Instruction Manual For PCI P2PE V3 - Shift4

Transcription

Instruction Manual for PCI P2PE v3.0

External Use - NDAShift4 P2PE PIM v3Shift4 Payments, LLC1551 Hillshire DriveLas Vegas, NV 891341. P2PE Solution Information and Solution Provider Contact Details1.1 P2PE Solution InformationSolution name:Shift4 P2PESolution reference number per PCI SSCwebsite:2020-00127.0021.2 Solution Provider Contact InformationCompany name:Shift4 Payments, LLC.Company address:1551 Hillshire Drive, Las Vegas, NV 89134Company URL:https://www.shift4.comContact name:Stephen AmesContact phone number:702.597.2480Contact e-mail address:pci@shift4.comP2PE and PCI DSSMerchants using this P2PE solution may be required to validate PCI DSS compliance and should be awareof their applicable PCI DSS requirements. Merchants should contact their acquirer or payment brands todetermine their PCI DSS validation requirements.P2PE Instruction Manual for PCI P2PE v3.0Copyright 2020 Shift4 Payments, LLC. All Rights ReservedApril 2020Universal Transaction Gateway (UTG ), 4Go , and i4Go are covered by one or more of the following U.S. Pat.Nos.: 7770789; 7841523; 7891563; 8328095; 8688589; 8690056; 9082120; 9256874Shift4 P2PE PIM v3 Page 2

External Use - NDAShift4 P2PE PIM v3Shift4 Payments, LLC1551 Hillshire DriveLas Vegas, NV 891342. Confirm Devices were not tampered with and confirm the identity of anythird-party personnel2.1 Instructions for ensuring POI devices originate from trusted sites/locations only.Shift4 and its partners take all necessary precautions to ensure devices are not tampered with orcompromised prior to being shipped to you. However, there are steps that you must undertake toensure that devices have not been tampered with during transit.First you must confirm that shipment of devices originated from one of the following True P2PE KeyInjection Facilities: IngenicoITSCO (IDTech)JR’s POS DepotPOS DataPOS PortalScanSourceShift4 Payments LLCSpencer TechnologiesTasq (FDC)The Phoenix GroupUnattended Card Payments Inc. (UCP)VerifoneIn order to remain compliant, you may only deploy POI devices that are shipped from one of theaforementioned PCI P2PE Component Solution Providers. Confirmation that devices were shippedfrom an authorized source may be performed by comparing the providers shipping information withthe information listed above.If you receive POI devices from another provider, you must contact us at PCI@Shift4.com forconfirmation. We will take necessary steps to communicate with you if our list of providers of POIdevices has changed.2.2 Instructions for confirming POI device and packaging were not tampered with, and forestablishing secure, confirmed communications with the solution provider.In addition to confirmation of shipping origination, you must confirm that neither the packaging northe device has been tampered with. All POI devices will be shipped using tamper-evidentpackaging. This packing will be evident on the shipping package itself and internally. Examples ofsaid packaging include: Sealed Tamper Evident Bags: like Tamper Evident Deposit Bags Tamper Evident Tape used on all seams of the boxYou must also inspect the device. You should look for broken security seals and cracks arounddevice’s seals to determine if the POI device itself has been compromised. If you believe theP2PE Instruction Manual for PCI P2PE v3.0Copyright 2020 Shift4 Payments, LLC. All Rights ReservedApril 2020Universal Transaction Gateway (UTG ), 4Go , and i4Go are covered by one or more of the following U.S. Pat.Nos.: 7770789; 7841523; 7891563; 8328095; 8688589; 8690056; 9082120; 9256874Shift4 P2PE PIM v3 Page 3

External Use - NDAShift4 P2PE PIM v3Shift4 Payments, LLC1551 Hillshire DriveLas Vegas, NV 89134packaging or the device has been tampered with, DO NOT deploy the device.Physically secure POI devices in your possession, including devices: Awaiting deploymentUndergoing repair or otherwise not in useWaiting transport between sites/locations2.3 Instructions to confirm the business need for, and identities of, any third-party personnelclaiming to be support or repair personnel, prior to granting those personnel access to POIdevices.Access to POI devices by third-party personnel for repair/maintenance must be monitored. Thismonitoring is required to ensure there is no unauthorized access to device that could result in tampering,theft, or substitution of the device. To ensure proper third-party access monitoring, you should have apolicy in place that requires the following steps:1) Maintenance/repair of the device must be pre-arranged with date and timeframe of third-partypersonnel defined. Unexpected visits for repair/maintenance must be verified. If they cannot beverified, access to the device must be denied;2) Prior to granting access to a device, personnel must be identified and authorized to access thedevice;3) Third-party personnel access must be recorded and include personnel name, company, time ofaccess, and purpose of access. Log must be maintained for no less than one year;4) Personnel must be escorted and observed at all times; and5) Personnel may not remove or replace a device without prior authorization. If authorized, newdevices must be properly inspected and inventoried.P2PE Instruction Manual for PCI P2PE v3.0Copyright 2020 Shift4 Payments, LLC. All Rights ReservedApril 2020Universal Transaction Gateway (UTG ), 4Go , and i4Go are covered by one or more of the following U.S. Pat.Nos.: 7770789; 7841523; 7891563; 8328095; 8688589; 8690056; 9082120; 9256874Shift4 P2PE PIM v3 Page 4

External Use - NDAShift4 P2PE PIM v3Shift4 Payments, LLC1551 Hillshire DriveLas Vegas, NV 891343. Approved POI Devices, Applications/Software, and the Merchant Inventory3.1 POI Device DetailsThe following information lists the details of the PCI-approved POI devices approved for use in this P2PEsolution.All POI device information can be verified by oved companies providers/approved pin transaction security.phpSee also Section 9.2, “Instructions for how to confirm hardware, firmware, and application versions on POIdevices.”PCI PTSapproval #:4-10144,POI devicevendor:POI device modelname and number:Hardware version #(s):Firmware version #(s):IDTechSecuREDIDSR-33x1xxxxx &IDSR-38xxxxxxSRED: 1.07, 1.08,2.00, V2.00, v2.014-10156IDTechSREDKeyIDSK-53XXXXXXXSRED: 1.014-90075IDTechSREDKey 280172001 (With MSR),80172002 (WithoutMSR)SREDKEY2 FWv1.00.xxx.xxxx.S4-10218IDTechAugusta SIDEM-8xxx, IDEM8xxxx, 80146001V1.00, x,ICMxxx-31TxxxxxSRED 310, iPP320,iPP350, xSRED (Non CTLS):820157V01.xx4-101844-301764-20142SRED (CTLS):820365 V02.xx,820305V02.xx,820528V02.xx SRED(Non CTLS):820375V01.xx820305 V11.xx (basefirmware), 820180V01.xx x4-30062P2PE Instruction Manual for PCI P2PE v3.0Copyright 2020 Shift4 Payments, LLC. All Rights ReservedSRED (Non CTLS):820157 V01.xxApril 2020Universal Transaction Gateway (UTG ), 4Go , and i4Go are covered by one or more of the following U.S. Pat.Nos.: 7770789; 7841523; 7891563; 8328095; 8688589; 8690056; 9082120; 9256874Shift4 P2PE PIM v3 Page 5

External Use - NDAShift4 P2PE PIM v3Shift4 Payments, LLC1551 Hillshire DriveLas Vegas, NV 891344-20133IngenicoiSC350ISC3xx-01TxxxxxSRED (Non CTLS) :820157V01.xx4-30098,IngenicoiSC480 TouchISC4xx-01Txxxxx (noCTLS), ISC4xx11Txxxxx (CTLS)SRED 1Txxxxx(already approvedhardware version),iMP3x2-01Txxxxx (newhardware version)SRED (Non CTLS) ithout contactless),IMP6xx-11Txxxxx BiUC15x-01Txxxxx820168 1.xx4-30075IngenicoiUP250IUP2xx-01TxxxxxSRED: 820528V02.xx4-20181IngenicoIWL220, IWL250IWL2xx-01TxxxxxSRED (NonCTLS):820528v02.xx4-30083IngenicoiUR250, iUR250PiUR2xx-01Txxxxx,iUR2xx-11TxxxxxSRED: .xx,820561v01.xx (basefirmware)4-20286IngenicoLane/5000LAN50AB (non CTLS),LAN50BB 03.xx(OpenProtocol)P2PE Instruction Manual for PCI P2PE v3.0Copyright 2020 Shift4 Payments, LLC. All Rights ReservedApril 2020Universal Transaction Gateway (UTG ), 4Go , and i4Go are covered by one or more of the following U.S. Pat.Nos.: 7770789; 7841523; 7891563; 8328095; 8688589; 8690056; 9082120; 9256874Shift4 P2PE PIM v3 Page 6

External Use - NDAShift4 P2PE PIM v3Shift4 Payments, LLC1551 Hillshire DriveLas Vegas, NV 891344-20303IngenicoLane/5000LAN51BA, LAN51CA,LAN51DA, LAN51EA(Non SRED)820376v01.xx (NonSRED),820547v01.xx,820549V01.xx,820556V01.xx (SREDOnGuard SDE),820559V01.xx (SREDANL), 820565v01.xx(SRED FF1)4-20324IngenicoLane/5000LAN51BA (single MSRhead), LAN51CA (dualMSR head), LAN51DA(single MSR head andcamera), LAN51EA(dual MSR head andcamera)820376v01.xx,820547v01.xx,820549v01.xx (SREDOnGuard FPE),820555v01.xx (SREDAWL), 820556v01.xx(SRED OnGuardSDE), 820559v01.xx(SRED ANL),820565v01.xx (SREDFF1), 820548V02.xx(Open oLane/7000LAN70AA, 00LAN80AA820547v01.xxP2PE Instruction Manual for PCI P2PE v3.0Copyright 2020 Shift4 Payments, LLC. All Rights ReservedApril 2020Universal Transaction Gateway (UTG ), 4Go , and i4Go are covered by one or more of the following U.S. Pat.Nos.: 7770789; 7841523; 7891563; 8328095; 8688589; 8690056; 9082120; 9256874Shift4 P2PE PIM v3 Page 7

External Use - NDAShift4 P2PE PIM v3Shift4 Payments, LLC1551 Hillshire DriveLas Vegas, NV 891344-30230IngenicoLink/2500LIN25AA, LIN25BA,LIN25CA, LIN25DA,LIN25EA; Touchscreenversion; no CTLSsupport, LIN25FA;Touchscreen version;with CTLS support,LIN25GA; Dual Headversion; no CTLSsupport, LIN25HA;Dual Head version;with CTLS support,LIN25IA (Companionversion with rearconnector and noCTLS support),LIN25JA (Companionversion with rearconnector and withCTLS)820547v01.xx,820555v01.xx (SREDAWL), 8(SRED OnGuard /2500LIN25AA (Basicversion no CTLSsupport), LIN25BA(Basic version withCTLS), LIN25CA(Companion version noCTLS support),LIN25DA (Companionversion with CTLS),LIN25EA (Touchversion no CTLSsupport), LIN25FA(Touch version withCTLS), LIN25GA (Dualhead version no CTLSsupport), LIN25HA(Dual head version withCTLS), LIN25IA(Companion versionwith rear connector andno CTLS support),LIN25JA (Companionversion with rearconnector and withCTLS)820547v01.xxP2PE Instruction Manual for PCI P2PE v3.0Copyright 2020 Shift4 Payments, LLC. All Rights ReservedApril 2020Universal Transaction Gateway (UTG ), 4Go , and i4Go are covered by one or more of the following U.S. Pat.Nos.: 7770789; 7841523; 7891563; 8328095; 8688589; 8690056; 9082120; 9256874Shift4 P2PE PIM v3 Page 8

External Use - NDAShift4 P2PE PIM v3Shift4 Payments, LLC1551 Hillshire DriveLas Vegas, NV 891344-20316IngenicoMove/5000(CTLS Privacyshield), (CTLS), (NonCTLS Privacyshield), (Non CTLS),MOV50AB, MOV50BB,MOV50CB, MOV50DB,MOV50JB (CTLS Privacy shield Desktop case lid)820376v01.xx,820547v01.xx,820549v01.xx (SREDOnGuard FPE),820555v01.xx(SRED),820556v01.xx (SREDOnGuard SDE),820559v01.xx (SREDANL), 820565v01.xx(SRED FF1),820548V02.xx 0MOV50AA (NonCTLS); MOV50BA(CTLS), MOV50AB,MOV50BB (CTLS),MOV50CA, MOV50CB,MOV50DA, MOV50DB(CTLS), MOV50JA(CTLS), MOV50JB(CTLS)820547v01.xx,820376v01.xx,(SRED) CTLS:820549V01.xx,820549v01.xx (SREDOnGuard FPE),820555v01.xx(SRED),820556v01.xx(SRED OnGuardSDE), 820559v01.xx(SRED ANL),820565v01.xx(SRED FF1)4-10110VerifoneMx925 / Mx915P132-509-01-R (MX925), P132-509-11-R(MX 925), P132-50921-R (MX 925), P132509-11-PF (MX 925),P132-409-01-R (MX915), P132-509-02-R(MX 925), P132-50912-R (MX 925), P132509-22-R (MX 925),P132-509-12-PF (MX925), P132-409-02-R(MX 915)SRED: 1.x.x, 3.x.x;4.x.x; 5.x.x, OP: 1.x.x,3.x.x; 4.x.x; 7.x.x,SRED 5.x.x.xxx4-10234Innowi, IncChecOut m11.01.10.1, 2.0.04-30287PAX ComputerTechnology(Shenzhen) CoLtdQ20, Q20 UQ20-xxx-Rx5-0xxx (w/CTLS), Q20-xxx-0x50xxx (w/o CTLS), Q20xxx-Rx5-1xxx (withCTLS), Q20-xxx-0x51xxx (without CTLS)15.00.xx xxxxP2PE Instruction Manual for PCI P2PE v3.0Copyright 2020 Shift4 Payments, LLC. All Rights ReservedApril 2020Universal Transaction Gateway (UTG ), 4Go , and i4Go are covered by one or more of the following U.S. Pat.Nos.: 7770789; 7841523; 7891563; 8328095; 8688589; 8690056; 9082120; 9256874Shift4 P2PE PIM v3 Page 9

External Use - NDAShift4 P2PE PIM v3Shift4 Payments, LLC1551 Hillshire DriveLas Vegas, NV 891344-40183PAX ComputerTechnology(Shenzhen) CoLtdA920A920-xxx-xx4-0xxx24.00.xxxx4-40215PAX ComputerTechnology(Shenzhen) CoLtdA920A920-xxx-0x5-0xxx,(Non CTLS), A920-xxxRx5-0xxx (CTLS),A920-xxx-0x5-1xxx,A920-xxx-Rx5-1xxx(CTLS), A920-xxx-0x52xxx, A920-xxx-Rx52xxx25.00.xxxx, 25.01.xxxx4-40187PAX ComputerTechnology(Shenzhen) CoLtdSP30SP30-xxx-2x4-0xxx,CTLS, SP30-xxx-0x40xxx4.00.xx4-40184PAX ComputerTechnology(Shenzhen) CoLtdS80S80-xxx-3x4-0xxx(CTLS support), S80xxx-0x4-0xxx (NonCTLS )4.00.xx, 4.01.xx4-30301PAX ComputerTechnology(Shenzhen) CoLtdA80A80-xxx-Rx5-0xxx(with CTLS), A80-xxx0x5-0xxx (withoutCTLS), A80-xxx-Rx51xxx (with CTLS), A80xxx-0x5-1xxx (withoutCTLS)25.00.xxxx, 25.01.xxxx4-30159PAX ComputerTechnology(Shenzhen) CoLtdS920, S920 2xxx,S920-xxx-xx4-AxxxProlin OS: 14.00.xx,Prolin Boot: 2.0.x,Prolin OS: 14.01.xxxxxx4-40188PAX ComputerTechnology(Shenzhen) CoLtdD220D220-xxx-xx4-0xxx14.00.xx xxxx4-30162PAX ComputerTechnology(Shenzhen) CoLtdPx5PX5-xxx-ax4-0xxx(a R CTLS support, 0no CTLS support)14.00.xx, Boot: 2.0.x,Firmware: 14.01.xxxxxx, Boot:3.0.xx.xxxx, Firmware:14.02.xx xxxxP2PE Instruction Manual for PCI P2PE v3.0Copyright 2020 Shift4 Payments, LLC. All Rights ReservedApril 2020Universal Transaction Gateway (UTG ), 4Go , and i4Go are covered by one or more of the following U.S. Pat.Nos.: 7770789; 7841523; 7891563; 8328095; 8688589; 8690056; 9082120; 9256874Shift4 P2PE PIM v3 Page 10

External Use - NDAShift4 P2PE PIM v3Shift4 Payments, LLC1551 Hillshire DriveLas Vegas, NV 891344-30297PAX ComputerTechnology(Shenzhen) CoLtdA930A930-xxx-Rx5-0xxx(with CTLS), A930-xxx0x5-0xxx (no CTLS),A930-xxx-Rx5-1xxx(with CTLS), A930-xxx0x5-1xxx (no CTLS)25.00.xxxx, 25.01.xxxx4-30224PAX ComputerTechnology(Shenzhen) CoLtdS300S300-xxx-0x4-0xxx(w/o CTLS), S300-xxx3x4-0xxx (with CTLS)14.01.xx xxxx4-40157PAX ComputerTechnology(Shenzhen) CoLtdD210D210-xxx-xx4-0xxx,D210-xxx-0x4-1xxx(Non CTLS), D210-xxx3x4-1xxx (CTLS)4.00.xx, 4.01.xx4-30163PAX ComputerTechnology(Shenzhen) CoLtdPx7PX7-xxx-ax4-0xxx(a R CTLS support; 0no CTLS support),PX7-xxx-ax4-1xxx(a R CTLS support; 0no CTLS support),PX7-xxx-Rx4-2xxxCTLS support, PX7xxx-0x4-2xxx no CTLSsupport14.00.xx, Boot: 2.0.x,14.01.xx xxxx, Boot:3.0.xx.xxxx, 14.02.xxxxxx3.2 POI Software/Application DetailsThe following information lists the details of all software/applications (both P2PE applications and P2PEnon-payment software) on POI devices used in this P2PE solution.All applications with access to clear-text account data must be reviewed according to Domain 2 and areincluded in the P2PE solution listing. These applications may also be optionally included in the PCI P2PElist of Validated P2PE Applications list at vendor or solution provider discretion.ApplicationVendor,Name, andVersion #Shift4,FormAgent,30250600POI DeviceVendorIDTechPOI DeviceModel Name(s)and Number:SecuREDPOI Device Hardware &Firmware Version #Hardware: IDSR33x1xxxxx & IDSR38xxxxxxIsApplication PCIListed?(Y/N)NDoesApplicationHave Accessto Clear-textAccountData (Y/N)NFirmware: SRED: 1.07,P2PE Instruction Manual for PCI P2PE v3.0Copyright 2020 Shift4 Payments, LLC. All Rights ReservedApril 2020Universal Transaction Gateway (UTG ), 4Go , and i4Go are covered by one or more of the following U.S. Pat.Nos.: 7770789; 7841523; 7891563; 8328095; 8688589; 8690056; 9082120; 9256874Shift4 P2PE PIM v3 Page 11

External Use - NDAShift4 P2PE PIM v3Shift4 Payments, LLC1551 Hillshire DriveLas Vegas, NV 891343.2 POI Software/Application Details1.08, 2.00, V2.00, ift4,FormAgent,30250600IngenicoSREDKeyHardware: IDSK53XXXXXXXNNNNNNNNNNFirmware: SRED: 1.01SREDKey2Hardware: 80172001(With MSR), 80172002(Without MSR)Firmware: SREDKEY2FW v1.00.xxx.xxxx.SAugusta SHardware:IDEM-8xxx,IDEM-8xxxx, 80146001Firmware: V1.00,V1.01.xxx.S, V1.02.xxx.S,V1.03.xxx.SiCMPHardware: ICMxxx01Txxxxx, ICMxxx11Txxxxx, ICMxxx21Txxxxx, ICMxxx31TxxxxxFirmware: SRED : IPP3xx01Txxxxx, IPP3xx11Txxxxx, iPP3xx21Txxxxx, iPP3xx31Txxxxx, iPP3xx41Txxxxx, iPP3xx51TxxxxxFirmware: SRED (NonCTLS) :820157V01.xx,SRED (CTLS): 820365V02.xx, 820305V02.xx,820528V02.xx SRED(Non CTLS):820375V01.xx, 820305V11.xx (base firmware),820180 V01.xx (basefirmware)P2PE Instruction Manual for PCI P2PE v3.0Copyright 2020 Shift4 Payments, LLC. All Rights ReservedApril 2020Universal Transaction Gateway (UTG ), 4Go , and i4Go are covered by one or more of the following U.S. Pat.Nos.: 7770789; 7841523; 7891563; 8328095; 8688589; 8690056; 9082120; 9256874Shift4 P2PE PIM v3 Page 12

External Use - NDAShift4 P2PE PIM v3Shift4 Payments, LLC1551 Hillshire DriveLas Vegas, NV 891343.2 POI Software/Application genicoiSC250Hardware: iSC2xx01TxxxxxNNNNNNNNNNNNNNFirmware: SRED (NonCTLS): 820157V01.xxiSC350Hardware: ISC3xx01TxxxxxFirmware: SRED (NonCTLS) : 820157V01.xxiSC480TouchHardware: ISC4xx01Txxxxx (no CTLS),ISC4xx-11Txxxxx(CTLS), ISC4xx01Txxxxx, ISC4xx11TxxxxxFirmware: SRED(CTLS): ardware: iMP3xx01Txxxxx, iMP3x001Txxxxx (alreadyapproved hardwareversion), iMP3x201Txxxxx (newhardware version)Firmware: SRED (NonCTLS) : Hardware: IMP6xx01Txxxxx (withoutcontactless), IMP6xx11Txxxxx dware: iUC15x01TxxxxxFirmware: 820168v01.xxiUC285Hardware: iUC28x01TxxxxxP2PE Instruction Manual for PCI P2PE v3.0Copyright 2020 Shift4 Payments, LLC. All Rights ReservedApril 2020Universal Transaction Gateway (UTG ), 4Go , and i4Go are covered by one or more of the following U.S. Pat.Nos.: 7770789; 7841523; 7891563; 8328095; 8688589; 8690056; 9082120; 9256874Shift4 P2PE PIM v3 Page 13

External Use - NDAShift4 P2PE PIM v3Shift4 Payments, LLC1551 Hillshire DriveLas Vegas, NV 891343.2 POI Software/Application ormAgent,30250600IngenicoiUP250Hardware: IUP2xx01TxxxxxNNNNNNNNNNFirmware: SRED:820528V02.xxIWL220,IWL250Hardware: IWL2xx01TxxxxxFirmware: SRED (NonCTLS):820528v02.xxiUR250,iUR250PHardware: iUR2xx01Txxxxx, iUR2xx11TxxxxxFirmware: SRED:820514V01.xxLane/3000,Desk/1500Hardware: LAN30AA,LAN30AN, LAN30BA,LAN30BN, LAN30CA,LAN30DA, LAN30EA,LAN30EN, LAN30FA,LAN30FN, LAN30GA,LAN30HAFirmware:820547v01.xx,820561v01.xx e/5000Hardware: LAN50AB(non CTLS), D)820548V01.xx (OpenProtocol),820548V02.xx (OpenProtocol),P2PE Instruction Manual for PCI P2PE v3.0Copyright 2020 Shift4 Payments, LLC. All Rights ReservedApril 2020Universal Transaction Gateway (UTG ), 4Go , and i4Go are covered by one or more of the following U.S. Pat.Nos.: 7770789; 7841523; 7891563; 8328095; 8688589; 8690056; 9082120; 9256874Shift4 P2PE PIM v3 Page 14

External Use - NDAShift4 P2PE PIM v3Shift4 Payments, LLC1551 Hillshire DriveLas Vegas, NV 891343.2 POI Software/Application Details820548V03.xx ft4,FormAgent,30250600IngenicoLane/5000Hardware: LAN51BA,LAN51CA, LAN51DA,LAN51EANNNNNNFirmware: (NonSRED) 820376v01.xx(Non SRED),820547v01.xx,820549V01.xx,820556V01.xx (SREDOnGuard SDE),820559V01.xx (SREDANL), 820565v01.xx(SRED FF1)Lane/5000Hardware: LAN51BA(single MSR head),LAN51CA (dual MSRhead), LAN51DA(single MSR head andcamera), LAN51EA(dual MSR head 9v01.xx (SREDOnGuard FPE),820555v01.xx (SREDAWL), 820556v01.xx(SRED OnGuardSDE), 820559v01.xx(SRED ANL),820565v01.xx (SREDFF1), 820548V02.xx(Open Protocol),820548v03.xx e/7000Hardware: LAN70AA,LAN70ABFirmware:820547v01.xxP2PE Instruction Manual for PCI P2PE v3.0Copyright 2020 Shift4 Payments, LLC. All Rights ReservedApril 2020Universal Transaction Gateway (UTG ), 4Go , and i4Go are covered by one or more of the following U.S. Pat.Nos.: 7770789; 7841523; 7891563; 8328095; 8688589; 8690056; 9082120; 9256874Shift4 P2PE PIM v3 Page 15

External Use - NDAShift4 P2PE PIM v3Shift4 Payments, LLC1551 Hillshire DriveLas Vegas, NV 891343.2 POI Software/Application genicoLane/7000Hardware: 820549v01.xx ardware: LAN80AAFirmware:820547v01.xxMove/5000Hardware: (CTLS Privacy shield),(CTLS), (Non CTLS Privacy shield), (NonCTLS), MOV50AB,MOV50BB,MOV50CB,MOV50DB, MOV50JB(CTLS Privacy shield Desktop case x (SREDOnGuard FPE),820555v01.xx (SRED),820556v01.xx (SREDOnGuard SDE),820559v01.xx (SREDANL), 820565v01.xx(SRED FF1),820548V02.xx 00IngenicoMove/5000Hardware: MOV50AA(Non CTLS);MOV50BA (CTLS),MOV50AB, MOV50BB(CTLS), MOV50CA,MOV50CB,MOV50DA,P2PE Instruction Manual for PCI P2PE v3.0Copyright 2020 Shift4 Payments, LLC. All Rights ReservedApril 2020Universal Transaction Gateway (UTG ), 4Go , and i4Go are covered by one or more of the following U.S. Pat.Nos.: 7770789; 7841523; 7891563; 8328095; 8688589; 8690056; 9082120; 9256874Shift4 P2PE PIM v3 Page 16

External Use - NDAShift4 P2PE PIM v3Shift4 Payments, LLC1551 Hillshire DriveLas Vegas, NV 891343.2 POI Software/Application DetailsMOV50DB (CTLS),MOV50JA (CTLS),MOV50JB (CTLS)Firmware:820547v01.xx,820376v01.xx, (SRED)CTLS: 820549V01.xx,820549v01.xx (SREDOnGuard FPE),820555v01.xx (SRED),820556v01.xx (SREDOnGuard SDE),820559v01.xx (SREDANL), 820565v01.xx(SRED ware: LIN25AA,LIN25BA, LIN25CA,LIN25DA, LIN25EA;Touchscreen version;no CTLS support,LIN25FA;Touchscreen version;with CTLS support,LIN25GA; Dual Headversion; no CTLSsupport, LIN25HA;Dual Head version;with CTLS support,LIN25IA (Companionversion with rearconnector and noCTLS support),LIN25JA (Companionversion with rearconnector and withCTLS)NNFirmware:820547v01.xx,820555v01.xx (SREDAWL), 820556v01.xx(SRED On-GuardSDE), 820376V01.xx,820549v01.xx (SRED),820548v02.xxP2PE Instruction Manual for PCI P2PE v3.0Copyright 2020 Shift4 Payments, LLC. All Rights ReservedApril 2020Universal Transaction Gateway (UTG ), 4Go , and i4Go are covered by one or more of the following U.S. Pat.Nos.: 7770789; 7841523; 7891563; 8328095; 8688589; 8690056; 9082120; 9256874Shift4 P2PE PIM v3 Page 17

External Use - NDAShift4 P2PE PIM v3Shift4 Payments, LLC1551 Hillshire DriveLas Vegas, NV 891343.2 POI Software/Application 600IngenicoLink/2500Hardware: LIN25AA(Basic version noCTLS support),LIN25BA (Basicversion with CTLS),LIN25CA (Companionversion no CTLSsupport), LIN25DA(Companion versionwith CTLS), LIN25EA(Touch version noCTLS support),LIN25FA (Touchversion with CTLS),LIN25GA (Dual headversion no CTLSsupport), LIN25HA(Dual head versionwith CTLS), LIN25IA(Companion versionwith rear connectorand no CTLS support),LIN25JA (Companionversion with rearconnector and ,30250600VeriFoneMx925 /Mx915Hardware version #(s):P132-509-01-R (MX925), P132-509-11-R(MX 925), P132-50921-R (MX 925), P132509-11-PF (MX 925),P132-409-01-R (MX915), P132-509-02-R(MX 925), P132-50912-R (MX 925), P132509-22-R (MX 925),P132-509-12-PF (MX925), P132-409-02-R(MX 915)P2PE Instruction Manual for PCI P2PE v3.0Copyright 2020 Shift4 Payments, LLC. All Rights ReservedApril 2020Universal Transaction Gateway (UTG ), 4Go , and i4Go are covered by one or more of the following U.S. Pat.Nos.: 7770789; 7841523; 7891563; 8328095; 8688589; 8690056; 9082120; 9256874Shift4 P2PE PIM v3 Page 18

External Use - NDAShift4 P2PE PIM v3Shift4 Payments, LLC1551 Hillshire DriveLas Vegas, NV 891343.2 POI Software/Application DetailsFirmware version #(s):SRED: 1.x.x, 3.x.x;4.x.x; 5.x.x, OP: 1.x.x,3.x.x; 4.x.x; 7.x.x,SRED ology(Shenzhen)Co LtdQ20Q20 UHardware: Q20-xxxRx5-0xxx (w/ CTLS),Q20-xxx-0x5-0xxx (w/oCTLS), Q20-xxx-Rx51xxx (with CTLS),Q20-xxx-0x5-1xxx(without nt,30250600PAXComputerTechnology(Shenzhen)Co LtdA920Hardware: A920-xxxxx4-0xxx, A920-xxx0x5-0xxx, (Non CTLS),A920-xxx-Rx5-0xxx(CTLS), A920-xxx-0x51xxx, A920-xxx-Rx51xxx (CTLS), A920xxx-0x5-2xxx, A920xxx-Rx5-2xxxFirmware: 24.00.xxxx,25.00.xxxx, nology(Shenzhen)Co ogy(Shenzhen)Co mAgent,30250600Hardware: SP30-xxx2x4-0xxx, CTLS,SP30-xxx-0x4-0xxxFirmware: 4.00.xxHardware: S80-xxx3x4-0xxx (CTLSsupport), S80-xxx-0x40xxx (Non CTLS )Firmware: 4.00.xx,4.01.xxHardware: A80-xxxRx5-0xxx (with CTLS),A80-xxx-0x5-0xxx(without CTLS), A80-P2PE Instruction Manual for PCI P2PE v3.0Copyright 2020 Shift4 Payments, LLC. All Rights ReservedApril 2020Universal Transaction Gateway (UTG ), 4Go , and i4Go are covered by one or more of the following U.S. Pat.Nos.: 7770789; 7841523; 7891563; 8328095; 8688589; 8690056; 9082120; 9256874Shift4 P2PE PIM v3 Page 19

External Use - NDAShift4 P2PE PIM v3Shift4 Payments, LLC1551 Hillshire DriveLas Vegas, NV 891343.2 POI Software/Application DetailsCo Ltdxxx-Rx5-1xxx (withCTLS), A80-xxx-0x51xxx (without CTLS)Firmware: omputerTechnology(Shenzhen)Co LtdS920S920 LHardware: S920-xxxxx4-0xxx, S920-xxxxx4-1xxx, S920-xxxxx4-2xxx, S920-xxxxx4-AxxxNNNNNNNNNNFirmware: Prolin OS:14.00.xx, Prolin Boot:2.0.x, Prolin OS:14.01.xx (Shenzhen)Co ogy(Shenzhen)Co LtdPx5PAXComputerTechnology(Shenzhen)Co LtdA930Shift4,FormAgent,30250600Hardware: D220-xxxxx4-0xxxFirmware: 14.00.xxxxxxHardware: PX5-xxxax4-0xxx (a R CTLSsupport, 0 no CTLSsupport)Firmware: 14.00.xx,Boot: 2.0.x, Firmware:14.01.xx xxxx, Boot:3.0.xx.xxxx, Firmware:14.02.xx xxxxHardware: A930-xxxRx5-0xxx (with CTLS),A930-xxx-0x5-0xxx (noCTLS), A930-xxx-Rx51xxx (with CTLS),A930-xxx-0x5-1xxx (noCTLS)Firmware: echnologyS300Hardware: S300-xxx0x4-0xxx (w/o CTLS),S300-xxx-3x4-0xxxP2PE Instruction Manual for PCI P2PE v3.0Copyright 2020 Shift4 Payments, LLC. All Rights ReservedApril 2020Universal Transaction Gateway (UTG ), 4Go , and i4Go are covered by one or more of the following U.S. Pat.Nos.: 7770789; 7841523; 7891563; 8328095; 8688589; 8690056; 9082120; 9256874Shift4 P2PE PIM v3 Page 20

External Use - NDAShift4 P2PE PIM v3Shift4 Payments, LLC1551 Hillshire DriveLas Vegas, NV 891343.2 POI Software/Application mAgent,30250600(Shenzhen)Co Ltd(with CTLS)Firmware: 14.01.xxxxxxPAXComputerTechnology(Shenzhen)Co LtdD210PAXComputerTechnology(Shenzhen)Co LtdPx7Hardware: S300-xxx0x4-0xxx (w/o CTLS),S300-xxx-3x4-0xxx(with CTLS)NNNNFirmware: 4.00.xx,4.01.xxHardware: PX7-xxxax4-0xxx (a R CTLSsupport; 0 no CTLSsupport), PX7-xxx-ax41xxx (a R CTLSsupport; 0 no CTLSsupport), PX7-xxxRx4-2xxx CTLSsupport, PX7-xxx-0x42xxx no CTLS supportFirmware: 14.00.xx,Boot: 2.0.x, 14.01.xxxxxx, Boot:3.0.xx.xxxx, 14.02.xxxxxx3.3 POI Inventory & Monitoring All POI devices must be documented via inventory control and monitoring procedures, includingdevice status (deployed, awaiting deployment, undergoing repair or otherwise not in use, or intransit). This inventory must be performed annually, at a minimum. Any variances in inventory, including missing or substituted POI devices, must be reported to Shift4Payments via the contact information in Section 1.2 above. Sample inventory table below is for illustrative purposes only. The actual inventory should becaptured and maintained by the merchant in an external document.In order for you to maintain your compliance you must maintain an inventory of the provided POI devices.You must track which devices are deployed, which are awaiting deployment, those that have beenremoved from service for repair or otherwise not in use, and those in transit for deployment or return forrepair. It is recommended that you designate a Job Role or personnel respo

Shift4 P2PE PIM v3 Page 2 1. P2PE Solution Information and Solution Provider Contact Details 1.1 P2PE Solution Information Solution name: Shift4 P2PE Solution reference number per PCI SSC website: 2020-00127.002 1.2 Solution Provider Contact Information Company name: Shift4 Payments, LLC. Company address: 1551 Hillshire Drive, Las Vegas, NV 89134