PCI DSS 9.3.3: Visitor badges or identification are surrendered or deactivated before visitors leave
PCI DSS v4.0.1 control 9.3.3: the requirement in full, the 1 testing procedure an assessor uses to verify it, and the related controls in section 9.3.
Requirement 9: Restrict Physical Access to Cardholder Data › Section 9.3
Visitor badges or identification are surrendered or deactivated before visitors leave the facility or at the date of expiration.
Summary
Visitor badges come back or are switched off when the visitor leaves, or when they expire.
What the assessor will examine
These are the testing procedures the standard defines for this control. They tell you what evidence to have ready.
| Procedure | |
|---|---|
| 9.3.3 | Observe visitors leaving the facility and interview personnel to verify visitor badges or other identification are surrendered or deactivated before visitors leave the facility or at the date of expiration. |
The closing half of 9.3.2, and the procedure is unusually direct: it observes visitors leaving the facility. That is a live check on the least-supervised moment of the visit, when the visitor is on their way out and reception is busy. Note the requirement offers two outcomes, surrendered or deactivated, so a badge that walks out of the building is acceptable if it has been disabled in the system. For entities where visitors regularly leave with a badge in a pocket, deactivation on expiry is the more reliable of the two, because it does not depend on anyone remembering at the door.
What to prepare
- The exit procedure, showing who collects or deactivates.
- Evidence of deactivation in the badging system for recent visits.
- Reconciliation of badges issued against badges returned or disabled.
- A live departure to observe, which the procedure requires.
How to implement it
1. Deactivate on expiry automatically. It satisfies the control without depending on the exit desk, and it covers the badge that left in a pocket.
2. Reconcile issued against returned daily. It is the cheapest way to notice a badge that never came back, and it produces the evidence for the interview.
3. Make the return step part of signing out, so the two happen together rather than the sign-out happening alone.
4. Handle the multi-day visitor deliberately. A contractor on site for a week has a badge that must still expire, which is where a general visitor process usually has a gap.
Where this commonly fails
- Badges collected when convenient, so some leave the building live.
- Sign-out recorded and the badge neither returned nor deactivated.
- Long-term visitors issued a badge with no expiry because they are on site repeatedly.
- No reconciliation, so a missing badge is never noticed.
Related controls
Others in section 9.3:
| Control | What it requires |
|---|---|
| 9.3.1 | Procedures are implemented for authorizing and managing physical access of personnel… |
| 9.3.1.1 | Physical access to sensitive areas within the CDE for personnel is controlled… |
| 9.3.2 | Procedures are implemented for authorizing and managing visitor access to the CDE… |
| 9.3.4 | Visitor logs are used to maintain a physical record of visitor activity both within… |
← 9.3.2 · All controls · 9.3.4 →
Source
The requirement text and testing procedures above are reproduced from PCI DSS v4.0.1 (June 2024), ©2006-2024 PCI Security Standards Council, LLC. All rights reserved. The commentary is our own.
The official standard is authoritative and also contains the Customized Approach Objective, applicability notes and guidance for this control. Download it from the PCI Security Standards Council document library. PCI DSS is a registered standard of the PCI Security Standards Council, LLC, which does not endorse this site. Nothing here is a substitute for advice from a Qualified Security Assessor.