What Requirement 9 covers
PCI DSS v4 organizes Requirement 9 into five sections. 9.1 asks that the processes for the requirement are defined and assigned. 9.2 covers physical access controls for facilities and systems in the cardholder data environment. 9.3 covers authorizing and managing access for personnel and visitors. 9.4 covers storing, moving and destroying media with cardholder data. 9.5 covers protecting point-of-interaction (POI) devices, such as card terminals, from tampering and substitution.
We are not a QSA and do not complete Reports on Compliance. Your assessor decides what is in scope and what evidence they accept. This guide describes the requirement in plain English.
The parts that are tested on site
- Entry controls for sensitive areas, and monitoring of individual access to them by cameras or access control records, with that data kept for at least three months.
- Network jacks, wireless access points and network hardware in public or shared areas restricted so a visitor cannot plug in.
- Personnel access granted by role and revoked on termination, with badges and keys returned or disabled.
- Visitors authorized before entry, escorted, given a badge that expires and is surrendered or deactivated, and recorded in a log kept for at least three months.
- Media physically secured, tracked when it leaves, inventoried, and destroyed so it cannot be reconstructed.
- A list of POI devices, inspected periodically for tampering and substitution, and staff trained to spot it.
Where gaps usually turn up
- Leavers still active in the access control system. See why a terminated employee’s badge still works.
- Visitor badges that never expire and are never collected, so last month’s visitor badge still opens the door.
- Live network ports in meeting rooms and reception.
- Terminal inspections that are logged but not actually done, or done by staff who do not know what a skimmer overlay looks like.
- Badge technology that can be copied, which undermines every access control in the section. See can prox cards be cloned.
How we test it
Our compliance physical controls testing checks whether these controls work on site, not just whether the procedure exists, and maps every finding to the sub-requirement it affects, with a price range on each.
Last reviewed October 7, 2026.