Requirement 9.9 provides protection for devices that capture card data; when did this become a formal requirement?

Prepare for the PCI Data Security Standard Test with our quiz. Use flashcards and multiple-choice questions to learn each concept. Get ready to excel in your examination!

Multiple Choice

Requirement 9.9 provides protection for devices that capture card data; when did this become a formal requirement?

Explanation:
Protecting devices that capture card data is part of PCI DSS physical security controls. A formal, enforceable requirement for this protection was introduced with the PCI DSS 3.0 transition, and the deadline to align with that version was June 30, 2015. After that date, safeguarding devices that capture card data became an explicit requirement rather than just guidance. Before the transition, while there were expectations around device security, the formal, versioned mandate wasn’t in place. The timing isn’t about merchant size or a date like 2020—the change specifically reflects the move to PCI DSS 3.0 and its June 2015 transition deadline.

Protecting devices that capture card data is part of PCI DSS physical security controls. A formal, enforceable requirement for this protection was introduced with the PCI DSS 3.0 transition, and the deadline to align with that version was June 30, 2015. After that date, safeguarding devices that capture card data became an explicit requirement rather than just guidance. Before the transition, while there were expectations around device security, the formal, versioned mandate wasn’t in place. The timing isn’t about merchant size or a date like 2020—the change specifically reflects the move to PCI DSS 3.0 and its June 2015 transition deadline.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy