P2PE Card Readers for PCI Certification

We're RAMP clients and have a very small staff. Nearly 50% of our staff are responsible for selling tickets and/or processing payments in some form or fashion in the course of a work week. Some of our staff workly remotely and as a presenting partner, all of our venues and our main ticket window are remote from our office location.

We're trying to figure out how to certify for PCI compliance and keep going around in circles with our out-sourced IT vendor, Vantiv, and Trustwave. The network segmentation required for PCI compliance seems impossible to us as everyone wears multiple hats and we can't figure out how they can do their "day jobs" AND be able to process payments when orders come in.

Our card readers (Verifone Vx805 units) are P2PE certified. However, we primarily type in credit card numbers using our keyboards since most payments are for card-not-present transactions. In the rare case where we have a card present transaction, we do use the card readers. We're trying to decide if we should implement ONLY card readers for credit card payments (no more typing in cc numbers) and thus complete the P2PE SAQ for PCI certification or if we should continue with our current practices and complete SAQ C for PCI certification.

If you've certified using the P2PE SAQ, what do you do to enforce using only card readers to enter credit card info (so staff can't use their keyboards to type in credit card info anymore)? If your card readers are P2PE approved devices and you still type credit card numbers in as well, did you certify for PCI compliance using SAQ C instead If you used SAQ C and have a distributed workforce with multiple responsibilities outside of taking payments, did you segment your network and if so, how?

Thanks,
Sara

  • Former Member
    Former Member $organization
    Hi Sara, Wouldn't it be nice, if Tessitura application automatically turned off the computer keyboard, when credit card info is being keyed in? I am not familiar with VeriFone Vx805's, so can your staff enter credit card info by either the keypads of Vx805's or the keyboards of cour computers? If that is the case, yes the keyboard presents a vulnerability, but I wonder if you can claim a Compensating Control by demonstrating that this issue is covered in your use policies, and your staff is sufficiently trained not to use the keyboard. Is it safe to assume that you are using triPOS to connect your Vx805's to your computers and that Vantiv is your acquirer? If that is the case, I believe TriPOS with Vx805 is already certified, when Vantiv is your acquirer, and you should not have any other issues. Those of us, who cannot use Vantiv as acquirer, are still waiting for Vantiv to certify our payment processor/acquirer. This may be a good Open Space Discussion topic in TLCC 2017. Best, Ahmet