Physical Security for Card Data: Terminals, Paper and Premises
Encryption does not help if someone can walk up to the terminal. Here is what PCI DSS Requirement 9 expects of a UK business — device inventories, tamper checks, paper handling and who gets into the back office.
Most conversations about card security are about networks. But a card terminal sits on a counter that the public can reach, the router is often in a room where deliveries are dropped, and the printout with the customer's details is in a drawer that does not lock. PCI DSS devotes an entire requirement to this — Requirement 9, physical access — and for a shop, restaurant or salon it is frequently the part of the standard with the biggest gap between the policy and the premises. This guide covers what it asks for and how to satisfy it without turning your business into a bank vault. For the wider context, see our complete PCI DSS compliance guide.
Why does physical security still matter if payments are encrypted?
Because the attacks that work against small businesses are not attacks on cryptography. They are attacks on access. A criminal who can spend two unobserved minutes with your card machine can fit a skimming overlay or swap the device for one that looks identical. Someone who can reach your router can plug in whatever they like. And a stack of paper order forms with full card numbers on them needs no hacking at all — it needs a bin bag.
The other reason is that physical controls are the ones your own staff can actually operate. Nobody at the counter can audit a firewall rule. Everybody at the counter can notice that the card machine has a cable that was not there yesterday.
What does Requirement 9 actually ask for?
In plain terms, four things. Restrict who can physically get to the places where cardholder data and payment equipment live. Identify and manage visitors so that anyone in those areas is accounted for. Handle and destroy media — paper and electronic — so card data does not leak out through the bin. And specifically protect the card-reading devices themselves against tampering and substitution, which for a face-to-face merchant is the part that bites.
How much of this applies depends on how you take payments. A purely online business that never sees a card has a much lighter Requirement 9 than a restaurant with handheld terminals. If you are not sure which questionnaire covers you, our guide to the card-present SAQ types sets out which one matches your setup.
How do you keep a device inventory worth having?
The standard expects a list of your card-reading devices, kept current. The point is not the paperwork — it is that you cannot notice a swapped terminal if you never recorded which terminals you had. A usable list records, for each device: make and model, serial number, where it normally lives, and who is responsible for it. Add whether it is allowed to leave the premises, because handhelds that go to tables or events are the ones that go missing.
Keep it somewhere that is not the same drawer as the devices, review it when anything changes, and reconcile it properly at least once a year. A list that has not been checked since the terminals were installed is a document, not a control.
What does a terminal tamper check involve?
Less than you would think, and it takes under a minute per device. You are looking for anything that differs from the device you recorded:
- Serial number matches the inventory — this is the check that catches a substituted device, and the one most often skipped.
- Casing is intact and consistent: no gaps, no fresh glue, no screws that look newer than the others, no mismatched colour or texture around the card slot and keypad.
- Security seals or tamper labels are present and unbroken.
- No extra hardware: unfamiliar cables, an additional device between the terminal and its cradle, or anything plugged into a port that was empty.
- The keypad feels right — an overlay usually sits slightly proud or feels spongy compared with the other terminals.
- The device is where it should be, and no unexplained 'spare' terminal has appeared.
Decide how often you do this and write the frequency down; the standard expects the interval to follow from your own assessment of the risk, so a busy unattended counter warrants more frequent checks than a terminal behind a staffed bar. Then make it somebody's named job at a named moment — opening, or the start of each shift. The same discipline applies to the people who service those devices remotely, which our guide to remote access and card terminals covers in detail.
What about paper?
Paper is the quiet failure in a lot of otherwise compliant businesses. Booking forms, function sheets, mail order slips, the pad by the phone — all of them accumulate card numbers, and none of them are covered by your payment provider's security. The rules are simple and worth stating to staff as absolutes: never write down the security code from the back of the card, under any circumstances; do not write down full card numbers at all if you can possibly avoid it; and if a business process genuinely requires paper card data, it must be locked away, access-controlled, and destroyed as soon as it is no longer needed for business or legal reasons.
Destruction means cross-cut shredding, incineration or pulping — not a bin, not a recycling sack, and not a bag waiting by the back door for collection. The same logic applies to electronic media: old tills, backup drives and laptops need wiping or destroying before disposal, and 'we gave it to a member of staff' is not a disposal process.
If you find you are holding card details on paper because a process requires it, that process is usually fixable — and fixing it often moves you to a simpler questionnaire as a side effect. Our guide to PCI compliance for phone payments covers the compliant alternatives.
Who should be able to get into the back office?
Access to the areas holding payment equipment and card data should be limited to the people who need it for their job, and reviewed when people change roles or leave. In a small business this is mostly about being deliberate rather than buying technology: a door that actually locks, a cabinet for the paperwork, keys that are accounted for, and a note of who holds them.
Two details are worth attention because they are commonly missed. Network sockets and the router in public or semi-public areas should not be freely usable — an open port in a customer-facing room is a genuine route in. And screens that display order or customer information should not be readable from the wrong side of the counter, which is usually solved by turning the monitor rather than buying anything.
What about visitors, contractors and deliveries?
Requirement 9 expects visitors to sensitive areas to be authorised before entry, escorted at all times, and given identification that visibly distinguishes them from staff and expires. It also expects a visitor log recording the name and organisation, the date and time, and who authorised the visit — kept for at least three months. In a shop or restaurant that does not mean a reception desk and lanyards. It means that the engineer, the cleaner and the delivery driver do not wander into the room with the router unaccompanied, that someone writes it down, and that any pass comes back.
One relief worth knowing, because businesses often over-apply this: your customers are not visitors in this sense. The standard specifically excludes cardholders present in a retail location to buy something, and its facility-access controls do not apply to areas the public can freely enter. 'Sensitive area' means the places holding your critical systems — the back office, the server cupboard — and explicitly excludes a retail cashier area where the only equipment is a payment terminal. So the shop floor is not in scope for visitor logging; the room with the router is.
The scenario to guard against is specific: a confident stranger in appropriate workwear, arriving at a busy moment, saying they are here about the card machine. The control that defeats it is a member of staff who has been told, explicitly and in advance, that they are allowed to say 'nobody told us you were coming — I'll ring the office and check'.
A ten-minute walk round
- Count the card terminals and check every serial number against your list.
- Look behind and underneath each one for cables and devices that should not be there.
- Open the drawers near the till and the phone. Anything with a card number on it needs a locked home or a shredder.
- Try the back office door. Then find out who holds a key.
- Look for network sockets and the router in any area a customer or visitor can reach.
- Stand where a customer stands and read the screens. If you can read an order record, so can they.
- Check the shredder works and is actually used, and that waiting confidential waste is not sitting in an open sack.
- Ask one member of staff what they would do if someone arrived to replace a terminal. Their answer is your real control.
Key takeaways
- Requirement 9 covers premises access, visitors, media handling and — for face-to-face merchants — protecting the card readers themselves.
- Keep a current inventory of card devices including serial numbers; without it, a swapped terminal is undetectable.
- Inspect devices on a defined schedule that reflects your own risk, and give the job to a named person at a named time.
- Never store the card security code, avoid paper card numbers entirely, and destroy confidential waste by shredding rather than binning it.
- Most of Requirement 9 costs nothing — a lock, a list, a shredder and staff who are allowed to ask questions.
Physical security is one of the areas where a self-assessment questionnaire asks a simple-sounding question that turns out to have a complicated answer. Fraud Defence First's fully managed PCI compliance service walks through these questions with you, works out which genuinely apply to your premises, and files the completed assessment with your acquirer — a flat £100 + VAT a year.
Related Guides
Training Staff to Spot Card Fraud: What PCI DSS Actually Requires
Your staff are the control that runs when every other control has already been passed. Here is what PCI DSS requires you to train them on, what card fraud looks like from behind the counter, and how to evidence the training when your acquirer asks.
Read ArticleWhy Phishing Still Works — and How to Be a Harder Target
Phishing is the most common way UK businesses get attacked, and the messages stopped being obvious years ago. Here is why it keeps working, what it looks like now, and the handful of controls that actually reduce the risk.
Read ArticlePasswords and MFA: Where NCSC Advice and PCI DSS Meet
Forcing everyone to change their password every 90 days is now considered actively harmful by the NCSC — but PCI DSS still mentions 90 days. Here is how the two actually reconcile, and what a compliant, sensible password policy looks like in 2026.
Read Article