Get Demo
↑

PCI DSS Requirement 9: Physical Security of Cardholder Data and POI Devices

PCI DSS v4.0.1 Requirement 9 - facility entry controls, visitor management, media handling/destruction, and POI device tamper protection (9.5.1).

Published: September 2026 Compliance · PCI DSS 8-12 min read

PCI DSS Requirement 9 in v4.0.1 is titled Restrict Physical Access to Cardholder Data. It covers facility entry controls, personnel and visitor access, securing and destroying media with cardholder data, and protecting point-of-interaction (POI) devices from tampering and unauthorized substitution (9.5).

Related: Requirement 3 · Requirement 12 · 12 requirements hub.

Gotchas: Media destruction under 9.4.6 / 9.4.7 is distinct from electronic data retention and deletion under 3.2.1. 9.5.1 applies to deployed POI devices used in card-present transactions (swipe, tap, or dip) - not COTS devices such as smartphones or tablets designed for mass-market distribution. PCI DSS v4.0.1 Appendix G adds a formal definition of Visitor for 9.3.x controls.

Requirement Structure

Clause
Focus
9.1
Processes and roles for physical access controls
9.2
Facility entry controls for systems containing CHD
9.3
Authorize and manage personnel and visitor physical access
9.4
Secure, classify, distribute, and destroy media with CHD
9.5
Protect POI devices from tampering and unauthorized substitution

Deep Dives

How CyberSilo Helps

Map PCI DSS v4.0.1 Controls to Continuous Evidence

CyberSilo CSA and ThreatHawk SIEM help US merchants and service providers collect QSA-ready evidence across the 12 requirements.

Frequently Asked Questions

Does Requirement 9 apply to smartphones used as payment terminals?

9.5.1 does not apply to commercial off-the-shelf (COTS) devices such as smartphones or tablets designed for mass-market distribution. Confirm device classification with your QSA.

Is shredding CHD printouts the same as Requirement 3 retention deletion?

No. 9.4.6 and 9.4.7 cover destruction of media when that media is no longer needed for business or legal reasons. Requirement 3.2.1 covers retention and secure deletion of stored account data per the entity's retention policies.

How long must visitor logs and sensitive-area access recordings be kept?

At least three months unless otherwise restricted by law (9.2.1.1 for monitoring data and 9.3.4 for visitor logs).

PCI DSS hub · 12 requirements explained · Requirement 3 · Requirement 12

📰 More from CyberSilo

Latest Articles

Stay ahead of evolving cyber threats with our expert insights

✅ Link copied!