PCI DSS 9.5.1: POI devices that capture payment card data via direct physical interaction with the payment

PCI DSS v4.0.1 control 9.5.1: the requirement in full, the 1 testing procedure an assessor uses to verify it, and the related controls in section 9.5.

Requirement 9: Restrict Physical Access to Cardholder Data › Section 9.5

POI devices that capture payment card data via direct physical interaction with the payment card form factor are protected from tampering and unauthorized substitution, including the following:

  • Maintaining a list of POI devices.
  • Periodically inspecting POI devices to look for tampering or unauthorized substitution.
  • Training personnel to be aware of suspicious behavior and to report tampering or unauthorized substitution of devices.

Summary

Know every card-reading device you have, look at them regularly for signs of tampering or swapping, and train the people near them to notice and report it.

What the assessor will examine

These are the testing procedures the standard defines for this control. They tell you what evidence to have ready.

Procedure
9.5.1 Examine documented policies and procedures to verify that processes are defined that include all elements specified in this requirement.

Three obligations in one control, and they are assessed together: the list, the inspections, and the training. The single procedure examines documented policies and procedures covering all three, and the related controls beneath it cover what the list must contain and how often you look. This is a physical-world control and it fails in physical-world ways: skimming overlays fitted to a terminal, a device swapped for a lookalike, or a technician nobody verified. Face-to-face merchants sometimes assume the outsourcing that took their e-commerce out of scope covers this too. It does not: the device in the shop is theirs.

What to prepare

  • The device list: make, model, serial number and location for every POI device.
  • Inspection records, dated, saying who looked and what they checked.
  • Training material and completion records for staff who work near the devices.
  • The procedure for verifying an engineer before letting them touch a terminal.

How to implement it

1. Photograph each device when you install it. The most practical inspection aid is a known-good picture, including the serial number and any seals. Tampering is much easier to see against a reference than from memory.

2. Fix the inspection to a routine that already happens. Opening or closing checks survive; a monthly reminder does not. What matters for the evidence is that the record exists and is dated.

3. Train for the social attack, not only the physical one. Most substitution starts with someone in a high-visibility vest saying they have come to service the terminal. The training that pays is a rule that nobody touches a device without a verified appointment.

4. Keep the list current when devices move. A device list that does not match what is on the counter turns every inspection record into a question about which device it covered.

Where this commonly fails

  • A list with models but no serial numbers, so substitution cannot be detected by inspection.
  • Inspections performed but never recorded, which leaves nothing for the assessor to examine.
  • Training given to the manager and not to the staff who actually stand at the terminal.
  • Unattended or customer-facing devices inspected less often than staffed ones, when they are the easier target.
  • Assuming a compliant payment provider covers the physical device the merchant owns and operates.

Others in section 9.5:

Control What it requires
9.5.1.1 An up-to-date list of POI devices is maintained…
9.5.1.2 POI device surfaces are periodically inspected to detect tampering and unauthorized substitution
9.5.1.3 Training is provided for personnel in POI environments to be aware of attempted tampering…

9.4.7 · All controls · 9.5.1.1

Source

The requirement text and testing procedures above are reproduced from PCI DSS v4.0.1 (June 2024), ©2006-2024 PCI Security Standards Council, LLC. All rights reserved. The commentary is our own.

The official standard is authoritative and also contains the Customized Approach Objective, applicability notes and guidance for this control. Download it from the PCI Security Standards Council document library. PCI DSS is a registered standard of the PCI Security Standards Council, LLC, which does not endorse this site. Nothing here is a substitute for advice from a Qualified Security Assessor.