Nora
Blake

PCI DSS Kiosk Security: How to Protect Self-Service Payment Terminals

Nora Blake

Sep 23, 2026

11 min read

PCI DSS Kiosk Security How to Protect Self-Service Payment Terminals

TL;DR

PCI DSS kiosk security extends beyond the payment terminal to the systems, networks, software, and controls that support the payment environment.

  • In-scope kiosks can be subject to applicable PCI DSS controls for network security, patching, logging, data transmission, physical protection, and monitoring.
  • Kiosk lockdown, segmentation, timely updates, and applicable POI tamper inspections can strengthen security, but they do not cover every PCI DSS requirement.
  • Hexnode UEM can support device-level controls such as kiosk lockdown, VPN configuration, and patch management.

Payment kiosks support convenient self-service transactions. However, terminals and supporting systems can expand the environment organizations must protect when they fall within PCI DSS scope. PCI DSS kiosk security helps organizations protect payment account data across self-service kiosks and their supporting systems.

A secure deployment involves more than protecting the card reader. IT teams must consider the operating system, payment application, network connections, access controls, patching, and physical security.

As kiosk fleets expand across distributed locations, maintaining consistent security controls can become more complex. An outdated operating system or poorly restricted device can introduce an avoidable security gap.

This guide explains how PCI DSS applies to payment kiosks and which controls can help teams protect them throughout their lifecycle.

What Is PCI DSS Kiosk Security?

In this guide, PCI DSS kiosk security refers to applying relevant PCI DSS requirements and supporting security controls to self-service payment kiosk environments.

The Payment Card Industry Data Security Standard (PCI DSS) defines baseline requirements for protecting payment account data. The PCI Security Standards Council (PCI SSC) develops and maintains the standard.

Payment kiosks that store cardholder data or process or transmit cardholder data and/or sensitive authentication data are part of the cardholder data environment (CDE) and fall within PCI DSS scope. Sensitive authentication data must not be stored after authorization except where the PCI DSS issuer-related exception applies.

The CDE includes people, processes, and system components that store, process, or transmit CHD/SAD. Other connected-to or security-impacting system components can also be within PCI DSS scope.

Organizations must consider more than the card reader. Kiosk operating systems, networks, applications, and supporting infrastructure can fall within PCI DSS scope.

PCI DSS also differs from the former Payment Application Data Security Standard (PA-DSS). PA-DSS focused on eligible payment applications.

PCI DSS applies to entities that store, process, or transmit cardholder data and/or sensitive authentication data, or that could impact the security of the cardholder data environment (CDE). Its requirements apply to system components identified as in scope.

PCI SSC formally retired PA-DSS on October 28, 2022. The Secure Software Standard and Secure Software Lifecycle Standard, under the PCI Software Security Framework, superseded PA-DSS.

Why PCI DSS Non-Compliance in Kiosk Environments Is a Costly Risk

PCI DSS non-compliance within a payment kiosk environment can expose an organization to financial and operational consequences. An account-data compromise can also create fraud-related and reputational costs.

Potential consequences include:

  • Payment-brand consequences: Individual payment brands may impose financial or operational consequences for PCI DSS non-compliance under their own compliance programs.
  • Additional compliance costs: A payment-account-data compromise can result in higher subsequent compliance costs, alongside other potential financial liabilities.
  • Fraud-related costs: A payment account data compromise can create investigation, remediation, and potential fraud-related costs.
  • Reputational damage: A self-service kiosk data breach can create reputational consequences and affect customer trust.

Operating a payment terminal as a self-service kiosk does not remove it from PCI DSS scope. Instead, the applicable requirements depend on the device and its implementation.

Legacy operating systems add another risk. For example, Microsoft ended Windows XP support on April 8, 2014.

Microsoft then stopped issuing new Windows XP operating-system security updates. However, antimalware updates for certain Microsoft security products continued until July 14, 2015.

Therefore, an overlooked kiosk can continue processing payments after its operating system stops receiving new vendor-supplied operating-system security updates.

Which PCI DSS Requirements Apply to Kiosks?

Payment kiosks that store cardholder data or process or transmit cardholder data and/or sensitive authentication data are in PCI DSS scope. Applicable requirements vary with the device and its implementation.

The Cardholder Data Environment (CDE) includes people, processes, and system components that store, process, or transmit cardholder data or sensitive authentication data.

PCI DSS scope can additionally include connected-to and security-impacting system components.

Relevant people and processes involved with the in-scope environment can also fall within scope.

PCI DSS control area  What it means for kiosk deployments 
Network security and segmentation  Network segmentation is not required by PCI DSS. Properly implemented segmentation can isolate systems from the CDE and reduce PCI DSS scope. 
OS patching and vulnerability management  Install applicable security patches and updates for critical or high-security vulnerabilities within one month of release. Install all other applicable security patches and updates within appropriate risk-based time frames. 
Physical security and tamper protection  Maintain applicable POI device inventories and periodically inspect devices for tampering or unauthorized substitution. 
Access logging and audit trails  Log and monitor applicable in-scope systems and required events to support detection and investigation. 
Encrypted data transmission  Protect PAN transmitted over open, public networks with strong cryptography and security protocols. 

When segmentation isolates the CDE from other networks, organizations must meet applicable PCI DSS requirements for testing segmentation controls.

For deployed POI devices used in card-present transactions where a payment card is swiped, tapped, or dipped, also provide the personnel training required by PCI DSS Requirement 9.5.1.3.

Requirement 9.5 does not apply to components used only for manual PAN key entry or qualifying merchant-owned COTS devices, such as smartphones or tablets. However, PCI SSC recommends these controls as best practices for both categories.

A PCI-listed P2PE solution is validated against the PCI P2PE Standard and cryptographically protects account data from capture in the payment device through the secure point of decryption within the validated P2PE solution. It can significantly reduce the number of PCI DSS requirements applicable to a merchant’s cardholder data environment.

However, it does not completely remove PCI DSS applicability from the merchant environment.

Therefore, payment terminal security extends beyond the kiosk enclosure. Teams must evaluate the complete payment architecture and determine which PCI DSS requirements apply to each in-scope component.

How to Secure a Payment Kiosk for PCI DSS Compliance

The following steps address important kiosk security controls, but they do not represent every PCI DSS requirement that may apply to a payment environment.

1. Lock the kiosk to its required applications

Restrict kiosk functionality to what the payment workflow requires. Apply secure configurations to applicable in-scope system components.

Where appropriate, restrict unnecessary applications, system settings, removable media, and unauthorized user functions. This kiosk lockdown compliance approach can reduce opportunities for unauthorized access to the underlying operating system.

2. Restrict network access

As a security-hardening practice, restrict kiosk network connectivity to the destinations and services required by the payment workflow. Implement all applicable PCI DSS network-security controls.

Where organizations use segmentation for scope reduction, they should effectively isolate out-of-scope systems from the CDE. They should also apply appropriate controls to permitted connections.

Protect PAN transmitted over open, public networks with strong cryptography and security protocols according to Requirement 4.2.1.

A VPN may form part of this protection, but the implementation must satisfy all applicable PCI DSS Requirement 4.2.1 criteria for protecting PAN over open, public networks.

3. Keep operating systems and software patched

Establish a defined process for identifying, testing, and deploying applicable security updates. Install applicable security patches and updates that address critical or high-security vulnerabilities within one month of release.

Meanwhile, install all other applicable security patches and updates within appropriate time frames determined by the entity’s assessment of risk to its environment. Monitor kiosk operating system versions so unsupported devices do not remain unnoticed.

4. Log administrative and remote-access activity

Implement applicable audit logging for privileged and remote-access activity involving in-scope systems. Capture the events and information required by the relevant PCI DSS logging controls.

Additionally, restrict administrative access according to job responsibilities. Teams should review applicable logs and investigate suspicious activity according to their security processes.

5. Check kiosks for vulnerabilities and tampering

Regularly assess kiosk hardware, software, and security posture instead of relying solely on the initial configuration.

For POI devices subject to Requirement 9.5.1.2, Requirement 9.5.1.2.1 requires the entity to define the frequency and type of periodic inspections through a targeted risk analysis performed according to Requirement 12.3.1.

Additionally, monitor managed endpoints for relevant security conditions, such as compliance violations and root or jailbreak status where supported.

POI inspections help identify signs of device tampering or unauthorized substitution. Separate endpoint-monitoring controls can surface the device conditions they are configured to monitor.

Simplifying PCI DSS Kiosk Compliance with Hexnode

Hexnode UEM is one way IT teams can operationalize device-level controls that support PCI DSS kiosk security across managed payment kiosks. Organizations must still assess their complete payment environment against applicable PCI DSS requirements.

See how Hexnode manages purpose-built kiosks

Lock Down Payment Kiosks

Hexnode Single App Kiosk Mode can restrict supported devices to an application selected by the administrator.

In Single App Kiosk Mode, the device is restricted to the selected application, limiting access to other applications and device functionality outside the configured kiosk environment.

Configure VPN Controls for Kiosk Networks

Hexnode lets administrators configure VPN profiles on supported platforms, with available VPN types and controls varying by operating system.

For supported Android Enterprise 7.0+ VPN configurations, administrators can enable Always-on to keep the device connected to the configured VPN network.

Hexnode also provides an Always-on connection type that can use an Enterprise App or Managed Google Play app. The selected app must be installed on the device for the policy to take effect.

VPN Lockdown is available on supported Android configurations. It enforces the configured VPN connection and restricts access to other networks, including mobile data, when the VPN is disconnected or unavailable.

When VPN Lockdown is enabled, administrators can use Bypass Lockdown and specify Allowed Apps that may directly access cellular data or Wi-Fi.

Keep Kiosk Operating Systems and Applications Updated

Hexnode provides patch management capabilities for supported Windows and macOS devices, with OS and application update coverage varying by platform and patch workflow. Manual patch deployment on Windows also supports co-managed Windows devices.

On Windows, manual patch deployment supports OS updates and app updates for Hexnode Store, Windows Store, and Enterprise Apps.

On macOS, manual patch deployment supports OS updates and app updates for Hexnode Store, VPP Apps, and System Apps, with available capabilities varying by patch workflow and update type.

Hexnode also provides centralized monitoring of Windows and macOS patch automations, including the automation name, version, platform, creation time, status, and last status update.

When the applicable compliance criterion is configured, Hexnode can mark an iOS/iPadOS device as non-compliant when it is identified as jailbroken.

Hexnode Kiosk Solution
Featured resource

Hexnode Kiosk Solution

See how Hexnode UEM helps IT teams configure and manage purpose-built kiosk environments with centralized device controls.

Download the Datasheet

FAQs

Not necessarily. A self-service payment kiosk that stores, processes, or transmits cardholder data or sensitive authentication data falls within PCI DSS scope. Connected-to and security-impacting components can also be in scope.

Yes. Properly implemented segmentation can separate the CDE from unrelated systems and reduce PCI DSS scope. PCI DSS does not require segmentation, but applicable segmentation controls must be maintained and tested when used for scope reduction.

No. Point-to-point encryption does not automatically make a payment kiosk PCI DSS compliant. A PCI-listed P2PE solution can significantly reduce applicable PCI DSS requirements, but PCI DSS obligations remain in the merchant environment.

An unsupported operating system creates PCI DSS challenges because security patches may no longer be available. Compensating controls may temporarily address the risk when they meet PCI DSS compensating-control requirements and protect against vulnerabilities that could exploit unsupported code. Internet-facing unsupported operating systems also trigger an ASV scan failure, and entities should maintain an active migration plan.

Deployed POI devices covered by Requirement 9.5 must be periodically inspected for tampering or unauthorized substitution. For devices subject to Requirement 9.5.1.2, the inspection frequency and type are defined through a targeted risk analysis under Requirement 12.3.1.

No. UEM alone does not make a payment kiosk PCI DSS compliant. It can support device-level controls such as kiosk lockdown, patch management, VPN configuration, and configurable jailbreak-based compliance criteria for iOS/iPadOS.

Get Ahead of PCI DSS Kiosk Compliance

PCI SSC recommends maintaining PCI DSS control activities and security practices continuously rather than relying solely on point-in-time compliance assessments.

Payment environments change as operating systems, applications, networks, and security risks evolve. Therefore, teams need repeatable processes that keep kiosk security controls aligned with their compliance obligations.

Whichever platform manages your kiosk fleet, use a consistent framework to review device lockdown, network security, patching, logging, and tamper monitoring. This approach helps teams identify security and compliance gaps before they become harder to address.

Share

Nora Blake

I write at the intersection of technology, process, and people, focusing on explaining complex products with clarity. I break down tools, systems, and workflows without any noise, jargon, or the hype.