PCI DSS 9.4.7: Electronic media with cardholder data is destroyed when no longer needed for business or legal

PCI DSS v4.0.1 control 9.4.7: the requirement in full, the 2 testing procedures an assessor uses to verify it, and the related controls in section 9.4.

Requirement 9: Restrict Physical Access to Cardholder Data › Section 9.4

Electronic media with cardholder data is destroyed when no longer needed for business or legal reasons via one of the following:

  • The electronic media is destroyed.
  • The cardholder data is rendered unrecoverable so that it cannot be reconstructed.

Summary

When electronic media holding cardholder data is no longer needed, destroy it or make the data genuinely unrecoverable. Deleting is neither.

What the assessor will examine

These are the testing procedures the standard defines for this control. They tell you what evidence to have ready.

Procedure
9.4.7.a Examine the media destruction policy to verify that procedures are defined to destroy electronic media when no longer needed for business or legal reasons in accordance with all elements specified in this requirement.
9.4.7.b Observe the media destruction process and interview responsible personnel to verify that electronic media with cardholder data is destroyed via one of the methods specified in this requirement.

The electronic counterpart of 9.4.6, which covers hard copy. The standard offers two routes and you may take either: destroy the media, or render the data unrecoverable so that it cannot be reconstructed. That last phrase is the whole control. A delete removes a pointer, a quick format rewrites a table, and both leave data that ordinary recovery tools retrieve. Procedure 9.4.7.b observes the destruction process, so this is demonstrated rather than described. It is also the endpoint of 3.2.1: the retention policy decides when data is no longer needed, and this control is what happens next.

What to prepare

  • The media destruction policy, showing both the trigger and the accepted methods.
  • Certificates of destruction from any third party, itemised rather than by weight.
  • The process available to observe, or a scheduled destruction the assessor can attend.
  • The reconciliation against the inventory in 9.4.5.

How to implement it

1. Pick a method that matches the medium. Degaussing works on magnetic media and does nothing useful to an SSD. Flash needs a cryptographic erase or physical destruction, and using a tape-era method on a solid-state drive is the most common technical failure of this control.

2. Prefer encryption plus key destruction where the media is not in your hands. For cloud and managed storage, destroying the key is the practical route to "cannot be reconstructed", and it is auditable in a way that a provider's deletion is not.

3. Get itemised destruction certificates. A certificate recording a weight of shredded material cannot be reconciled to the serial numbers in your inventory, which is what an assessor will try to do.

4. Secure the queue. Media awaiting destruction is media still holding cardholder data, and it is usually in a box in a corridor. 9.4.6 says this explicitly for hard copy and the same exposure applies here.

Where this commonly fails

  • Deletion or reformatting treated as rendering data unrecoverable.
  • Degaussing applied to solid-state drives, which does not erase them.
  • Third-party destruction with no itemised certificate, so nothing ties the disposal to the inventory.
  • Cloud storage deleted through the console with no evidence beyond the console, when the control asks for a process that can be observed.
  • Drives held for months awaiting destruction in an area with no physical control.

Others in section 9.4:

Control What it requires
9.4.1 All media with cardholder data is physically secured
9.4.1.1 Offline media backups with cardholder data are stored in a secure location
9.4.1.2 The security of the offline media backup location(s) with cardholder data is reviewed at least…
9.4.2 All media with cardholder data is classified in accordance with the sensitivity of the data
9.4.3 Media with cardholder data sent outside the facility is secured…
9.4.4 Management approves all media with cardholder data that is moved outside the facility…
9.4.5 Inventory logs of all electronic media with cardholder data are maintained
9.4.5.1 Inventories of electronic media with cardholder data are conducted at least once every 12 months
9.4.6 Hard-copy materials with cardholder data are destroyed when no longer needed for business…

9.4.6 · All controls · 9.5.1

Source

The requirement text and testing procedures above are reproduced from PCI DSS v4.0.1 (June 2024), ©2006-2024 PCI Security Standards Council, LLC. All rights reserved. The commentary is our own.

The official standard is authoritative and also contains the Customized Approach Objective, applicability notes and guidance for this control. Download it from the PCI Security Standards Council document library. PCI DSS is a registered standard of the PCI Security Standards Council, LLC, which does not endorse this site. Nothing here is a substitute for advice from a Qualified Security Assessor.