Payment terminal security

How should payment terminals be inventoried?

A payment terminal inventory should identify each deployed card-present device clearly enough that staff can confirm it is the expected device at the expected place. For point-of-interaction devices covered by PCI DSS Requirement 9.5, the PCI Security Standards Council identifies three required inventory details: the device make and model, its location, and its serial number or another unique identifier. The list should stay current as devices are added, moved, replaced, or retired.

Start with a reliable record for every terminal

Create one inventory entry for each deployed terminal that accepts a physical payment card by tap, dip, or swipe. Record the manufacturer and model exactly as shown on the device or approved documentation. Add the full serial number or another identifier that uniquely distinguishes that unit, plus a precise location such as the store, checkout lane, service counter, or unattended station.

A practical internal record may also include an asset tag, responsible team, deployment date, connection type, and current status. Those extra fields can help operations, but they do not replace the core PCI DSS inventory details. Avoid recording card numbers, authentication data, passwords, encryption keys, or customer information in the inventory.

Use locations that staff can verify

A broad label such as "front counter" may be ambiguous when several devices are nearby. Use a location description that lets an employee find and compare the correct unit without guessing. For a business with several sites, include the site identifier and the device's position within that site. For a mobile unit, document its assigned team or controlled storage point and define how its custody is tracked.

Keep the inventory accessible to the people responsible for inspections, but limit editing rights so accidental changes do not weaken the record. If a spreadsheet is used, protect access and retain change history. A managed asset system may be more useful when the terminal count, locations, or responsible teams are complex.

Connect the inventory to physical inspections

The inventory is most useful when staff compare it with the actual device during a periodic inspection. Confirm that the identifier and location match the record. Look for unexpected attachments or cables, altered security labels, damaged or differently colored casing, changed markings, or any other sign that the device may have been tampered with or substituted.

PCI SSC does not prescribe one universal inspection interval for every merchant in its public FAQ. The frequency can depend on the environment and the device's exposure. A terminal supervised throughout the day may present a different situation from an unattended device available to the public. Document the inspection approach, the person or role responsible, and how completed checks are recorded.

Update the list through the device lifecycle

Before deployment

Capture the device details, confirm the expected source and destination, assign responsibility, and add the unit to the inventory before it begins accepting payments.

After a move or replacement

Update the location or status promptly. For a replacement, create a record for the new unit and retain an appropriate history for the removed unit.

At retirement

Mark the terminal as retired or returned, record the date and disposition, and follow provider or vendor instructions for secure return, storage, or disposal.

Define a safe response to discrepancies

If a serial number does not match, a terminal is unexpectedly missing, or a device shows suspicious physical changes, employees should stop using it and follow the organization's incident or escalation procedure. Do not ask staff to troubleshoot an apparently altered device by opening it. Preserve the device and surrounding evidence, restrict access, and contact the appropriate internal security lead, payment provider, acquirer, or qualified incident contact according to the established plan.

Train personnel who work around terminals to recognize suspicious behavior and report attempted replacement or tampering. The PCI SSC identifies staff awareness and reporting alongside the device list and periodic inspections as parts of protecting deployed point-of-interaction devices.

Know which devices the requirement addresses

PCI SSC states that Requirement 9.5 applies to deployed point-of-interaction devices used for card-present transactions. It does not apply to commercial off-the-shelf merchant-owned mobile devices such as ordinary smartphones or tablets, and manual card-number-entry components are outside this specific requirement, though the Council recommends the practices for manual-entry components. Other PCI DSS controls may still apply to those systems, so confirm scope with the organization that manages your compliance program.

For more context, review the PCI compliance FAQ hub, learn how to organize accounts for multiple business websites, and see how operational records help when reconciling deposits with sales.

Build the inventory around your actual environment

Begin with a physical count of deployed terminals, reconcile each device to the required identifying details, and document who updates and inspects the list. Confirm the applicable PCI DSS scope and validation expectations with your acquirer, payment brand, Qualified Security Assessor, or other organization responsible for your compliance program. When requesting general guidance, do not submit cardholder data, passwords, bank credentials, full account numbers, or secret keys.

To learn more about how TSYS can help improve the way your organization accepts payments, markets to new customers, or manages its HR responsibilities, get in touch by calling 585-981-8463 to get started.

CONTACT US