Requirement 9: Restrict Physical Access to Cardholder Data
The requirement people forget until the walkthrough: badge readers, visitor logs, media destruction — and for anyone operating card-present channels, the POI-device controls whose inspection logs assessors always ask to see.
Reviewed by Abhay Singh, PCI SSC-qualified QSA professional · CyberSigma is a PCI SSC-listed QSA company · Part of the Requirement 1–12 series
The controls that decide your assessment
Control numbers reference PCI DSS v4.0.1 (June 2024). Verify wording against the standard itself — PCI SSC document library.
Where programmes actually fail
Without dated inspection records per device, 9.5.1.2 fails — the log IS the control’s evidence.
Missing sign-outs and unlogged escorts turn a formality into a finding; logs must survive a 90-day retention check.
Decommissioned drives and shredded documents need evidence — certificates of destruction or internal records with method and date.
9.3.1 requires prompt revocation; the assessor reconciles HR leaver lists against the badge system.
Evidence a QSA accepts
A policy document proves intent; configuration proves control. Bring these to the assessment:
- Badge-system records and CCTV/access retention configuration (90 days)
- Visitor logs sampled across the period
- POI device inventory + dated inspection records + TRA for frequency
- Media inventory, movement approvals and destruction certificates
- Leaver reconciliation: HR list vs badge deactivation dates
Requirement 9 FAQ
How often must POS/POI devices be inspected?
At a frequency your targeted risk analysis defines and justifies (9.5.1.2.1) — daily for high-risk retail lanes, less often for controlled back-office devices, but always documented.
Do e-commerce-only merchants need Requirement 9?
The POI sections will be not-applicable, but facility, media and visitor controls still apply to offices and data centres that store or can access account data.
How long must visitor logs be kept?
At least 90 days (9.3.4), alongside 90-day retention for physical-access monitoring data.
Requirement 9 in your environment
A PCI SSC-listed QSA firm can tell you in one session whether your controls will survive assessment — before the assessment.
