We use essential cookies to run this site. Analytics & marketing cookies load only with your consent — see our Cookie Policy and Privacy Policy.

PCI DSS v4.0.1 · Requirement 9 of 12

Requirement 9: Restrict Physical Access to Cardholder Data

The requirement people forget until the walkthrough: badge readers, visitor logs, media destruction — and for anyone operating card-present channels, the POI-device controls whose inspection logs assessors always ask to see.

Reviewed by Abhay Singh, PCI SSC-qualified QSA professional · CyberSigma is a PCI SSC-listed QSA company · Part of the Requirement 1–12 series

The controls that decide your assessment

9.2.1–9.2.4
Facility entry controls

Physical access to CDE areas is controlled and monitored — badge systems or equivalent, video or access-control mechanisms retained 90 days, console access in sensitive areas restricted.

9.3.1–9.3.4
Personnel and visitor authorisation

Physical access is authorised per role, revoked on termination; visitors are approved, escorted, identified and logged, with logs retained at least 90 days.

9.4.1–9.4.7
Media with cardholder data controlled

Physical media is secured, classified, sent only by trackable methods, approved for movement, stored securely and destroyed when no longer needed (cross-cut shred, incinerate, or secure-wipe).

9.5.1.1
POI device inventory

An up-to-date list of all point-of-interaction devices: make, model, location, serial number.

9.5.1.2
Periodic POI inspections

Devices are periodically inspected for tampering and substitution, at a frequency justified by targeted risk analysis (9.5.1.2.1).

9.5.1.3
Staff trained to spot tampering

Personnel in device environments are trained to verify technician identity, recognise tampering and report suspicious behaviour.

Control numbers reference PCI DSS v4.0.1 (June 2024). Verify wording against the standard itself — PCI SSC document library.

Where programmes actually fail

POI inspection "happens" but is not logged

Without dated inspection records per device, 9.5.1.2 fails — the log IS the control’s evidence.

Visitor logs with gaps

Missing sign-outs and unlogged escorts turn a formality into a finding; logs must survive a 90-day retention check.

No destruction certificates

Decommissioned drives and shredded documents need evidence — certificates of destruction or internal records with method and date.

Terminated staff badges active for weeks

9.3.1 requires prompt revocation; the assessor reconciles HR leaver lists against the badge system.

Evidence a QSA accepts

A policy document proves intent; configuration proves control. Bring these to the assessment:

  • Badge-system records and CCTV/access retention configuration (90 days)
  • Visitor logs sampled across the period
  • POI device inventory + dated inspection records + TRA for frequency
  • Media inventory, movement approvals and destruction certificates
  • Leaver reconciliation: HR list vs badge deactivation dates

Requirement 9 FAQ

How often must POS/POI devices be inspected?

At a frequency your targeted risk analysis defines and justifies (9.5.1.2.1) — daily for high-risk retail lanes, less often for controlled back-office devices, but always documented.

Do e-commerce-only merchants need Requirement 9?

The POI sections will be not-applicable, but facility, media and visitor controls still apply to offices and data centres that store or can access account data.

How long must visitor logs be kept?

At least 90 days (9.3.4), alongside 90-day retention for physical-access monitoring data.

← Requirement 8: Identity & AuthenticationRequirement 10: Logging & Monitoring

Requirement 9 in your environment

A PCI SSC-listed QSA firm can tell you in one session whether your controls will survive assessment — before the assessment.