Bluefin and Visa Acceptance Solutions announced a joint card-present acceptance offering on August 25, 2026. It combines transaction processing, point-to-point encryption (P2PE) validated by the PCI Security Standards Council, tokenization, and terminal lifecycle management in a single contract. The offering covers in-store payments, where the card is read by chip, contactless, or magnetic stripe, as opposed to remote transactions.
The press release spells out who does what. Bluefin supplies its P2PE solution, secure decryption services, a certified payment application, terminal integration, and P2PE Manager, its device management tool. Visa Acceptance Solutions provides payment processing, tokenization, and its global payment services. The offering is sold through Visa Acceptance Solutions and through Visa’s global sales and partner channels.
Validated P2PE shrinks a merchant’s PCI scope
In the words of the PCI Security Standards Council, a P2PE solution “cryptographically protects account data from the point where a merchant accepts the payment card to the secure point of decryption.” The council publishes the P2PE standard and keeps a list of validated solutions. The standard covers three elements: P2PE solutions, P2PE components, and the P2PE applications that run on them.
Validation matters because of what it does to compliance. According to the council, merchants that use a PCI-listed P2PE solution “have fewer applicable PCI Data Security Standard (PCI DSS) requirements, which helps simplify compliance efforts.” Card data leaves the terminal already encrypted, so the systems it passes through afterward no longer count as handling it in the clear. The scope of the audit shrinks accordingly.
Terminal management is usually a separate contract
A validated P2PE solution comes with obligations for the terminals themselves, from injecting cryptographic keys to tracking each device from the factory to the warehouse to the store. A merchant running several thousand terminals is constantly managing inventory, swaps, and a documented chain of custody. Bluefin’s P2PE Manager handles that work, which large organizations often buy from a vendor other than their acquirer.
The offering launches on certified Ingenico Lane series devices and is designed to expand to other certified device ecosystems. It targets retail, hospitality, petroleum, healthcare, and higher education.
| Component | Provided by |
|---|---|
| PCI-validated point-to-point encryption and secure decryption | Bluefin |
| Certified payment application and terminal integration | Bluefin |
| Device lifecycle management (P2PE Manager) | Bluefin |
| Transaction processing and global payment services | Visa Acceptance Solutions |
| Tokenization | Visa Acceptance Solutions |
Bluefin pitches one vendor instead of many
Large companies want “infrastructure that enables secure commerce” across channels, said Ruston Miles, Bluefin’s founder and chief strategy officer. “Enterprise organizations are no longer looking for individual payment technologies,” he said. Bluefin says it has more than 300 partners and 40,000 business customers, and that it protects more than $350 billion in transactions a year.
PYMNTS tied the announcement to its Global Digital Shopping Index, which found that payment acceptance influences the choice of merchant for 65% of US shoppers, up from 58% in January 2023. The share reaches 78% among consumers who say they use artificial intelligence when they shop.
Visa moves further into in-store acceptance
The deal extends a long-running push by Visa to sell acceptance services directly to merchants, which a card network has traditionally had no contract with. Visa bought the payment gateway CyberSource in July 2010 for about $2 billion, which made it a supplier to online merchants. Teaming up with a terminal security specialist takes that presence into in-store payments, where the network has been further from the point of sale.