Menu
Payment terminals are an essential part of any type of card-present payment system at retail locations. Whether it’s a countertop POS terminal, a PIN pad at checkout, or a payment device within a kiosk, all these devices process sensitive cardholder information and PINs. The payment industry utilizes the PCI PTS POI standard, which specifies how payment terminals are designed, tested, and certified to meet safety standards.
However, compliance with this standard is not static. With the launch of PCI PTS v7.0, this updated version introduces several distinct changes to alleviate the threats of new advanced malware attacks and continually evolving payment technologies.
This article provides an overview of what the PCI PTS Points of Interface (POI) standard is, changes in PCI PTS v7.0, requirements for PIN pads impact both merchants and manufacturers, and why the expiration dates associated with terminals should be considered when it comes to payment security.

The PCI PTS POI is a security standard established by the PCI Security Standards Council to determine the requirements necessary to protect any payment device. In simple terms, it assures that payment terminals and PIN pads cannot be harmed by physical or logical attacks.
The PCI PTS POI requires all devices to protect cardholder data through the entire transaction process — from the time a customer enters a PIN to when that PIN is encrypted.
Some examples of the types of devices the PCI PTS POI applies to include:
These devices are tested at an approved lab, and only issue PTS POI approval once they satisfy all security requirements specified in the PCI DSS. The primary goal is to prevent attackers from capturing a cardholder’s data or PIN through tampering, malware, or manipulation of a device.
To fully understand PCI PTS POI’s meaning, it helps to break down the components of the acronym.
Together, PCI PTS POI defines the security baseline for tamper-resistant payment terminals used in card-present transactions.
The standard focuses on several key security domains:
1. Physical Security
Devices must resist tampering attempts such as:
If tampering is detected, the device must automatically erase sensitive cryptographic keys. This is why PCI-certified devices are considered tamper-resistant payment terminals.
2. Logical Security
PCI PTS POI also addresses software threats. Security mechanisms include:
These controls prevent attackers from modifying device behavior or capturing payment data.
3. Cryptographic Protection
All sensitive data must be encrypted and protected using approved cryptographic methods, which include:
Without these controls, attackers could intercept payment information during transmission.
4. Device Management
The standard also addresses how devices are:
Proper lifecycle management ensures devices remain secure long after deployment.

Devices that have received PTS POI approval are payment terminals that have undergone a rigorous security evaluation through PCI-recognized laboratories. Manufacturers test their devices with one of these laboratories to determine if their device meets all technical, security, and process requirements.
Once the device meets the specified requirements, it will be included on the PCI SSC’s PTS POI approval devices list, which includes:
Merchants and payment solution providers are encouraged to always confirm the status of their device through the official PCI listing before implementing the device.
The payment devices that record PINs have strict pin pad compliance requirements outlined in the PCI PTS framework. Each payment device must comply to ensure the protection of sensitive PIN information. The key compliance requirements include the following:
PIN Entry for a payment device must occur securely and within a secure cryptographic boundary of the payment device itself. Raw PIN data must never be accessible to external entities.
A payment device must be able to detect an attempted physical tampering with it. If a payment device has been tampered with, it will have an automatic security response. The payment device will:
This requirement serves the dual purpose of protecting a payment device from crimes involving skimming and from manipulation by criminals.
Firmware installed on all payment devices must be:
These requirements ultimately protect the payment device from malware.
Payment devices must be designed to ensure the secure handling of keys used for encryption. The following elements of key management must occur securely:
The release of PCI PTS POI v7.0 marks another significant evolution in securing the equipment that accepts payment cards at point-of-sale terminals. The change reinforces the protection of these devices against attacks from the internet, as well as developing new payment technologies. PCI SSC introduced over 30 changes to existing PTS requirements, providing the following details to meet the improvement and the updated version:
The use of the physical elements of a payment terminal is a growing trend among fraudsters. In PCI PTS POI v7.0, stronger requirements are being introduced to improve the security of payment terminals from hardware tampering. The following areas will see improvements:
Changes to the security requirements for tamper-resistant terminals used in unattended payment terminals will be even more stringent.
Payment card fraud is often perpetrated by installing malware on payment terminals. PCI PTS POI v7.0 has added requirements to reduce the risk of malware from:
The above measures are intended to prevent illegal access to transaction data, including data stored in the cardholder’s account.
Payment technologies have evolved to include:
New requirements introduced in PCI PTS POI v7.0 assist the new payment technologies, providing high levels of security.
PCI PTS POI v7.0 provides even greater guidance for vendors and developers who are implementing the PTS standards. Specifically, the following areas will receive increased guidance:
The PTS expiration dates and terminals are one of the most misunderstood parts of the standards. The expiration of the PCI-approved terminals is a date set in the PCI SSC that indicates the terminal’s compliance with the new security baseline. Here are some things to keep in mind regarding expiration dates:
The reason there are expiration dates on the terminals is that the security threats are always evolving. As an illustration, terminals approved may not have the protections from modern malware or sophisticated hardware vulnerabilities that are included in the most recent versions of the PTS.
Companies must continuously assess their devices’ ability to meet current PCI PTS compliance standards through regular assessments by doing the following:
Planned replacement strategies should be developed for devices that have expired or will soon expire.
The point of sale (POS) terminal is situated in one of the most sensitive areas of the payment process. If a POS device has been compromised, then an attacker can steal:
The PCI PTS POI specification was created to reduce these risks through strict design guidelines for tamper-proof point of sale terminals and secure PIN entry devices.
For Merchants, using compliant devices will:
For Manufacturers, compliance with the PCI PTS POI specification will demonstrate their products conform to internationally accepted security standards in payment.
The PCI PTS POI standard protects card-present payment environments through its implementation as a security standard. The framework establishes security standards that protect payment devices from unauthorized access and malicious software attacks, and data theft attempts. The PCI PTS POI v7.0 release introduces new security measures that protect contemporary payment systems while addressing current cybersecurity threats.
The updated standard delivers complete protection through advanced malware defense systems and enhanced physical security mechanisms. These secure payment terminals are based on tamper-resistant technology throughout the payment system.
The organization needs to conduct regular device checks for PTS POI-approved equipment while creating plans for hardware updates. This serves as a vital task to achieve ongoing compliance requirements. The PCI PTS POI requirements must be fulfilled by all terminals used in card-present payment operations, as they serve as the essential security controls for organizations.
The PCI Security Standards Council established PCI PTS POI as a security standard that specifies the security criteria for payment terminals and PIN entry devices.
The PCI PTS POI v7.0 introduces multiple new security features, like improved physical tampering protection, malware defense mechanisms, advanced cryptographic controls, and contemporary payment system security requirements.
The PTS POI-approved devices include payment terminals that have successfully passed testing at accredited laboratories and received approval from the PCI Security Standards Council.
The device continues to function after reaching its PTS expiration date, yet it no longer meets current security standards. Payment providers may require a replacement or upgrade.
Tamper-resistant payment terminals create protection for sensitive cardholder and PIN data as they can detect physical attacks and disable the device when attackers attempt to tamper with it.
Leave a Reply