Its scope can include tills, card readers, mobile terminals, POS software, store networks, back-office systems, remote-management tools, payment processors, support providers, and the physical environment around each device.
Controls should protect payment account data and other retail information while preserving transaction availability. Requirements depend on payment methods, data flows, software and terminal models, acquiring relationships, third parties, and the assessed cardholder data environment.
Key points
Transaction pathIdentify where payment and customer data enters, flows, is stored, or can be affected, including management systems, integrations, support access, wireless links, and connected systems.
Device and data protectionUse supported terminals and software, inspect for tampering or substitution, avoid unnecessary storage, protect keys, and follow instructions for any listed point-to-point encryption solution.
Operational controlsChange unsafe defaults, strongly authenticate remote access, separate duties, segment where effective, apply tested updates, monitor activity, train staff, and coordinate incident procedures with payment partners.
Important limitationAn approved terminal, encrypted transaction, or PCI DSS validation does not prove the whole POS environment secure. A PCI-listed point-to-point encryption (P2PE) solution can reduce applicable PCI DSS requirements when implemented as validated, but it does not eliminate merchant responsibilities or address malware, stolen credentials, unsafe integrations, device substitution, and later changes.