PCI DSS 9.5.1.2.1: How often you inspect each card reader, and what each inspection checks, are set in a targeted risk analysis, and the inspections you record have to match it.

PCI DSS v4.0.1 control 9.5.1.2.1: the requirement in full, the 2 testing procedures an assessor uses to verify it, and the related controls in section 9.5.

PCIComplianceHubLast updated Last reviewed against PCI DSS v4.0.1

Requirement 9: Restrict Physical Access to Cardholder Data › Section 9.5

The frequency of periodic POI device inspections and the type of inspections performed is defined in the entity’s targeted risk analysis, which is performed according to all elements specified in Requirement 12.3.1.

Summary

How often you inspect each card reader, and what each inspection checks, are set in a targeted risk analysis, and the inspections you record have to match it.

What the assessor will examine

These are the testing procedures the standard defines for this control. They tell you what evidence to have ready.

Procedure
9.5.1.2.1.a Examine the entity’s targeted risk analysis for the frequency of periodic POI device inspections and type of inspections performed to verify the risk analysis was performed in accordance with all elements specified in Requirement 12.3.1.
9.5.1.2.1.b Examine documented results of periodic device inspections and interview personnel to verify that the frequency and type of POI device inspections performed match what is defined in the entity’s targeted risk analysis conducted for this requirement.

The frequency and type behind 9.5.1.2, which says only that POI devices are inspected periodically. This control decides what periodically means and what an inspection looks at, through a targeted risk analysis performed according to all elements of 12.3.1. It is one of nine controls built on that pattern, alongside 5.2.3.1, 5.3.2.1, 7.2.5.1, 8.6.3, 10.4.2.1, 11.3.1.1, 11.6.1 and 12.10.4.1. Two procedures test it: 9.5.1.2.1.a examines the analysis for both the frequency and the type of inspection, and 9.5.1.2.1.b examines documented results of the inspections and interviews personnel, to check that what was done matches what the analysis defines. It was a best practice until 31 March 2025 and has been required since. The devices in scope are those of 9.5.1: card-present POI devices that read a card by swipe, tap or dip, not components used only for manual key entry or off-the-shelf phones and tablets.

What to prepare

  • The targeted risk analysis for POI inspections specifically, covering both how often and what each inspection checks.
  • Documented inspection results for every device at the frequency the analysis sets, which 9.5.1.2.1.b compares with it.
  • The device list from 9.5.1.1, so the analysis and the results can be matched device by device.
  • The review of the analysis at least once every 12 months that 12.3.1 requires.
  • The people who perform the inspections, available to be interviewed.

How to implement it

1. Let each device's location drive its frequency. The guidance suggests that devices left in public areas without supervision might be inspected more often than devices kept in secure areas or supervised when the public can reach them, so an analysis that sets one frequency for every device should say why.

2. Define the type as well as the frequency. The requirement covers both. A look at the casing and seals, a serial number compared with the device list, and a check for attached devices are different inspections, and the analysis should say which each device gets.

3. Start from the vendor's documentation. The guidance notes that many POI vendors say how often their devices should be checked and for what, and asks entities to fold those recommendations into their inspections.

4. Keep it with the other eight. One register of targeted risk analyses makes the 12-month review under 12.3.1 a single task.

Where this commonly fails

  • A frequency chosen without the analysis, which fails 9.5.1.2.1.a on the evidence.
  • An analysis that sets the frequency and says nothing about the type of inspection.
  • Inspections performed and not recorded, leaving 9.5.1.2.1.b nothing to compare with the analysis.
  • One frequency for every device, whether it sits unattended in a public area or behind the counter, with no reasoning for treating them alike.

This control refers to 12.3.1.

Others in section 9.5:

Control What it requires
9.5.1 POI devices that capture payment card data via direct physical interaction with the payment…
9.5.1.1 An up-to-date list of POI devices is maintained…
9.5.1.2 POI device surfaces are periodically inspected to detect tampering and unauthorized substitution
9.5.1.3 Training is provided for personnel in POI environments to be aware of attempted tampering…

← 9.5.1.2 · All controls · 9.5.1.3 →

Source

The requirement text and testing procedures above are reproduced from PCI DSS v4.0.1 (June 2024), ©2006-2024 PCI Security Standards Council, LLC. All rights reserved. The commentary is our own.

The official standard is authoritative and also contains the Customized Approach Objective, applicability notes and guidance for this control. Download it from the PCI Security Standards Council document library. PCI DSS is a registered standard of the PCI Security Standards Council, LLC, which does not endorse this site. Nothing here is a substitute for advice from a Qualified Security Assessor.