Framework overlap

Does Annex 11 to EU GMP cover PCI P2PE?

You hold Annex 11 to EU GMP and have been told to do PCI P2PE. Here is how much overlaps, control by control.

34% of PCI P2PE you already have

Annex 11 to EU GMP already covers about 34% of PCI P2PE, leaving 29 of 44 controls as genuinely new work.

Already covered 10 Likely covered 5 New work 29

What is genuinely new work

Nothing in Annex 11 to EU GMP reaches these. This is the list to scope.

Annex-A
Symmetric Key Distribution Using Asymmetric Techniques
Annex-B
Key Injection Facility Requirements
Domain-1.1
POI Device Approval Status
Domain-1.2
Account Data Encryption at POI
Domain-1.3
POI Device Tampering Protection
Domain-2.1
POI Application Security
Domain-2.2
POI Device Authentication
Domain-3.1
POI Device Management
Domain-3.2
Merchant POI Device Deployment
Domain-4.1
Decryption Environment Logical Security
Domain-4.2
Decryption Environment Physical Security
Domain-5.1
Key Generation
Domain-5.2
Key Distribution and Injection
Domain-5.3
Key Storage
Domain-5.4
Key Usage and Cryptoperiods
Domain-5.5
Key Destruction
Domain-6.1
P2PE Solution Documentation
Domain-6.2
Annual Reassessment and Change Management
Domain-6.3
Merchant Self-Assessment Support
PCI-P2PE-01
Information security program management
PCI-P2PE-02
Board and management oversight
PCI-P2PE-03
Risk appetite and tolerance for IT risk
PCI-P2PE-04
Security policy framework
PCI-P2PE-13
Third-party dependency management
PCI-P2PE-15
Communication and escalation procedures
PCI-P2PE-17
Contractual security requirements
PCI-P2PE-20
Exit strategy and transition planning
PCI-P2PE-23
Regulatory reporting requirements
PCI-P2PE-24
Customer notification procedures
Show the 15 you already have
PCI-P2PE-05
Roles and responsibilities definition
PCI-P2PE-10
Secure configuration standards
PCI-P2PE-11
Business continuity planning and testing
PCI-P2PE-12
Disaster recovery procedures
PCI-P2PE-16
Due diligence and onboarding
PCI-P2PE-18
Ongoing monitoring and assessment
PCI-P2PE-19
Concentration risk management
PCI-P2PE-21
Incident detection and classification
PCI-P2PE-22
Incident response and containment
PCI-P2PE-25
Post-incident review and improvement
PCI-P2PE-06
Network security and segmentation
PCI-P2PE-07
Endpoint protection and detection
PCI-P2PE-08
Application security controls
PCI-P2PE-09
Encryption and key management
PCI-P2PE-14
Critical service identification

How this is calculated

Already covered means a mapping runs from a control in Annex 11 to EU GMP to that control. Likely covered means no direct mapping exists but both frameworks map to the same control in a third standard. New work means neither. We keep those separate rather than adding them into one friendlier number, because blending them would present a two-hop inference as a verified fact.

Coverage is not symmetric. Run it the other way and you will get a different number; both are correct.

From 332,959 cross-framework control mappings across 723 frameworks, 531 of them verified against their source documents. It does not tell you that you are compliant: a mapped control means the two standards ask for the same thing, not that you have done it.

Try another pair ยท Today's edition