PCI DSS 9.4.6: Hard-copy materials with cardholder data are destroyed when no longer needed for business
PCI DSS v4.0.1 control 9.4.6: the requirement in full, the 3 testing procedures an assessor uses to verify it, and the related controls in section 9.4.
Requirement 9: Restrict Physical Access to Cardholder Data › Section 9.4
Hard-copy materials with cardholder data are destroyed when no longer needed for business or legal reasons, as follows:
- Materials are cross-cut shredded, incinerated, or pulped so that cardholder data cannot be reconstructed.
- Materials are stored in secure storage containers prior to destruction.
Summary
Destroy hard-copy cardholder data when you no longer need it, so it cannot be reconstructed, and secure it while it waits.
What the assessor will examine
These are the testing procedures the standard defines for this control. They tell you what evidence to have ready.
| Procedure | |
|---|---|
| 9.4.6.a | Examine the media destruction policy to verify that procedures are defined to destroy hard-copy media with cardholder data when no longer needed for business or legal reasons in accordance with all elements specified in this requirement. |
| 9.4.6.b | Observe processes and interview personnel to verify that hard-copy materials are cross-cut shredded, incinerated, or pulped such that cardholder data cannot be reconstructed. |
| 9.4.6.c | Observe storage containers used for materials that contain information to be destroyed to verify that the containers are secure. |
The disposal end of 9.4.1. Two bullets and both are tested: the destruction method must render data unreconstructable, which is why the requirement names cross-cut shredding, incineration and pulping rather than "shredding", and the material must be in secure storage containers while awaiting destruction. That second bullet is the one entities miss: a locked shredding console is part of the control, and a box beside the printer is not. Pairs with 3.2.1: paper you have no retention justification for should be going into that container.
What to prepare
- The destruction procedure naming the method.
- Evidence of the secure containers used while material awaits destruction.
- Certificates of destruction where a service is used, and the contract for it.
- The retention position that says when hard copy is no longer needed.
How to implement it
1. Check the shredder, not the policy. Strip-cut output can be reassembled and does not meet the requirement; the standard names cross-cut for that reason.
2. Make the container the default destination. Where the secure container is inconvenient, paper accumulates in desks, which is the failure this bullet exists to prevent.
3. Keep the certificates. Where destruction is outsourced they are the only evidence you have, and the provider is also a third party for 12.8.1.
4. Look beyond the obvious paper. Signed receipts, delivery notes with card details, and printed reports all count, and are usually stored by whoever generated them rather than centrally.
Where this commonly fails
- Strip-cut shredding, which does not render data unreconstructable.
- An open recycling box used for material awaiting destruction.
- A destruction service engaged with no certificates retained and no agreement on file.
- Retention never applied to paper, so nothing is ever due for destruction.
Related controls
Others in section 9.4:
| Control | What it requires |
|---|---|
| 9.4.1 | All media with cardholder data is physically secured |
| 9.4.1.1 | Offline media backups with cardholder data are stored in a secure location |
| 9.4.1.2 | The security of the offline media backup location(s) with cardholder data is reviewed at least… |
| 9.4.2 | All media with cardholder data is classified in accordance with the sensitivity of the data |
| 9.4.3 | Media with cardholder data sent outside the facility is secured… |
| 9.4.4 | Management approves all media with cardholder data that is moved outside the facility… |
| 9.4.5 | Inventory logs of all electronic media with cardholder data are maintained |
| 9.4.5.1 | Inventories of electronic media with cardholder data are conducted at least once every 12 months |
| 9.4.7 | Electronic media with cardholder data is destroyed when no longer needed for business or legal… |
← 9.4.5.1 · All controls · 9.4.7 →
Source
The requirement text and testing procedures above are reproduced from PCI DSS v4.0.1 (June 2024), ©2006-2024 PCI Security Standards Council, LLC. All rights reserved. The commentary is our own.
The official standard is authoritative and also contains the Customized Approach Objective, applicability notes and guidance for this control. Download it from the PCI Security Standards Council document library. PCI DSS is a registered standard of the PCI Security Standards Council, LLC, which does not endorse this site. Nothing here is a substitute for advice from a Qualified Security Assessor.