Acceptable PCI Environments at Harvard

Harvard University supports a limited number of approved PCI environments. Each department that accepts credit card payments must operate within one of these environments.  

SAQ A — Ecommerce / Online Payments  

For departments that accept payments online using a PCI-compliant third-party provider.  

  • All cardholder data is handled by the service provider (fully outsourced)
  • No cardholder data is processed, transmitted or stored on merchant systems  
  • Does not apply to face-to-face merchants  

SAQ P2PE — Point-to-Point Encryption Devices  

For departments using an approved P2PE (Point-to-Point Encryption) solution.

  • The P2PE system is the only system that processes cardholder data  
  • Cardholder data may only be stored on paper
  • Departments must implement and follow all controls in the P2PE Instruction Manual (PIM)  
  • The solution must be approved by the PCI Security Standards Council (PCI SSC)  

SAQ B — Stand-Alone Terminals  

For departments using stand-alone payment terminals with no electronic storage of cardholder data.  

  • Dial-up or cellular-connected devices  
  • No electronic storage of cardholder data  

Note: SAQ B devices are limited due to the discontinuation of campus analog phone lines. No workshop is available for SAQ B.

Need Help?

If you are unsure which PCI environment applies to your department, please contact pci_compliance@harvard.edu