PCI_DSS_v4Requirement 9voice-validated

PCI_DSS_v4 R9: Requirement 9

PCI_DSS_v4

AL
Adam Lundqvist
Founder at SQUR · last verified 2026-10-06

Regulation text

Any physical access to data or systems that store, process, or transmit cardholder data provides the opportunity for individuals to access devices or data, and to remove systems or hardcopies, and should be appropriately restricted. Includes media handling, visitor controls, and destruction procedures.

ATT&CK techniques this article tests · 0

TechniqueWhy it mapsConfidence

Defending mitigations · 0

MitigationWhat it doesConfidence

Underlying weaknesses · 6

CWEWhy it persistsConfidence
CWE-2849.1.1, 9.1.2. Insufficient authorization for physical access allows unauthorized individuals to enter restricted areas, directly compromising the security of cardholder data.
90%
CWE-2879.1.3. Improper authentication of visitors or personnel at physical access points can lead to unauthorized entry, bypassing established security protocols.
80%
CWE-5329.1.4. Inadequate logging of physical access events (e.g., visitor logs, entry/exit records) hinders forensic analysis and accountability in the event of a physical breach.
80%
CWE-7329.1.1, 9.1.2. Incorrect permission assignment for physical access controls (e.g., access cards, keys) can grant access to individuals who should not have it, creating security gaps.
80%
CWE-2009.1.4. Exposure of sensitive information through improper media handling or inadequate destruction procedures allows unauthorized disclosure of cardholder data.
70%
CWE-3069.1.1, 9.1.2. Missing authentication for critical physical access points (e.g., server rooms, data centers) creates a direct vulnerability for unauthorized entry and data compromise.
70%

What SQUR Covers

Web application + API pentesting for OWASP Top 10, business logic flaws, authentication bypass, injection attacks, and other application-layer vulnerabilities. €1,995 per scan, 24-hour turnaround, EU-only data.

What SQUR Does Not Cover

Internal network pentesting, endpoint security testing, physical security assessments, social engineering, or ICT third-party concentration risk reviews. Engage a complementary provider for those scope items.

Provenance

Mapped Q2.2026 using gemini-2.5-flash · €0.0185 compute · voice-rubric self-validated