We use EMV card readers to automate the payments at the entry and exit to our services. These card readers and the unattended payment terminals are fully PTS complaint and use P2PE encryption. Also, implemented by PCI-DSS complaint service providers. These devices only transmit "Irreversible Hash" into our systems so as to calculate the charges based on entry and exit time stamps. We process more than 2 million transactions per year.
How far we ("the merchant") go in terms of scoping given that we have implemented the physical security requirements for these card readers and the firmware updates etc for the card readers can only done PCI-DSS compliant providers. All these devices are in a separate VLAN.
Going by PCI-DSS 3.2 requirements which talks about the "connected systems" - In our case although there is an internal system which is a connected system, the card readers never transmit clear text PAN out of them to our internal system. Could our internal system ruled out of scope as they talk to only the complaint card readers.
Having discussed with 2 different QSAs, they provide different opinions about how far we need to go with respect to the connect system. We know for sure there is no way that the EMV readers are going to transmit clear text PAN unless they are physically tampered with - For which we have physical controls in place.
We have also ensured that none of the refund processes will need a full text pan to be shared between the customer and the merchant
(or) all the connected systems (and their shared services like monitoring and logging systems) are in scope just because the EMV readers are in our (Merchants) network?
Will be great to know the opinion of the experts.
Cheers