---
title: "TEST Security: Are You Using Tested Products and Vendors?"
description: A sure way to improve payment card security during the holiday selling season is to use products and vendors that are tested and approved by the PCI Council.
image: https://blog.pcisecuritystandards.org/hubfs/tested-products.png
---

[< Return to Blog Home](https://blog.pcisecuritystandards.org) [Print](https://blog.pcisecuritystandards.org/using-tested-products-and-vendors#)

# [TEST Security: Are You Using Tested Products and Vendors?](https://blog.pcisecuritystandards.org/using-tested-products-and-vendors)

 Posted by [Laura K. Gray](https://blog.pcisecuritystandards.org/author/laura-k-gray) on 23 Dec, 2015 in [Small Business](https://blog.pcisecuritystandards.org/topic/small-business) and [P2PE Product Family](https://blog.pcisecuritystandards.org/topic/p2pe-product-family) and [Holidays](https://blog.pcisecuritystandards.org/topic/holidays) and [Vendors](https://blog.pcisecuritystandards.org/topic/vendors) and [QIR](https://blog.pcisecuritystandards.org/topic/qir) and [Remote Access](https://blog.pcisecuritystandards.org/topic/remote-access)

![tested-products.png](https://blog.pcisecuritystandards.org/hs-fs/hubfs/tested-products.png?width=800&name=tested-products.png "tested-products.png")

<https://www.linkedin.com/shareArticle?mini=true&url=https://blog.pcisecuritystandards.org/using-tested-products-and-vendors>

<https://www.facebook.com/share.php?u=https://blog.pcisecuritystandards.org/using-tested-products-and-vendors>

<https://twitter.com/intent/tweet?original_referer=https://blog.pcisecuritystandards.org/using-tested-products-and-vendors&url=https://blog.pcisecuritystandards.org/using-tested-products-and-vendors&source=tweetbutton&text=TEST%20Security:%20Are%20You%20Using%20Tested%20Products%20and%20Vendors> 

[mailto:?subject=Check%20out%20this%20article&body=https://blog.pcisecuritystandards.org/using-tested-products-and-vendors](mailto:?subject=Check%20out%20this%20article&body=https://blog.pcisecuritystandards.org/using-tested-products-and-vendors)

*Our [12 Days of Tips series](https://blog.pcisecuritystandards.org/act-now-black-friday-hacker-season) explores how small retailers can **ACT** **now** to repel data thieves during this prime shopping season.  **A**wareness, **C**hecking security controls and **T**esting security now will help your business lock down your systems during the holiday rush. *

*Merchants looking for more information on how to secure customer payment data should visit the    [PCI SSC merchant site](https://www.pcisecuritystandards.org/merchants/). *

**Are You Using Tested Products and Vendors?**

A sure way to improve payment card security during the holiday selling season is to use products and vendors that are tested and approved by the PCI Council. 

For a small merchant, two primary product types are the terminal equipment you use to accept payment cards, and the applications you use to process payments. A third product type is point-to-point encryption – an advanced technology solution that provides super-strong protection for cardholder data that is processed, transmitted or stored by merchants.

The PCI Council conducts programs for testing and validating all three product categories.

The Council also conducts training and qualification programs for the people and companies that install these solutions in retail stores like yours. 

Here are four places on the PCI Council website to get information about tested products and vendors.

1. **Terminal Equipment.** Validated PIN Transaction Security (PTS) devices are used by a merchant at the point-of-interaction for capturing payment card data and validating approval of its use for a transaction. For a list, see: [https://www.pcisecuritystandards.org/approved_companies_providers/approved_pin_transaction_security.php](https://www.pcisecuritystandards.org/approved_companies_providers/approved_pin_transaction_security.php) 

2. **Payment Applications**. Validated payment applications are used by merchants to process electronic payments. For a list, see: [https://www.pcisecuritystandards.org/program-listings-overview/](https://www.pcisecuritystandards.org/program-listings-overview/) 

3. **Point-to-Point Encryption**. Validated P2PE solutions and applications may simplify PCI compliance programs by eliminating clear-text cardholder data from the payment processing environment and reducing the scope of PCI Data Security Standard requirements. 

- For a list of validated P2PE solutions, see: [https://listings.pcisecuritystandards.org/assessors_and_solutions/point_to_point_encryption_solutions](https://listings.pcisecuritystandards.org/assessors_and_solutions/point_to_point_encryption_solutions) 
- For a list of validated P2PE applications, see: [https://listings.pcisecuritystandards.org/assessors_and_solutions/point_to_point_encryption_applications](https://listings.pcisecuritystandards.org/assessors_and_solutions/point_to_point_encryption_applications) 
- Get started with P2PE with this merchant guide: [https://www.pcisecuritystandards.org/documents/P2PE_Solutions_for_Merchants_v2.pdf](https://www.pcisecuritystandards.org/documents/P2PE_Solutions_for_Merchants_v2.pdf)

4. **Qualified Integrators and Resellers**. These are professionals of qualifying organizations with training and qualification on the secure installation of Payment Application Data Security Standard (PA-DSS) validated payment applications. For a list, see: [https://listings.pcisecuritystandards.org/assessors_and_solutions/qualified_integrators_and_resellers](https://listings.pcisecuritystandards.org/assessors_and_solutions/qualified_integrators_and_resellers) 

To learn more about how using tested products and vendors improves payment card security, visit the PCI SSC [website](https://www.pcisecuritystandards.org/pci_security/maintaining_payment_security).

Merchants looking for more information on payment security essentials should start here:

[![Payment Security Essentials for Merchants](https://no-cache.hubspot.com/cta/default/281302/07b993b4-2ba8-4a34-8bf5-afbb43bca162.png)](https://cta-redirect.hubspot.com/cta/redirect/281302/07b993b4-2ba8-4a34-8bf5-afbb43bca162) 

 

### LIKE WHAT YOU READ?

Subscribe to the PCI Perspectives blog to receive insights, information and practical resources to help your organization protect payment data.

[Subscribe Here](https://training.pcisecuritystandards.org/subscribe-to-pci-perspectives-blog)

![Laura K. Gray](https://blog.pcisecuritystandards.org/hubfs/Headshots/laura-gray.jpg)

[ Laura K. Gray ](https://blog.pcisecuritystandards.org/author/laura-k-gray)

[Twitter ](https://www.twitter.com/pcissc) [Email](mailto:blog@pcisecuritystandards.org) [Website](http://www.pcisecuritystandards.org)

 The PCI Security Standards Council (PCI SSC) is a global forum that brings together payments industry stakeholders to develop and drive adoption of data security standards and resources for safe payments worldwide.

[< Return to Blog Home](https://blog.pcisecuritystandards.org) [Print](https://blog.pcisecuritystandards.org/using-tested-products-and-vendors#)