PCI Security Standards Council Bulletin: P2PE v3.2 Program Guide Update and New Secure Software v2.0 ROV Template for P2PE Applications Now Available
PCI Security Standards Council Bulletin: P2PE v3.2 Program Guide Update and New Secure
Software v2.0 ROV Template for P2PE Applications Now Available
1 July 2026
The PCI Security Standards Council (PCI SSC) has published an update to the P2PE v3. x Program
Guide with a new one-page Appendix J. This update establishes the criteria to allow P2PE Application
Assessors to assess P2PE Applications to the recently published Secure Software Standard v2.0.
To support this update, PCI SSC has introduced a new Secure Software Standard v2.0 ROV Template
exclusively for use by P2PE Application Assessors to assess P2PE Applications to Secure Software
Standard v2.0.
Note: This ROV template does not introduce any additional or new security requirements. It has unique
amendments for P2PE Applications, including:
• Disallowing support for non-SRED PTS POI devices
• Requiring use of the PTS POI device’s RNG
• Requiring Module A (account data) and Module B (POI devices) to be assessed.
As a reminder, all P2PE Application Assessors, which are also required to be Secure Software
Assessors, will need to complete the new Secure Software Standard v2.0 training to assess any software,
including P2PE Applications, to v2.0 of the Secure Software Standard.
The updated P2PE v3.2 Program Guide and new Secure Software Standard v2.0 ROV Template are now
available in the Document Library.
###