Services
Services
SOC & Attestations
SOC & Attestations
Payment Card Assessments
Payment Card Assessments
ISO Certifications
ISO Certifications
Privacy Assessments
Privacy Assessments
Federal Assessments
Federal Assessments
Healthcare Assessments
Healthcare Assessments
Penetration Testing
Penetration Testing
Cybersecurity Assessments
Cybersecurity Assessments
Crypto and Digital Trust
Crypto and Digital Trust
Schellman Training
Schellman Training
Industry Solutions
Industry Solutions
Cloud Computing & Data Centers
Cloud Computing & Data Centers
Financial Services & Fintech
Financial Services & Fintech
Healthcare
Healthcare
Payment Card Processing
Payment Card Processing
US Government
US Government
Learning Center
Learning Center
Articles
Articles
Whitepapers
Whitepapers
Case Studies
Case Studies
Events & Live Webinars
Events & Live Webinars
On-Demand Webinars
On-Demand Webinars
About Us
About Us
Leadership Team
Leadership Team
Careers
Careers
Corporate Social Responsibility
Corporate Social Responsibility

Schellman Adds PCI Point-to-Point Encryption (P2PE) Assessment Services

News | Payment Card Industry (PCI) Data Security

Via MarketWired

TAMPA, FL— May 21, 2015- Schellman & Company, Inc., a leading provider of compliance services, is now a Point to Point Encryption (P2PE) QSA company. The new service builds upon Schellman’s deep security expertise making it the only firm in the world that can offer a comprehensive suite of PCI , SOC 2, FedRAMP, and ISO 27001 assessments.

The PCI P2PE standard allows solution providers to offer merchants a secure payment acceptance channel. The P2PE solutions utilize secure and validated cryptographic hardware devices along with rigorous security practices to encrypt data from the point of interaction (POI), usually a card swipe or read, until the data reaches the its secure decryption environment. As these solutions have the potential to keep unencrypted credit card numbers out of merchant and service provider environment, it may allow for reducing scope to the physical and operational security controls of those encryption devices.

A PCI P2PE assessment includes a thorough assessment of the device management practices for the POIs and other cryptographic devices, the use of hardware security modules (HSMs) for key management and decryption, and the security controls for key management, key injection, and security operations for the decryption environment. A validated solution demonstrates to merchants that the solution provider has implemented effective controls and that the merchant may reduce their scope with confidence in the defenses to prevent device tampering or substitution or attacks against the Solution Provider itself. The PCI Security Standards Council (SSC) only recognizes validated P2PE solutions for scope reduction.

Jacob Ansari, Schellman’s PA-DSS and P2PE practice lead:

“PCI P2PE represents the most stringent set of controls while offering the potential for significant scope reduction for merchants... Schellman is pleased to be able to complement our existing PCI DSS, PA-DSS, and other security and compliance offerings with P2PE validation.”

Inquiries for P2PE services can be made with Schellman at 1-866-254-0000, or by submitting a request for a professional consultation at www.schellmanco.com/contact-us

About Schellman

Schellman is a leading provider of attestation and compliance services. We are the only company in the world that is a CPA firm, a globally licensed PCI Qualified Security Assessor, an ISO Certification Body, HITRUST CSF Assessor, a FedRAMP 3PAO, and most recently, an APEC Accountability Agent. Renowned for expertise tempered by practical experience, Schellman's professionals provide superior client service balanced by steadfast independence. Our approach builds successful, long-term relationships and allows our clients to achieve multiple compliance objectives through a single third-party assessor.