Skip to main content

Card Machine Security & PCI DSS: How to Protect In-Person Payments

Published - 05 February 2024
Revised - 27 August 2026

Please provide your full name
Please provide a valid email address
Please provide a valid contact number
Invalid Input

Libby James – Founder & Payments Expert
Written by Libby James

Libby James is the founder and Managing Director of Merchant Advice Service. Since 2016, she has worked directly with businesses and payment providers across merchant accounts, card processing, payment gateways and complex provider requirements.

Libby specialises in high-risk, declined and harder-to-place merchants, as well as businesses requiring specialist payment methods, integrations or international support. She writes and reviews Merchant Advice Service content, drawing on practical experience gained from real merchant enquiries and provider relationships.

Card-machine security is not just about encrypting a transaction.

For businesses accepting face-to-face card payments, security also means knowing:

  • which payment terminals are authorised;
  • where those devices are located;
  • who can access them;
  • whether they have been tampered with or substituted;
  • how new and replacement terminals are introduced;
  • how software and remote access are controlled; and
  • what happens when something looks wrong.

This becomes particularly important for retailers, restaurants, hotels and multi-site businesses operating dozens or hundreds of payment terminals.

Under PCI DSS, specific requirements apply to point-of-interaction devices used for card-present transactions.

Card-machine security therefore starts with a simple principle: know which devices should be there, check that they are still the same devices, and make sure staff know what to do if something looks wrong.

Quick Summary

  • PCI DSS v4.0.1 is the current version of PCI DSS.
  • PCI DSS Requirement 9.5 addresses protection of applicable point-of-interaction devices from tampering and unauthorised substitution.
  • Relevant merchants should maintain an up-to-date list of applicable payment devices.
  • Devices should be periodically inspected for evidence of tampering or substitution.
  • Staff working around payment terminals should be trained to recognise and report suspicious activity.
  • PCI DSS does not require every terminal to be physically tethered or bolted to a counter.
  • A fixed terminal is not automatically more secure than a portable one.
  • PCI SSC's PTS Point of Interaction standard covers security requirements for devices protecting PINs and payment-card data.
  • PCI DSS itself does not universally require merchants to use PTS-approved devices, although payment brands or acquirers may impose additional requirements.
  • A PCI-listed P2PE solution can significantly reduce PCI DSS scope but does not remove PCI DSS entirely.
  • Businesses should control the installation, replacement and removal of terminals.
  • Remote terminal management and support access should form part of the wider security review.
  • Multi-site merchants should manage their terminals as a controlled payment-device estate rather than a collection of individual machines.
Do you already take payments?
How do you take payments?


Please select a payment type
Please let us know how you take payments
Invalid Input
Invalid Input
Turnover(*)
Turnover




Please let us know your turnover
Invalid Input
Ever Had a Terminated or Declined Account?(*)
Ever Had a Terminated or Declined Account?
Please let us know if you've ever had a terminated or declined account
Please let us know who declined or terminated a previous account
Invalid Input
Please let us know where your company is based.
Please let us know the companies location
Please let us know about your goods or services
Please let us know your name
Please let us know your email address
Please let us know a contact number
Invalid Input

Find Your New Processor

What Is Card Machine Security?

Card-machine security covers the measures used to protect payment terminals, the information they process and the wider environment in which they operate.

This includes:

  • physical security;
  • device identification;
  • tampering prevention and detection;
  • terminal software;
  • network connectivity;
  • remote access;
  • encryption;
  • staff processes;
  • replacement and maintenance procedures;
  • incident response; and
  • PCI DSS compliance.

The terminal itself is only one part of the payment environment.

An integrated retail setup might involve:

EPOS → terminal → payment application → terminal-management system → processor/acquirer → settlement and reporting.

Security therefore needs to consider how those components interact.

What Does PCI DSS Require for Card Machines?

PCI DSS Requirement 9.5 specifically addresses point-of-interaction devices used in card-present transactions.

PCI SSC identifies three core controls:

  1. Maintain an up-to-date list of POI devices.
  2. Periodically inspect devices for tampering or unauthorised substitution.
  3. Train personnel to recognise and report suspicious behaviour, tampering or device replacement.

This applies to deployed point-of-interaction devices that capture payment-card data through direct physical interaction with the card or payment form factor — for example where a card is:

  • tapped;
  • dipped; or
  • swiped.

Read PCI SSC's guidance on Requirement 9.5.

MAS View

You cannot reliably identify a substituted card machine if nobody knows which card machine is supposed to be there.

Do Card Machines Have to Be Bolted or Tethered to the Counter?

No — PCI DSS Requirement 9.5 does not itself require every payment terminal to be physically fixed to a surface using a cable, bracket or tether.

PCI SSC expressly clarifies this point.

The requirement focuses instead on:

  • maintaining a device list;
  • periodic inspection; and
  • staff awareness and training.

A business may still decide that physically securing a terminal is appropriate for its environment.

For example, it could help reduce:

  • device theft;
  • accidental movement;
  • unauthorised access; or
  • substitution risk.

But a cable should not be mistaken for the whole security control.

Are Countertop Card Machines More Secure Than Portable Terminals?

Not automatically.

A countertop terminal may be easier to control physically because it normally remains in one location.

A portable terminal may move between:

  • tables;
  • staff members;
  • floors;
  • outdoor areas;
  • bars;
  • reception desks; and
  • different sections of a venue.

That can create different operational controls, but it does not mean the device is inherently less secure.

Security depends on the complete implementation, including:

  • approved hardware;
  • software;
  • encryption;
  • configuration;
  • physical controls;
  • staff procedures;
  • provider management; and
  • payment architecture.

What Should Be Included in a Card Machine Inventory?

The purpose of a terminal inventory is to help the business identify its authorised payment devices.

Depending on the environment, useful information can include:

  • terminal manufacturer;
  • model;
  • serial number or another unique identifier;
  • asset number;
  • merchant location;
  • specific till or payment point;
  • MID or merchant configuration where appropriate;
  • payment provider;
  • date deployed;
  • status;
  • replacement history; and
  • person or team responsible for the device.

A multi-site business should maintain this centrally rather than relying entirely on individual locations to remember which devices they have.

How Often Should Card Machines Be Inspected?

PCI DSS requires applicable devices to be inspected periodically, but it does not prescribe one universal inspection frequency suitable for every merchant.

The appropriate frequency should take account of the merchant's environment and risk.

Factors may include:

  • number of terminals;
  • location;
  • whether customers can physically access the device;
  • whether terminals move around;
  • staff turnover;
  • opening hours;
  • volume of transactions;
  • temporary or seasonal staff;
  • public accessibility; and
  • previous security incidents.

A terminal at a permanently staffed reception desk and one left in a publicly accessible unattended environment may justify different controls.

What Should Staff Look for When Inspecting a Card Machine?

The objective is to identify changes that may indicate the terminal has been tampered with or replaced.

Checks can include:

  • serial number or asset identifier;
  • unexpected changes to the casing;
  • loose or damaged components;
  • unfamiliar overlays or attachments;
  • changes around the card slot or contactless area;
  • unexpected cables;
  • broken seals where applicable;
  • signs that the terminal has been opened;
  • different logos or labels;
  • unexpected software screens;
  • changes to the terminal location; and
  • a device that does not match the authorised inventory.

The business should follow the inspection guidance supplied by its payment provider and terminal manufacturer.

Important

Staff should not dismantle a payment terminal themselves to determine whether it has been tampered with.

If something appears suspicious, stop using the device and follow the agreed escalation procedure.

What Is Card Machine Substitution?

Unauthorised substitution occurs when a legitimate payment terminal is replaced with another device without the merchant's permission.

This is one reason maintaining an accurate device inventory is important.

For example, staff should question:

  • an engineer arriving unexpectedly to replace a terminal;
  • a courier delivering an unrequested device;
  • a terminal appearing at a till without an internal deployment record;
  • a device with a different serial number from the inventory; or
  • someone claiming a terminal needs to be removed without verified authorisation.

Should Staff Verify Payment Engineers?

Yes.

Staff should not automatically allow someone access to payment devices simply because they say they are from the terminal provider.

A merchant's procedure might include:

  • confirming that a visit is expected;
  • verifying the engineer through an approved contact route;
  • checking identification;
  • restricting access to authorised areas;
  • recording device changes;
  • checking replacement serial numbers; and
  • updating the terminal inventory immediately.

This is particularly important in businesses where many staff members work shifts and may not know whether an engineer visit was arranged by head office.

What Should Happen When a New Card Machine Arrives?

A new terminal should enter the payment environment through a controlled process.

That might include:

  1. confirm the device was ordered;
  2. verify the supplier;
  3. inspect packaging and hardware;
  4. record the terminal identifier;
  5. assign the device to the correct location;
  6. configure it using the provider's approved process;
  7. test the terminal;
  8. update the device inventory; and
  9. securely remove the old terminal if it is being replaced.

For a multi-site rollout, this should form part of the formal deployment process rather than being left to each individual location.

What Should Happen to an Old Card Machine?

Old payment terminals should not simply be put in a cupboard indefinitely or discarded with ordinary office equipment.

Establish:

  • who owns the device;
  • whether it must be returned;
  • how it should be decommissioned;
  • whether the payment provider needs to disable it;
  • how it is removed from the terminal-management system;
  • when it should be removed from the active inventory;
  • how equipment is transported securely; and
  • how disposal is handled if the merchant owns the hardware.

Keep records of returned equipment, particularly where multiple terminals are being replaced.

What Is a PCI PTS-Approved Card Machine?

PCI SSC maintains the PIN Transaction Security Point of Interaction — PTS POI — Standard.

The standard contains security requirements for devices used to protect:

  • cardholder PINs;
  • account data; and
  • other sensitive payment-card information

at the point of interaction.

The current PCI SSC document library lists PCI PTS POI Modular Security Requirements v7.0.

Read PCI SSC's PTS Point of Interaction information.

Does PCI DSS Require Every Merchant to Use a PTS-Approved Terminal?

PCI DSS itself does not universally require the use of PTS-approved devices.

PCI SSC notes that payment brands may have their own requirements concerning PTS-approved hardware.

Businesses should therefore confirm acceptable terminal requirements with:

  • their acquirer;
  • payment provider; and
  • applicable card schemes.

This distinction matters because:

PCI DSS compliance and terminal-device approval are related but separate concepts.

What Is P2PE?

Point-to-Point Encryption — P2PE — protects account data by encrypting it from the point of interaction through to a secure decryption environment.

PCI SSC maintains a dedicated P2PE standard and listings of validated P2PE solutions.

Where a merchant correctly implements a PCI-listed P2PE solution, the number of PCI DSS requirements applicable to the merchant's cardholder-data environment can be significantly reduced.

However, PCI SSC is clear that P2PE does not completely remove PCI DSS applicability.

Read PCI SSC's guidance on P2PE and PCI DSS scope.

MAS View

Encryption is valuable, but “our terminals are encrypted” is not the same as saying the merchant is using a PCI-listed P2PE solution.

How Do You Check Whether a P2PE Solution Is Validated?

PCI SSC publishes listings for validated payment-security solutions.

Merchants considering P2PE should confirm:

  • the exact solution is PCI-listed;
  • the specific terminals being deployed are covered;
  • the solution provider is the correct provider;
  • implementation follows the provider's P2PE Instruction Manual;
  • the merchant meets its own responsibilities; and
  • the solution remains within its validation lifecycle.

Simply seeing the term “P2PE” in sales material is not enough.

Does Encryption Make Card Data Out of Scope?

Not automatically.

PCI SSC clarified again in March 2026 that encryption alone is not sufficient to make cardholder data automatically out of scope for PCI DSS.

The scope impact depends on the architecture, access to decryption capability and whether a recognised validated solution such as PCI-listed P2PE is being used correctly.

Read PCI SSC's current guidance on encrypted cardholder data and scope.

Do Integrated Card Machines Create Different Security Considerations?

Potentially.

An integrated terminal communicates with systems such as:

  • EPOS;
  • till software;
  • payment applications;
  • payment connectors;
  • terminal-management systems; and
  • merchant networks.

The merchant needs to understand:

  • what information passes between systems;
  • whether cardholder data enters merchant-controlled systems;
  • how the terminal is authenticated;
  • how software is updated;
  • who can remotely access the environment;
  • how network connections are protected; and
  • who is responsible for each component.

See our Integrated Card Machines & EPOS Compatibility guide.

What Is a Terminal Management System?

A Terminal Management System — often abbreviated to TMS — can be used by payment providers or other authorised parties to manage payment terminals remotely.

Depending on the implementation, it may support activities such as:

  • configuration;
  • software distribution;
  • parameter updates;
  • terminal monitoring;
  • estate management; and
  • device deployment.

Remote management can be operationally valuable, especially for large terminal estates.

But access to payment infrastructure must itself be secured.

PCI SSC's guidance for payment-terminal environments highlights controls around supported applications, security updates and multi-factor authentication for applicable remote access into the cardholder-data environment, including payment terminals and terminal-management systems where relevant.

Who Is Responsible for Card Machine Software Updates?

Responsibility depends on the provider and architecture.

Updates may be managed by:

  • the payment provider;
  • terminal-management provider;
  • EPOS supplier;
  • merchant IT team; or
  • a combination of parties.

The important thing is that ownership is clear.

Businesses should understand:

  • which software runs on terminals;
  • who supports it;
  • how updates are deployed;
  • what happens when a product reaches end of support;
  • whether merchant action is required; and
  • how failed updates are managed.

Can an Old Card Machine Become a Security Risk?

Potentially.

A terminal may need replacing where:

  • manufacturer support has ended;
  • payment-provider support has ended;
  • security updates are no longer available;
  • connectivity technology is obsolete;
  • the terminal no longer meets scheme/acquirer requirements;
  • the device is physically damaged;
  • the integration is no longer supported; or
  • the wider payment architecture has changed.

The fact that a terminal still powers on does not necessarily mean it should remain in service.

What About 2G and 3G Card Machines?

UK 3G mobile networks have now been switched off, and UK mobile operators are also phasing out 2G.

Older payment terminals dependent on legacy connectivity may therefore require replacement or reconfiguration.

This is primarily a connectivity issue, but keeping obsolete unsupported hardware in service can also create operational and security-management problems.

See our Portable Card Machines guide for the current connectivity position.

Are Portable Card Machines Harder to Control?

They can require different physical controls because they move around the business.

For example, a hospitality business may need to know:

  • how many terminals are on shift;
  • which areas they are assigned to;
  • where devices are stored overnight;
  • who is authorised to use them;
  • how missing devices are reported;
  • how terminals are charged securely; and
  • how inspections are completed.

Portable-terminal security should therefore be built into operational processes rather than treated as an IT-only issue.

What If a Card Machine Is Lost or Stolen?

The merchant should follow its payment-provider and incident-response procedures immediately.

Depending on the setup, this may include:

  • reporting the missing device;
  • recording the serial number;
  • notifying the payment provider;
  • disabling or deregistering the terminal where supported;
  • removing relevant access;
  • reviewing recent transactions;
  • investigating how the device disappeared;
  • updating the asset inventory; and
  • replacing the terminal securely.

Do not simply replace the hardware without investigating what happened to the original device.

What Should Staff Do if a Card Machine Looks Different?

They should not continue using it simply because payments still appear to work.

An internal procedure should tell staff to:

  1. stop using the terminal;
  2. do not dismantle it;
  3. secure it from further use;
  4. notify the designated manager or security contact;
  5. check the device against the authorised inventory;
  6. contact the payment provider through a trusted contact route; and
  7. follow the incident-response process.

MAS View

A terminal processing payments successfully is not proof that the device is legitimate.

What Should Staff Be Trained to Recognise?

PCI DSS expects personnel in relevant point-of-interaction environments to be aware of attempted tampering and device substitution.

Training can cover:

  • what authorised terminals look like;
  • how to identify the device reference;
  • signs of physical alteration;
  • unexpected terminal replacements;
  • unverified engineers;
  • suspicious requests for access;
  • where terminals should be stored;
  • who can move devices;
  • how to report concerns; and
  • what not to do when a device is suspicious.

This is particularly important for businesses employing temporary, seasonal or high-turnover staff.

Should Card Machines Be Checked After an Engineer Visit?

Yes, as part of a controlled change process.

After legitimate maintenance or replacement, consider:

  • confirming the terminal serial number;
  • updating the inventory;
  • recording who completed the work;
  • checking the device is assigned to the correct location;
  • testing a transaction;
  • confirming EPOS integration;
  • checking settlement/reporting configuration; and
  • removing the old device appropriately.

What About Unattended Payment Terminals?

Unattended payment environments can include:

  • self-service kiosks;
  • ticket machines;
  • parking terminals;
  • fuel environments;
  • vending;
  • self-checkout equipment; and
  • other automated payment points.

These can create different physical-security considerations because a member of staff may not be continuously present.

The PCI PTS POI Standard includes security requirements relevant to categories including unattended payment terminals.

Merchants should work with their acquirer, payment provider and technology supplier to establish the correct controls for their particular environment.

How Should Multi-Site Businesses Manage Card Machine Security?

For a multi-location merchant, terminal security needs central governance.

A useful framework can include:

  • central device inventory;
  • standard approved terminal models;
  • controlled ordering;
  • authorised deployment;
  • site-level inspections;
  • central replacement records;
  • approved engineer procedures;
  • staff training;
  • terminal-management oversight;
  • lost-device escalation;
  • software lifecycle management;
  • contractor controls; and
  • decommissioning procedures.

A 100-site retailer should not have 100 different approaches to handling payment terminals.

MAS View

Once a merchant has a large terminal estate, payment-device security becomes an asset-management discipline as well as a PCI requirement.

Does Changing Card Machine Provider Affect PCI DSS?

Potentially.

Simply changing provider does not automatically alter PCI DSS scope.

But the migration may also change:

  • terminal models;
  • integration architecture;
  • P2PE solution;
  • payment application;
  • network connectivity;
  • terminal-management arrangements;
  • merchant systems interacting with payments; or
  • how cardholder data is handled.

Those changes can affect the merchant's PCI DSS environment and validation requirements.

See our Changing Card Processor & PCI DSS guide.

Card Machine Security Checklist

Businesses accepting card-present payments should be able to answer:

  • Do we know every authorised payment terminal?
  • Do we know where each terminal is located?
  • Do we have a unique identifier for each device?
  • Are applicable devices inspected periodically?
  • Do staff know what tampering can look like?
  • Do staff know how to verify engineers?
  • Do we control terminal replacements?
  • Do we securely remove old terminals?
  • Do we know who manages terminal software?
  • Do we know who can remotely access payment infrastructure?
  • Are our terminals still supported?
  • Do we understand whether P2PE is being used?
  • If P2PE is claimed, is the solution PCI-listed?
  • Do we understand our PCI DSS validation route?
  • Do we know what happens if a device goes missing?
  • Do we have an incident-response process?

Find Your New Processor

The MAS Card Machine Security Test

We would separate terminal security into six areas.

1. Device Control

Does the business know exactly which terminals are authorised and where they are?

2. Physical Control

Can tampering, substitution, loss or unauthorised access be detected and escalated?

3. Technology Control

Are terminals, applications and integrations supported and appropriately secured?

4. Data Control

How is payment data protected, and is a validated P2PE solution involved?

5. Access Control

Who can install, configure, remotely manage and replace payment devices?

6. Lifecycle Control

How are terminals ordered, deployed, inspected, upgraded, replaced and decommissioned?

MAS View

The strongest card-machine security controls cover the entire life of the device — from the moment it arrives to the moment it leaves the business.

How Merchant Advice Service Approaches Card Machine Security

Merchant Advice Service helps businesses compare payment providers and payment architectures, including the practical implications of changing terminal estates.

When reviewing a card-machine setup, we may consider:

  • current terminal provider;
  • terminal estate;
  • payment provider;
  • acquirer;
  • EPOS integration;
  • P2PE availability;
  • PCI DSS implications;
  • connectivity;
  • remote management;
  • replacement procedures;
  • multi-site requirements;
  • support;
  • contracts; and
  • migration planning.

Formal PCI DSS validation and security advice should be obtained from the merchant's acquirer, payment provider, Qualified Security Assessor or other appropriately qualified PCI professional where required.

Businesses can explore payment providers through The Payments Directory® or read How Merchant Advice Service Works.

Sources & Further Reading

PCI Security Standards Council — PCI DSS

The current PCI SSC document library lists PCI DSS v4.0.1 as the current PCI Data Security Standard.

PCI SSC — PCI DSS

PCI SSC — Point-of-Interaction Device Protection

PCI SSC confirms that Requirement 9.5 covers device inventories, periodic inspections and staff training for applicable card-present POI devices. It also confirms that PCI DSS does not specifically require every terminal to be physically tethered to a surface.

PCI SSC — POI Tampering and Substitution Guidance

PCI SSC — PTS Point of Interaction

The PTS POI Standard establishes security requirements for devices protecting PINs and sensitive payment-card data at the point of interaction.

PCI SSC — PTS POI Standard

PCI SSC — P2PE and PCI DSS Scope

PCI SSC confirms that use of a PCI-listed P2PE solution can significantly reduce applicable PCI DSS requirements but does not completely remove PCI DSS applicability.

PCI SSC — Effect of P2PE on PCI DSS Validation

PCI SSC — Encryption and PCI DSS Scope

PCI SSC's March 2026 guidance confirms that encryption alone does not automatically render cardholder data out of PCI DSS scope.

PCI SSC — Encrypted Cardholder Data and PCI DSS Scope

Related Merchant Advice Service Guidance

Editorial & Commercial Disclosure

Merchant Advice Service is an independent payments information, comparison and provider-matching service.

MAS may receive commission or a referral fee from some payment providers where a business chooses to proceed following an introduction. This does not determine the factual information or security principles included in this guide.

PCI DSS requirements vary according to the merchant's payment environment, systems, payment channels and validation requirements.

PCI DSS Requirement 9.5 applies to relevant deployed POI devices used for card-present transactions. PCI SSC states that these requirements do not apply in the same way to certain components, including commercial off-the-shelf smartphones and tablets, although similar controls may remain sensible operational practices.

PCI DSS does not universally require every merchant to use a PTS-approved terminal. Separate payment-brand, acquirer or provider requirements may apply.

A PCI-listed P2PE solution can reduce PCI DSS scope but does not completely remove PCI DSS applicability. Encryption alone should not be assumed to make cardholder data out of scope.

Formal PCI DSS validation, security architecture and incident-response requirements should be confirmed with the merchant's acquirer, payment provider, QSA or appropriately qualified PCI professional.

Security standards, device approvals, terminal software and provider requirements can change.

Merchant Advice Service does not provide PCI certification or guarantee that a particular payment environment is PCI DSS compliant.

PCI and security information last checked: 27 August 2026

This guide provides general payments information and should not be treated as legal, regulatory, cybersecurity or formal PCI compliance advice.

FAQs

What is PCI DSS Requirement 9.5 for card machines?
Requirement 9.5 focuses on protecting applicable point-of-interaction devices from tampering and unauthorised substitution. This includes maintaining a device list, periodically inspecting terminals and training staff to recognise suspicious changes.
Do card machines have to be physically tethered to the counter?
No. PCI DSS does not require every terminal to be bolted, tethered or fixed to a surface. A business may still choose to do this as an additional physical control.
How can I tell if a card machine has been tampered with?
Look for unexpected changes such as damaged casing, unfamiliar attachments, different serial numbers, broken seals, unusual cables, altered screens or a device that does not match your authorised inventory.
How often should card machines be inspected?
There is no single inspection frequency for every merchant. The appropriate schedule should reflect the business environment, number of terminals, accessibility, staff turnover and overall risk.
What information should be kept in a card-machine inventory?
Useful information can include manufacturer, model, serial number, location, till position, provider, deployment date and current status.
Should staff verify engineers before allowing access to card terminals?
Yes. Unexpected engineer visits or terminal replacements should be verified through a trusted contact route before access is granted.
What should I do if a replacement terminal arrives unexpectedly?
Do not install it automatically. Confirm that it was genuinely ordered, verify the supplier and check the device against the payment provider’s authorised process.
What should happen to old card machines?
They should be formally decommissioned, removed from the active terminal inventory and returned or disposed of according to the provider’s instructions.
What is a PCI PTS-approved terminal?
PCI PTS refers to security standards for payment devices that protect PINs and sensitive payment-card data at the point of interaction.
Does PCI DSS require every merchant to use a PTS-approved terminal?
Not universally. PCI DSS itself does not mandate PTS approval for every merchant, although acquirers, providers or card schemes may impose additional requirements.
What is P2PE?
Point-to-Point Encryption protects card data from the point where it is captured at the terminal through to a secure decryption environment.
Does using P2PE remove PCI DSS requirements?
No. A PCI-listed P2PE solution can significantly reduce PCI DSS scope, but it does not remove PCI DSS entirely.
Is encrypted card data automatically out of PCI scope?
No. Encryption by itself does not automatically remove cardholder data from PCI DSS scope.
Are portable card machines less secure than countertop terminals?
Not inherently. Portable devices may need different physical controls because they move around the business, but security depends on the overall implementation rather than whether the terminal is fixed.
What should I do if a card machine goes missing?
Notify the payment provider, record the device details, disable or deregister it where possible, review recent activity and investigate how it went missing.
Can an old card machine become a security risk?
Potentially. Unsupported hardware, obsolete connectivity, outdated software or end-of-life devices should be reviewed and replaced where necessary.
Who is responsible for card machine software updates?
That depends on the payment setup. Updates may be managed by the provider, terminal-management company, EPOS supplier or merchant IT team. Responsibility should be clearly defined.
Can integrated card machines create additional security considerations?
Yes. Integration can introduce additional systems, networks and software into the payment environment, so merchants should understand how data moves between the terminal, EPOS and provider.
Should multi-site businesses manage card terminals centrally?
Where practical, yes. Central inventories, standard deployment processes, replacement controls and consistent staff procedures make large terminal estates easier to secure.
Can Merchant Advice Service certify that my card machines are PCI compliant?
No. MAS can help businesses understand payment-provider and terminal options, but formal PCI DSS validation and security advice should come from the merchant’s acquirer, payment provider, QSA or another appropriately qualified PCI professional.

Written or reviewed by Libby James, founder of Merchant Advice Service and specialist in merchant payments and complex provider requirements.

In this article
    Share this article with others:

    Related Articles