Skip to content

PCI DSS Requirement 9: physical access

By Sam Rivera, Founder, SentinelPanda · August 6, 2026 · 2 min read · PCI DSS

Cloud-hosted teams assume Requirement 9 is inherited from their provider. Most of it is. The parts that are not — media, offices, and card-reading devices — are the parts that fail.

What you inherit and what you do not

If your CDE runs entirely in a public cloud, the data-centre portions of Requirement 9 are satisfied by your provider and evidenced through their own PCI DSS attestation — you obtain their AOC and confirm the requirements are covered as part of Requirement 12.8 third-party management.

What is not inherited: your own offices, if account data is accessible from them; any physical media containing account data; and any card-reading devices you operate. Teams routinely mark Requirement 9 as not applicable on the strength of being cloud-hosted, then discover that printed reports, backup media, or a card terminal in reception bring parts of it straight back into scope.

Facility and visitor controls

  • Entry controls for facilities and systems in the CDE, with access monitored (9.2.1).
  • Physical and logical controls restricting use of publicly accessible network jacks (9.2.2).
  • Restricted physical access to wireless access points, gateways, networking hardware, and telecommunication lines (9.2.3).
  • Visitors authorised before entry, escorted at all times, and given identification that expires and visibly distinguishes them from personnel (9.3.2, 9.3.3).
  • A visitor log retained for at least three months (9.3.4).

Media handling

Requirement 9.4 covers media containing account data across its life: physically secured (9.4.1), classified so sensitivity is apparent (9.4.1.2), sent by secured courier with tracking (9.4.2, 9.4.3), management approval required before moving media outside the facility (9.4.4), inventories maintained and reconciled at least annually (9.4.5).

Requirement 9.4.6 and 9.4.7 cover destruction: hard-copy materials cross-cut shredded, incinerated, or pulped so they cannot be reconstructed, and electronic media rendered unrecoverable. Storage containers used for materials awaiting destruction must be secured — an unlocked shred bin in a shared corridor is a finding.

POI devices and skimming

Requirement 9.5 addresses point-of-interaction devices that capture payment card data through direct physical interaction. You need an up-to-date list of devices including make, model, location, and serial number (9.5.1.1); periodic inspection of device surfaces to detect tampering or substitution (9.5.1.2), with frequency determined by a targeted risk analysis; and training for personnel so they can recognise suspicious behaviour and know how to report it (9.5.1.3).

This is a physical-world attack with a long history — skimmers overlaid on terminals, devices swapped for compromised replacements by someone in a plausible uniform. The training element matters more than the paperwork: the control only works if the person at the counter notices and escalates.

Data classification PCI DSS Requirement 12: policies and programs PCI DSS CDE scoping

Run your compliance program in one workspace.