PCI DSS Testing for Payment Terminal Fleets: Everything You Need to Know

Read time:00:05

Release date:7.28.2026

A merchant or payment service provider operating hundreds or thousands of payment terminals must protect more than a single device model. 

PCA Cyber Security are experts in testing payment terminal fleets to and beyond PCI DSS standards. Learn more.  

Terminals tend to be distributed across shops, restaurants, kiosks, fuel pumps and franchise locations. Each site can have different networks, software versions, physical controls and maintenance arrangements. 

PCI DSS testing examines whether payment account data is protected across this environment. Yet applying the standard to a large terminal fleet raises practical questions. Does every terminal need to be tested? Which PCI DSS requirements apply? Does a PCI PTS approval reduce the need for testing? What can representative sampling miss? 

This guide explains how PCI DSS testing applies to payment terminal fleets and where extra security testing may be needed. 

What Is Payment Terminal Fleet PCI DSS Testing? 

 

Payment terminal fleet PCI DSS testing is the application of PCI DSS assessment and security-testing requirements across a deployed population of payment terminals and the systems supporting them. 

It is not a separate PCI standard or a single type of penetration test. It is a way of assessing PCI DSS controls across a large terminal estate covering multiple locations, device models, network designs, and management arrangements.

Payment terminals form part of the cardholder data environment when they capture, store, process, or transmit payment account data. They must be reviewed during a PCI DSS assessment, including terminals approved under the PCI PTS standard.

Depending on the payment architecture and applicable PCI DSS requirements, fleet testing may include:  

 

  • Checking the terminal inventory against devices deployed in the field.
  • Inspecting terminals for tampering or unauthorized substitution.
  • Reviewing terminal configurations and security settings.
  • Testing store networks and cardholder data environment boundaries.
  • Conducting internal and external vulnerability scans.
  • Performing internal and external penetration testing.
  • Testing network segmentation.
  • Reviewing remote support and administrative access.
  • Assessing terminal management systems and third-party connections.
  • Confirming how payment data is protected between terminals and connected systems.

 

Fleet operators need to bear in mind that PCI PTS approval, and most penetration testing, applies to a device model or a cardholder data environment as it stood at a point in time. It does not automatically extend to every individual unit deployed afterward.

Also worth bearing in mind is that no amount of design certification can assure a fleet owner that every device sitting on a counter, at a fuel pump, or in a kiosk right now matches the one that passed testing.

Which PCI DSS Requirements Apply to Payment Terminal Fleets? 

PCI DSS testing for terminal fleets covers six main areas

 

  1. Terminal inventory must list every device with make, model, location, and serial number, and a good inventory also tracks firmware version, patch status, and vendor support
  2. Physical inspections check terminal surfaces for tampering, and the frequency is set by a risk analysis rather than a fixed schedule.  
  3. Staff need training to check devices before installation and to spot signs of tampering.
  4. Internal and external vulnerability scans run every three months, though many payment terminals cannot take a standard scan, so the scope often shifts to the servers and networks around them. 
  5. Penetration testing runs every 12 months and covers the paths into the cardholder data environment, but it does not usually include firmware extraction or physical tamper testing. 
  6. Segmentation testing confirms the cardholder data environment stays separate from the rest of the network, and this needs to cover the different site types in the fleet, not just one location.

 

PCI DSS Requirements FAQs 

 

Does every terminal need to be tested by a PCI lab? 

No. You do not need to test your entire fleet to be compliant.

PCI DSS allows sampling instead of testing every device, as long as the sample covers every terminal type, location type, acquirer, and payment application in use. A good sample groups terminals by model, firmware version, site type, region, and other factors, so the test result reflects the real spread of devices.

 

Does a PCI PTS approval reduce the need for testing?  

To a degree, yes, but not entirely.  

PCI PTS approval provides product-level assurance for a defined terminal model, hardware version, and firmware configuration. It may prevent unnecessary duplication of some device-security testing, but it does not replace PCI DSS testing or fleet-level checks.  

Operators must still verify that deployed terminals match the approved configuration and remain securely configured, updated, and managed throughout their service life.

 

Are payment terminal device fleets secure if they have been tested as per PCI requirements? 

No. Lab-certified devices can still be at risk when they become part of a live payment terminal fleet.

PCI DSS is a baseline of technical and operational controls, rather than a guarantee that compromise is impossible. Sampling does not remove untested terminals from scope, and payment terminals must still be considered during the PCI DSS assessment.

Fleet operators need ongoing inventory checks, update verification, tamper inspections, monitoring, and risk-based testing between formal assessments. The more accurate conclusion is that PCI-tested fleets have demonstrated compliance with defined requirements, not that they are proven secure.

For example, in 2019, Checkers and Rally's disclosed that point-of-sale malware had been found at around 100 of its nearly 900 restaurant locations across 20 states in the USA. At one location, the malware had been present for several years about malware found pos systems checkers and rallys restaurants/ before it was found. 

Tellingly, the terminals at compromised locations were the same models running the same software as the ones at the restaurants that were never compromised. What differed was the environments surrounding them, showing that the same device can be safe in one environment but at risk in another.

Testing Your Payment Terminal Fleet with PCA Cyber Security  

PCA Cyber Security tests payment terminal fleets to and beyond PCI DSS standards. Our team works across the full estate, from terminal inventories and physical inspections through to vulnerability scanning, penetration testing and segmentation checks.

Learn more.  about services/penetration testing/pci dss compliant penetration testing

Article tags

pci dss

pci pts

payment device security

payment terminal fleet security

fleet management

Popular tags

automotive cybersecurity

pci pts

payment device security

pci dss

automotive threat intelligence

pcautomotive

pcacybersecurity

payment security

cra

pts device security