PCI Compliance and Chip & PIN: What Every Hospitality Operator Needs to Know
Every hospitality operator taking card payments is obliged to maintain PCI-DSS compliance — but the practical implications differ a lot depending on the hardware you've chosen and how it's integrated with your POS. For pay-at-table operators with mobile chip-and-PIN devices in particular, there are a handful of operational patterns that separate "compliant on paper" from "compliant in practice". This isn't legal advice and we're not your QSA. It is the practical operational guidance we give hospitality customers when they're standardising chip-and-PIN hardware across a multi-site estate. The device class question UK chip-and-PIN devices come in three broad classes: Tethered PIN pads connected to a fixed POS terminal. Lowest PCI scope, highest restriction. Standalone mobile terminals (Bluetooth or 4G). Higher mobility, slightly broader PCI scope. iPad-attached PIN sleds combining a magstripe / chip reader and an iPad case. PCI scope depends heavily on whether the sled is PIN-on-glass certified. For pay-at-table we recommend standalone mobile terminals from the PCI PTS-certified product list, paired (Bluetooth or 4G) to your POS via a certified P2PE solution. Avoid card-present workflows that touch the iPad's screen for PIN entry unless the integrated sled is PCI PTS-certified for that explicitly. Key rotation: the operational discipline PCI-DSS mandates encryption key rotation on PIN-entry devices. In practice this means: Device key injection at procurement, by the acquirer or a certified injection facility Annual or per-incident re-injection for the lifetime of the device Secure decommissioning — devices can't just be thrown in a bin at end of life; keys must be zeroed and chain-of-custody documented The operational pattern that catches multi-site operators out is decommissioning. When a venue closes, when devices are stolen, when a unit is retired for damage — the keys still need to be properly zeroed and the event documented for PCI audit. Build this into your operations runbook from day one. Acquirer choice matters more than you think Different acquirers (Stripe, Adyen, Worldpay, Barclays, Lloyds, etc.) approve different devices and different P2PE solutions. Switching acquirer mid-estate is painful because the hardware may not transfer. Pick your acquirer carefully — and confirm the device list with them — before you buy hardware in volume. What we supply, what we don't We supply PCI PTS-listed chip-and-PIN devices and recommend the acquirer-approved combinations based on your existing relationships. We don't act as a PCI QSA or P2PE solution provider — that's a separate discipline, and we recommend engaging one for any operator with more than 25 sites or processing more than a few million annually. Quick checklist ✅ Device is on the current PCI PTS-listed product list ✅ Acquirer has approved the specific device/firmware combination ✅ Key injection done at procurement, re-injection schedule defined ✅ Decommissioning runbook documented ✅ Staff trained on PIN-entry handling (never enter PIN on operator's behalf, never read PIN aloud, etc.) ✅ Annual PCI self-assessment questionnaire (SAQ) completed