PCI DSS 9.2.1: Appropriate facility entry controls are in place to restrict physical access to systems
PCI DSS v4.0.1 control 9.2.1: the requirement in full, the 1 testing procedure an assessor uses to verify it, and the related controls in section 9.2.
Requirement 9: Restrict Physical Access to Cardholder Data › Section 9.2
Appropriate facility entry controls are in place to restrict physical access to systems in the CDE.
Summary
Control who can physically get to the systems in your cardholder data environment.
What the assessor will examine
These are the testing procedures the standard defines for this control. They tell you what evidence to have ready.
| Procedure | |
|---|---|
| 9.2.1 | Observe entry controls and interview responsible personnel to verify that physical security controls are in place to restrict access to systems in the CDE. |
The entry point of Requirement 9, and the one most often waved away by entities whose systems are all in a cloud provider's data centre. That is a legitimate position, but it is a position that must be evidenced: the provider's facility controls are covered by their attestation, which is where 12.8.2 and 12.8.5 come in, and anything you still operate: an office where staff take card details, a comms cupboard with a switch on the CDE segment, a back room with a POS terminal: remains yours. The single procedure observes the entry controls, so this is assessed by someone looking at the door.
What to prepare
- The list of physical locations holding in-scope systems, including offices and comms rooms.
- The entry controls at each, and who authorises access.
- Provider attestations for facilities you do not operate, mapped as their responsibility.
How to implement it
1. Write down which facilities are yours and which are a provider's. That mapping is the whole answer for a cloud-hosted entity, and it belongs in the responsibility matrix rather than being asserted at assessment time.
2. Do not forget the comms cupboard. A switch carrying CDE traffic in an unlocked riser is a system in the CDE behind a door anyone can open.
3. Include the places people handle cards, not just where machines are. A call centre desk taking card details over the phone is in scope for physical access.
4. Match the control to the risk. The requirement says appropriate; a locked door with a key register is appropriate for a small office, and pretending to badge readers you do not have is worse than describing what you do.
Where this commonly fails
- Cloud hosting treated as removing Requirement 9 entirely, with no attestation evidencing the provider's side.
- Comms rooms and risers overlooked.
- Offices where card data is handled excluded because no servers are there.
- Entry controls described in policy that an observation contradicts.
Related controls
Others in section 9.2:
| Control | What it requires |
|---|---|
| 9.2.1.1 | Individual physical access to sensitive areas within the CDE is monitored with either video… |
| 9.2.2 | Physical and/or logical controls are implemented to restrict use of publicly accessible network… |
| 9.2.3 | Physical access to wireless access points, gateways, networking/communications hardware… |
| 9.2.4 | Access to consoles in sensitive areas is restricted via locking when not in use |
← 9.1.2 · All controls · 9.2.1.1 →
Source
The requirement text and testing procedures above are reproduced from PCI DSS v4.0.1 (June 2024), ©2006-2024 PCI Security Standards Council, LLC. All rights reserved. The commentary is our own.
The official standard is authoritative and also contains the Customized Approach Objective, applicability notes and guidance for this control. Download it from the PCI Security Standards Council document library. PCI DSS is a registered standard of the PCI Security Standards Council, LLC, which does not endorse this site. Nothing here is a substitute for advice from a Qualified Security Assessor.