Skip to main content

Buy Credit Card Terminals

Is Your Terminal Compliant? PCI PTS POI + What Changed in v7.0 (and Why Device Expiration Matters) 
By John Misarti March 13, 2026

Payment terminals are an essential part of any type of card-present payment system at retail locations. Whether it’s a countertop POS terminal, a PIN pad at checkout, or a payment device within a kiosk, all these devices process sensitive cardholder information and PINs. The payment industry utilizes the PCI PTS POI standard, which specifies how payment terminals are designed, tested, and certified to meet safety standards. 

However, compliance with this standard is not static. With the launch of PCI PTS v7.0, this updated version introduces several distinct changes to alleviate the threats of new advanced malware attacks and continually evolving payment technologies. 

This article provides an overview of what the PCI PTS Points of Interface (POI) standard is, changes in PCI PTS v7.0, requirements for PIN pads impact both merchants and manufacturers, and why the expiration dates associated with terminals should be considered when it comes to payment security. 

What Is PCI PTS POI? 

The PCI PTS POI is a security standard established by the PCI Security Standards Council to determine the requirements necessary to protect any payment device. In simple terms, it assures that payment terminals and PIN pads cannot be harmed by physical or logical attacks. 

The PCI PTS POI requires all devices to protect cardholder data through the entire transaction process — from the time a customer enters a PIN to when that PIN is encrypted. 

Some examples of the types of devices the PCI PTS POI applies to include: 

  • Retail point-of-sale terminals. 
  • PIN Entry Devices (PEDs). 
  • Unattended Payment Terminals (e.g., ATM, Kiosk, Parking Meters). 
  • Integrated point-of-sale systems with secure PIN entry. 

These devices are tested at an approved lab, and only issue PTS POI approval once they satisfy all security requirements specified in the PCI DSS. The primary goal is to prevent attackers from capturing a cardholder’s data or PIN through tampering, malware, or manipulation of a device. 

PCI PTS POI Meaning: Understanding the Standard 

To fully understand PCI PTS POI’s meaning, it helps to break down the components of the acronym. 

  • PCI (Payment Card Industry)- A global framework maintained by the PCI Security Standards Council. 
  • PTS (PIN Transaction Security)- Security requirements for devices that capture and process PIN data. 
  • POI (Point of Interaction)- Any device where a cardholder interacts with a payment system. 

Together, PCI PTS POI defines the security baseline for tamper-resistant payment terminals used in card-present transactions. 

The standard focuses on several key security domains: 

1. Physical Security 

Devices must resist tampering attempts such as: 

  • Opening the terminal enclosure 
  • Probing internal components 
  • Installing skimmers or sniffers 

If tampering is detected, the device must automatically erase sensitive cryptographic keys. This is why PCI-certified devices are considered tamper-resistant payment terminals. 

2. Logical Security 

PCI PTS POI also addresses software threats. Security mechanisms include: 

  • Secure firmware loading 
  • Authentication for software updates 
  • Protection against malware injection 

These controls prevent attackers from modifying device behavior or capturing payment data. 

3. Cryptographic Protection 

All sensitive data must be encrypted and protected using approved cryptographic methods, which include: 

  • PIN encryption 
  • Key management 
  • Secure key injection 

Without these controls, attackers could intercept payment information during transmission. 

4. Device Management 

The standard also addresses how devices are: 

  • Manufactured 
  • Distributed 
  • Maintained in the field 

Proper lifecycle management ensures devices remain secure long after deployment. 

What Is the PTS POI-Approved Devices? 

Devices that have received PTS POI approval are payment terminals that have undergone a rigorous security evaluation through PCI-recognized laboratories. Manufacturers test their devices with one of these laboratories to determine if their device meets all technical, security, and process requirements. 

Once the device meets the specified requirements, it will be included on the PCI SSC’s PTS POI approval devices list, which includes: 

  • Payment terminals that are located on the countertop. 
  • PIN pads that connect to POS systems. 
  • Mobile payment readers. 
  • Unattended payment kiosks. 

Merchants and payment solution providers are encouraged to always confirm the status of their device through the official PCI listing before implementing the device.  

Key Pin Pad Compliance Requirements 

The payment devices that record PINs have strict pin pad compliance requirements outlined in the PCI PTS framework. Each payment device must comply to ensure the protection of sensitive PIN information. The key compliance requirements include the following: 

  1. Secure PIN Entry 

PIN Entry for a payment device must occur securely and within a secure cryptographic boundary of the payment device itself. Raw PIN data must never be accessible to external entities. 

  1. Tamper Detection 

A payment device must be able to detect an attempted physical tampering with it. If a payment device has been tampered with, it will have an automatic security response. The payment device will: 

  • Disable itself. 
  • Erase all cryptographic keys. 
  • Prevent further transaction processing by disabling the payment device. 

This requirement serves the dual purpose of protecting a payment device from crimes involving skimming and from manipulation by criminals. 

  1. Secure Firmware 

Firmware installed on all payment devices must be: 

  • Digitally signed. 
  • Authenticated as part of the installation process. 
  • Protected from unauthorized alteration. 

These requirements ultimately protect the payment device from malware. 

  1. Secure Key Management 

Payment devices must be designed to ensure the secure handling of keys used for encryption. The following elements of key management must occur securely: 

  • Keys must be injected into the payment device securely. 
  • There must be protection against key extraction. 
  • Keys must be securely stored within the payment device. 

PCI PTS POI v7.0: What Changed? 

The release of PCI PTS POI v7.0 marks another significant evolution in securing the equipment that accepts payment cards at point-of-sale terminals. The change reinforces the protection of these devices against attacks from the internet, as well as developing new payment technologies. PCI SSC introduced over 30 changes to existing PTS requirements, providing the following details to meet the improvement and the updated version: 

  1. Stronger Protection Against Physical Tampering 

The use of the physical elements of a payment terminal is a growing trend among fraudsters. In PCI PTS POI v7.0, stronger requirements are being introduced to improve the security of payment terminals from hardware tampering. The following areas will see improvements: 

  • Hardware tamper detection. 
  • Secure enclosure of devices. 
  • Protection against probe attacks. 

Changes to the security requirements for tamper-resistant terminals used in unattended payment terminals will be even more stringent. 

  1. Enhanced Malware Protection 

Payment card fraud is often perpetrated by installing malware on payment terminals. PCI PTS POI v7.0 has added requirements to reduce the risk of malware from: 

  • Secure loading software. 
  • Firmware was established for the proper loading process. 
  • Integrity checking of the application and the operating system during the processing of a transaction. 

The above measures are intended to prevent illegal access to transaction data, including data stored in the cardholder’s account. 

  1. Support for Modern Payment Technologies 

Payment technologies have evolved to include: 

  • Contactless payments. 
  • Mobile wallets. 
  • Payment terminals connected to the internet. 

New requirements introduced in PCI PTS POI v7.0 assist the new payment technologies, providing high levels of security. 

  1. Expanded Security Guidance 

PCI PTS POI v7.0 provides even greater guidance for vendors and developers who are implementing the PTS standards. Specifically, the following areas will receive increased guidance: 

  • Designing secure device architecture. 
  • Integrating with payment applications. 
  • Improving the security practices associated with cryptography. 

Why PTS Expiration Dates for Termina ls Matter? 

The PTS expiration dates and terminals are one of the most misunderstood parts of the standards. The expiration of the PCI-approved terminals is a date set in the PCI SSC that indicates the terminal’s compliance with the new security baseline. Here are some things to keep in mind regarding expiration dates: 

  • When a PCI-approved terminal reaches an expiration date, it does not automatically stop working. 
  • The terminal has reached an expiration date, but this does not necessarily mean that all terminal operations will cease to work. 
  • Acquirers and payment processors will likely require the terminal to be replaced once it reaches its expiration date. 

The reason there are expiration dates on the terminals is that the security threats are always evolving. As an illustration, terminals approved may not have the protections from modern malware or sophisticated hardware vulnerabilities that are included in the most recent versions of the PTS. 

How to Check If Your Terminal Is Compliant? 

Companies must continuously assess their devices’ ability to meet current PCI PTS compliance standards through regular assessments by doing the following:  

  • Checking for an updated list of devices approved by the PCI SSC. 
  • Ensuring the device appears as a PTS POI-approved device. 
  • Confirming when the approval will expire. 
  • Reviewing if the device continues to adhere to the latest requirements for pin pads. 

Planned replacement strategies should be developed for devices that have expired or will soon expire. 

Why PCI PTS POI Compliance Is Critical for Payment Security? 

The point of sale (POS) terminal is situated in one of the most sensitive areas of the payment process. If a POS device has been compromised, then an attacker can steal: 

  • The PINs. 
  • Authentication data. 

The PCI PTS POI specification was created to reduce these risks through strict design guidelines for tamper-proof point of sale terminals and secure PIN entry devices. 

For Merchants, using compliant devices will: 

  • Decrease the risk of fraud. 
  • Maintain compliance with the PCI standards. 
  • Protect the trust of customers. 

For Manufacturers, compliance with the PCI PTS POI specification will demonstrate their products conform to internationally accepted security standards in payment. 

Conclusion 

The PCI PTS POI standard protects card-present payment environments through its implementation as a security standard. The framework establishes security standards that protect payment devices from unauthorized access and malicious software attacks, and data theft attempts. The PCI PTS POI v7.0 release introduces new security measures that protect contemporary payment systems while addressing current cybersecurity threats. 

The updated standard delivers complete protection through advanced malware defense systems and enhanced physical security mechanisms. These secure payment terminals are based on tamper-resistant technology throughout the payment system. 

The organization needs to conduct regular device checks for PTS POI-approved equipment while creating plans for hardware updates. This serves as a vital task to achieve ongoing compliance requirements. The PCI PTS POI requirements must be fulfilled by all terminals used in card-present payment operations, as they serve as the essential security controls for organizations. 

FAQs 

1. What is PCI PTS POI? 

The PCI Security Standards Council established PCI PTS POI as a security standard that specifies the security criteria for payment terminals and PIN entry devices. 

What does PCI PTS POI v7.0 introduce? 

The PCI PTS POI v7.0 introduces multiple new security features, like improved physical tampering protection, malware defense mechanisms, advanced cryptographic controls, and contemporary payment system security requirements.

What are the PTS POI-approved devices?

The PTS POI-approved devices include payment terminals that have successfully passed testing at accredited laboratories and received approval from the PCI Security Standards Council. 

What happens when a payment terminal reaches its PTS expiration date? 

The device continues to function after reaching its PTS expiration date, yet it no longer meets current security standards. Payment providers may require a replacement or upgrade. 

Why are tamper-resistant payment terminals important?

Tamper-resistant payment terminals create protection for sensitive cardholder and PIN data as they can detect physical attacks and disable the device when attackers attempt to tamper with it.

 

Leave a Reply

Your email address will not be published. Required fields are marked *