Acceptable PCI Environments at Harvard
Harvard University supports a limited number of approved PCI environments. Each department that accepts credit card payments must operate within one of these environments.
SAQ A — Ecommerce / Online Payments
For departments that accept payments online using a PCI-compliant third-party provider.
- All cardholder data is handled by the service provider (fully outsourced)
- No cardholder data is processed, transmitted or stored on merchant systems
- Does not apply to face-to-face merchants
SAQ P2PE — Point-to-Point Encryption Devices
For departments using an approved P2PE (Point-to-Point Encryption) solution.
- The P2PE system is the only system that processes cardholder data
- Cardholder data may only be stored on paper
- Departments must implement and follow all controls in the P2PE Instruction Manual (PIM)
- The solution must be approved by the PCI Security Standards Council (PCI SSC)
SAQ B — Stand-Alone Terminals
For departments using stand-alone payment terminals with no electronic storage of cardholder data.
- Dial-up or cellular-connected devices
- No electronic storage of cardholder data
Note: SAQ B devices are limited due to the discontinuation of campus analog phone lines. No workshop is available for SAQ B.
Need Help?
If you are unsure which PCI environment applies to your department, please contact pci_compliance@harvard.edu.