Merchants Eye — Payments & Ecommerce News

Bluefin Expands AES Support to Enhance Cryptographic Agility in Payment Security

By Lauren Towner · 14 September 2026

Press Release: Bluefin Expands AES Support to Enhance Cryptographic Agility in Payment Security | Featured Image by FF News

Bluefin’s expansion of Advanced Encryption Standard (AES) support across its PCI-validated point-to-point encryption (P2PE) infrastructure marks a significant shift toward modernizing card-present security. For fintech professionals, this move provides the cryptographic agility necessary to defend against sophisticated threats while ensuring hardware investments remain viable as industry standards inevitably transition away from legacy encryption methods.

What was announced

The announcement centers on the broader availability of AES support within Bluefin’s P2PE infrastructure, specifically targeting environments utilizing PAX and ID TECH payment devices. While the payments sector has traditionally relied on Triple Data Encryption Standard (TDES) with Derived Unique Key Per Transaction (DUKPT) for securing card-present transactions, Bluefin is positioning AES as the necessary successor. AES provides a larger key space and greater cryptographic strength, offering a more robust defense than the aging TDES standard, which remains permitted under current PCI standards but is increasingly viewed as a legacy solution.

This expansion is designed for merchants, payment processors, and platform providers who require long-term security resilience. By integrating AES support now, Bluefin enables these organizations to adopt modern cryptography during routine technology refreshes and hardware deployments. This proactive approach bypasses the need for emergency migrations that often follow industry-wide mandates. The update specifically addresses the need for "cryptographic agility," allowing payment infrastructures to adapt to changing requirements and emerging risks, including the potential security challenges posed by the advent of quantum computing. The support is being rolled out across additional supported payment devices, ensuring that organizations can maintain high security standards across diverse physical payment environments without sacrificing flexibility.

"Bluefin is expanding AES support now so those environments can have the cryptographic agility built for today’s security requirements while maintaining the flexibility to adapt to future threats, including those posed by quantum computing."

Bluefin

The companies involved

Bluefin is a prominent player in the payment security space, specializing in encryption and tokenization technologies that protect sensitive data. The company has established a significant footprint in the market through its PCI-validated point-to-point encryption (P2PE) solutions, which are designed to devalue data and reduce the scope of PCI compliance for merchants. Bluefin’s reach extends across various sectors, including healthcare, higher education, and retail, where it provides secure payment processing through a wide network of partners.

The company’s technological evolution is reflected in its digital presence, which includes the integration of specialized payment platforms such as those found at tecs.at. This background has allowed Bluefin to offer a comprehensive suite of security products that bridge the gap between digital and in-person payments. By maintaining a focus on cryptographic standards and hardware-level security, Bluefin has positioned itself as a critical infrastructure provider for organizations that handle high volumes of card-present transactions. The company continues to operate as a key partner for major hardware manufacturers like PAX and ID TECH, ensuring that its security protocols are embedded within widely used payment terminals globally.

What FF News has reported before

FF News has closely followed Bluefin’s strategic partnerships and technical expansions over the past year. In August 2026, the publication covered how Bluefin and Visa Partner to Launch Unified Card-Present Payment Security Solution, a move that streamlined in-person payment security. Earlier that summer, the company’s hardware-focused initiatives were highlighted when Bluefin and LANDI Global Launch Direct-to-Processor P2PE for Smart Terminals.

The company has also demonstrated a strong presence in specialized sectors, as seen when Bluefin and PAX Technology Secure Patient Payments for Epic Wisdom Dental Environments. Additionally, FF News reported on the company’s efforts to bridge the physical and digital divide through a partnership with Basis Theory, as detailed in the report Bluefin and Basis Theory Partner to Enable Unified Tokenization Across Digital and In-Person Payments.

What this means

The shift from TDES to AES is no longer a theoretical upgrade but a practical necessity for the payment industry. By expanding AES support, Bluefin is addressing the growing obsolescence of legacy encryption standards that have dominated the card-present market for decades. This move puts pressure on other security providers to accelerate their own cryptographic transitions or risk leaving clients vulnerable to future decryption capabilities, particularly those associated with quantum computing. The industry is moving toward a state of "cryptographic agility," where the ability to swap encryption methods without replacing entire hardware fleets becomes a competitive advantage. This announcement highlights a broader trend: the proactive hardening of physical payment points against next-generation cyber threats.

Companies in this story: Bluefin

People in this story: Ruston Miles

More from News