NCR Counterpoint and PCI Compliance

Home » Categories » NCR Counterpoint

NCR Counterpoint and PCI Compliance

Summary:

NCR Counterpoint
The NCR Counterpoint application is PCI compliant and is listed on the PCI DSS site. Please note that although applications are listed with only 2 levels all versions are PCI compliant (for example, 8.3 is listed but all versions of 8.3 are compliant, e.g. 8.3.8, 8.3.9). 

Solution:

The AoC and CoC for Secure Pay can be found on the partner portal under Products / Data Security / PCI Compliance Status.

PCI P2PE Validation is an additional validation that allows merchants using validated PCI P2PE solutions to get an automatic reduction in scope, but it is not a requirement for PCI compliance.  NCR Secure Pay is not PCI P2PE Validated. This is TBD.

In parallel, NCR is also pursuing a white paper from our QSA to help facilitate a reduction in controls for Counterpoint merchants using Secure Pay P2PE. While the PCI P2PE validation provides “automatic” scope reduction, white papers have also been an effective technique to enable reduced PCI controls for non PCI P2PE solutions like Secure Pay. In fact, PCI recently introduced a new program for “Non listed P2PE encryption solutions” (NESA), because there are high number of P2PE payment solutions in situations similar to Secure Pay. Below is a link from CoalFire, our QSA, that explains the NESA Assessment: https://www.coalfire.com/The-Coalfire-Blog/December-2016/PCI-NESA-Non-Listed-Encrypted-Solution-Guidance. NCR is currently engaged with CoalFire to get that Assessment, in addition to laying out our more strategic path to true PCI P2PE validation.

 

 

 

 

 

Attachments Attachments
There are no attachments for this article.
Related Articles RSS Feed
Error: Counterpoint is running in Demo mode.
Viewed 1789 times since Wed, Jul 9, 2014
How to restrict workstations to a single instance of Counterpoint
Viewed 1817 times since Tue, Aug 1, 2017
Steps for End-of-Year processing in NCR Counterpoint
Viewed 1368 times since Mon, Sep 8, 2014
How to run a Problem Steps Recorder (PSR)
Viewed 1327 times since Thu, Oct 12, 2017
Practice Company limitations and functions
Viewed 1463 times since Wed, Sep 10, 2014