#  Acceptable PCI Environments at Harvard 

 



 ##  

  expand\_more  

 
  

 

Harvard University supports a limited number of approved PCI environments. Each department that accepts credit card payments must operate within one of these environments.

## SAQ A — Ecommerce / Online Payments 

For departments that accept payments online using a PCI-compliant third-party provider.

- All cardholder data is handled by the service provider (fully outsourced)
- No cardholder data is processed, transmitted or stored on merchant systems
- Does not apply to face-to-face merchants

## SAQ P2PE — Point-to-Point Encryption Devices 

For departments using an approved **P2PE (Point-to-Point Encryption)** solution.

- The P2PE system is the only system that processes cardholder data
- Cardholder data may only be stored on paper
- Departments must implement and follow all controls in the P2PE Instruction Manual (PIM)
- The solution must be approved by the PCI Security Standards Council (PCI SSC)

## SAQ B — Stand-Alone Terminals 

For departments using stand-alone payment terminals with no electronic storage of cardholder data.

- Dial-up or cellular-connected devices
- No electronic storage of cardholder data

*Note: SAQ B devices are limited due to the discontinuation of campus analog phone lines. No workshop is available for SAQ B.*



 

##  Need Help? 

If you are unsure which PCI environment applies to your department, please contact [pci\_compliance@harvard.edu](mailto:pci_compliance@harvard.edu).