Skip to content
The WesternTechSystems facility corner at night

Compliance · PCI DSS

PCI DSS media destruction, and where requirement 9.8 went

Two requirements, one renumbering that has left a lot of internal documentation citing a retired version, and a standard that is contractual rather than legal — which changes who can enforce it against you and what a vendor badge is worth.

In one paragraph

The short version

PCI DSS v4.0.1 requires media holding cardholder data to be destroyed when it is no longer needed for business or legal reasons — hard copy under requirement 9.4.6, electronic media under 9.4.7. If your documentation still cites 9.8, it is on a version retired in 2024.

PCI is a contractual standard rather than a law, enforced through your merchant agreement. That distinction matters commercially: the Council qualifies assessors, not disposal vendors, so there is no such thing as a PCI-certified destruction provider — only a provider whose evidence does or does not stand up in front of your QSA.

1 · The obligation

What the rule actually says

Cited to the PCI Security Standards Council's published documents. Quoted rather than paraphrased, because the paraphrases in circulation are where most of the confusion starts.

PCI DSS v4.0.1 — Requirement 9.4.6

Hard-copy materials with cardholder data are destroyed when no longer needed for business or legal reasons, as follows: materials are cross-cut shredded, incinerated, or pulped so that cardholder data cannot be reconstructed; materials are stored in secure storage containers prior to destruction.

This is the hard-copy requirement, and it is unusually prescriptive for PCI — it names the acceptable methods rather than describing an outcome. Quoted here from the Council's own published self-assessment questionnaire.

https://www.pcisecuritystandards.org/

PCI DSS v4.0.1 — Requirement 9.4.7 (electronic media)

The electronic media destruction requirement. We are giving you the number and the subject matter rather than a quotation, because the full standard sits behind the Council's licence click-through and we were not willing to reproduce wording we could not verify at source. If you hold the licensed PDF, the sixty seconds it takes to read 9.4.7 is worth more than any vendor's paraphrase of it — including ours.

https://www.pcisecuritystandards.org/

2 · The misreading

What the rule does not say

This is the section most vendor pages omit, and it is the one that decides whether the rest of the page can be trusted.

  • PCI DSS is not law. It is a private contractual standard, enforced by the payment brands and your acquirer through your merchant agreement — not by a regulator, and not by statute.

  • The Council certifies assessors, not disposal vendors. Its programmes cover QSAs and ASVs. There is no listing, approval or certification programme for ITAD or data destruction providers, so the phrase “PCI-compliant disposition service” describes nothing that exists.

  • It does not make your vendor responsible for your scope. If you cannot say which systems and media held cardholder data, no destruction certificate resolves that — you have a scoping problem, not a disposal problem.

  • It does not require destruction on a timetable. The trigger is when the media is no longer needed for business or legal reasons, which is a decision you make and must be able to justify.

  • Requirement 9.4.6 is about hard copy. Applying its cross-cut, incinerate or pulp language to drives is a common and confusing error — electronic media is 9.4.7.

3 · The evidence

What an auditor actually asks for

The destruction record, tied to your scope documentation

A QSA works from your cardholder data environment definition outward. The destruction evidence has to reconcile with the systems your scope says held cardholder data.

Method appropriate to the media type

The standard distinguishes hard copy from electronic media. An assessor will notice if one method is being described for both.

Secure storage before destruction

9.4.6 addresses the interval before destruction explicitly. Where media waits, and under what control, is part of the requirement rather than an operational detail.

Serial-level evidence for electronic media

Consignment-level paperwork cannot demonstrate that a specific drive from a specific in-scope system was destroyed.

Vendor due diligence on your part

PCI's service-provider expectations mean the assessor may ask what diligence you performed before engaging us, not only what we produced afterwards.

4 · Our part

What our documentation provides against it

Artefact What it answers
Per-serial erasure or destruction record Electronic media evidenced at the drive, reconcilable against the systems named in your cardholder data environment scope.
Chain-of-custody record Where media was between leaving your control and being processed — the interval 9.4.6 cares about for hard copy and an assessor will ask about for both.
Method statement Which method was applied to which media class, so hard copy and electronic media are evidenced separately rather than under one heading.
Intake reconciliation report What arrived against what was manifested, in writing, before processing begins.
Facility and process access Walkthrough and records review by appointment, which is what turns your vendor diligence from an assertion into a document.

5 · Your part

What remains your obligation

No vendor can discharge these for you. Any vendor implying otherwise is selling you a risk you will still be holding.

  • Defining your cardholder data environment, and knowing which media fell inside it. No disposal evidence can substitute for a scope you cannot describe.
  • Deciding and justifying when media is no longer needed for business or legal reasons.
  • Reconciling our records against your own asset register before your assessment, not during it.
  • Performing and documenting service-provider due diligence on us.
  • Reading 9.4.7 in the licensed standard rather than relying on any vendor's summary, this page included.

FAQ

PCI DSS destruction questions

Which version of PCI DSS is current?
v4.0.1, published in June 2024. v3.2.1 retired on 31 March 2024 and v4.0 on 31 December 2024, which leaves v4.0.1 as the only version the Council currently supports. If your internal documents cite requirement 9.8, they predate the renumbering.
Where did requirement 9.8 go?
It was consolidated. The Council's own Summary of Changes from v3.2.1 to v4.0 records that the media destruction procedures in 9.8 were merged into the related requirements, which are now 9.4.6 for hard-copy materials and 9.4.7 for electronic media.
Why will you not quote 9.4.7 on this page?
Because we could not verify the wording at the primary source. The full standard is behind the Council's licence click-through, and the ungated documents that are publicly available — the self-assessment questionnaires we could reach — legitimately omit 9.4.7 because they scope out electronic media storage. We would rather give you the requirement number and tell you where to read it than reproduce wording we have only seen on other vendors' websites.
Is there such a thing as a PCI-certified data destruction vendor?
No. The PCI Security Standards Council runs qualification programmes for assessors — QSAs and ASVs — and for certain products. It operates no certification, approval or listing programme for ITAD or data destruction providers. A vendor advertising PCI certification for destruction services is describing something the Council does not issue.
Does PCI DSS apply to us at all if we only take cards occasionally?
That is a question for your acquirer rather than for us, and the answer depends on your merchant level and how cardholder data touches your systems. What we can say is that if any of your retired equipment ever processed, stored or transmitted cardholder data, the destruction evidence for it is worth having regardless of which SAQ you complete.

Send us your QSA's request.

Tell us what has been asked for and we will tell you which of it we can evidence — and which of it is yours to produce.