9.2 Physical access controls manage entry into facilities and systems
How to meet it
Control and monitor entry to areas with cardholder data.
Defined requirements
The individual PCI DSS v4.0.1 requirements under 9.2, in plain English.
9.2.1Suitable facility entry controls limit physical access to systems within the CDE.
9.2.1.1Physical access to sensitive areas is monitored by cameras and/or access controls, protected from tampering, and kept at least three months.
9.2.2Physical and/or logical controls restrict use of publicly accessible network jacks.
9.2.3Physical access to wireless access points, gateways, and networking hardware is restricted.
9.2.4Access to consoles in sensitive areas is limited by locking them when not in use.
Policy templates for this control
Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.
Physical and environmental security policyUse for ISO 27001 A.7.1 to A.7.14, SOC 2 Security, and PCI DSS requirement 9 physical access controls.Access control policyUse for ISO 27001 A.5.15, A.5.16, A.5.17, A.5.18, A.8.2, SOC 2 Security, and PCI DSS requirements 7 and 8.Network security policyUse for ISO 27001 A.8.20, A.8.21, A.8.22, A.8.23, SOC 2 Security, and PCI DSS requirements 1 and 4.AI use and governance policyUse for ISO 42001, AI governance, employee AI use, data handling, human review, and AI supplier risk.
Open the control-to-policy map← 9.1 Processes and mechanisms are defined and understood9.3 Physical access for personnel and visitors is authorised and managed →
Back to Requirement 9, or see PCI DSS templates. To run PCI controls with automation, read how AI manages controls.