes store almost completely out of scope for PCI compliance
- Valuable cardholder data is protected at all times
- Reduces PCI compliance costs significantly
- Helps maintain compliance with minimal effort
- No need for expensive VPN networks
- Account data is less valuable if stolen in a breach
- No costly scans, remediation and day-to-day management of the retail environment
- Allows retailer to focus on its core business
- ACI, who provide the software to process transactions
- Futurex, who provide the security Module to decrypt the data
- Verifone, who provide the secure Pinpad used to encrypt the data at source
- Sysnet, the QSA who guided Ecentric in terms of all the compliance steps and requirements
- ABSA, the bank with whom it listed its first ever P2PE solution
- TFG, the first retailer who availed its POS and technical teams to participate in this initiative

