PCI DSS applies wherever cardholder data goes, and that now includes your employees' kitchen tables. If remote staff access your cardholder data environment (CDE) or take card payments from home, their devices and connections are in scope. The most effective approach is to keep card data off home devices entirely, using virtual desktops, thin clients or DTMF masking for phone payments. Whatever remains in scope needs the usual PCI DSS 3.2.1 controls: multi-factor authentication for remote access, session timeouts, personal firewalls, clear usage policies, secure paper handling and updated training.

This post walks through each of those. It's practical guidance, not legal advice, so confirm scoping decisions with your QSA or acquirer.

Does PCI DSS apply when employees work from home?

Yes. PCI DSS scope follows the data, not the building. Any system that stores, processes or transmits cardholder data is in scope, along with anything connected to those systems or able to affect their security. A laptop that connects to your CDE over a VPN is in scope whether it sits in the office or in a spare bedroom.

The PCI Security Standards Council addressed this in March. Its blog post Protecting Payments While Working Remotely, published March 23, 2020, pulls remote-working practices from the Council's information supplement Protecting Telephone-Based Payment Card Data (version 3.0, November 2018). The post notes that the guidance doesn't replace or supersede the requirements in any PCI SSC standard. The standard itself still sets the bar.

Which PCI DSS requirements matter most for remote staff?

Most of PCI DSS applies to remote systems just as it does in the office. These requirements deserve a second look when people work from home:

Requirement What it says What it means at home
8.3.2 Multi-factor authentication for all remote network access originating from outside your network Every remote connection into your environment needs MFA, for users, admins and third parties
8.3.1 MFA for all non-console administrative access into the CDE Admins working from home need MFA to manage CDE systems
8.1.8 Re-authentication after a session has been idle more than 15 minutes Unattended home laptops lock
12.3.8 Automatic disconnect of remote-access sessions after a period of inactivity Idle VPN or remote desktop sessions drop
12.3.10 Prohibit copying, moving or storing card data on local drives and removable media for remote users, unless explicitly authorized No card data saved to home laptops or USB drives
1.4 Personal firewall on portable devices that connect to the internet outside your network and also access the CDE Laptops need a firewall that's running and that users can't turn off
4.2 Never send unprotected PANs by end-user messaging No card numbers in email, chat or text messages
5.1, 6.2 Anti-malware and timely security patches Remote devices still get protected and patched
9.5–9.8 Secure, control and destroy media, including paper Notes with card data need locked storage and proper destruction
12.6 Security awareness program Training covers home-working risks

Multi-factor authentication for remote access

Requirement 8.3.2 is easy to miss when remote access is expanded in a hurry. It covers all remote network access from outside your network, including users who don't have administrative rights. A VPN protected only by a password doesn't meet it.

The factors must be independent. A password plus a one-time code from a separate device or app qualifies. Two passwords don't.

Session timeouts

Two requirements work together here. Requirement 8.1.8 requires re-authentication after 15 minutes of inactivity, which in practice means a screen lock. Requirement 12.3.8 requires remote-access sessions to disconnect automatically after a defined period of inactivity. Configure both on the endpoint and on your VPN or remote desktop gateway.

Personal firewalls on laptops

Requirement 1.4 applies to company-owned and employee-owned portable devices that connect to the internet outside your network and are also used to access the CDE. The firewall, or equivalent functionality, must have defined configuration settings, must be actively running, and must not be alterable by the device's users.

That last condition is hard to meet on a personal device your staff administer themselves. It's one of several reasons to issue managed equipment for CDE access.

Remote access and acceptable use policies

Requirement 12.3 asks you to set usage policies for critical technologies, including remote access, laptops and removable media. Among other things, those policies need explicit approval for use, authentication, a list of devices and people with access, acceptable uses, acceptable network locations and approved products.

Many of these policies were written with occasional remote access in mind. Update them to cover questions like:

  • Can staff use personal devices, or only company-issued ones?
  • Can other household members use a work device?
  • Is printing at home allowed?
  • Where in the home can staff take payment calls?
  • How should staff report a lost or stolen device?

Requirement 12.3.9 also applies: activate vendor and business partner remote access only when needed, and turn it off afterwards.

How do you keep card data off home devices?

The best way to reduce remote-work risk is to reduce what reaches the home at all.

Virtual desktops and thin clients

With virtual desktop infrastructure (VDI), the application that handles card data runs in your data center or cloud environment. The home device receives screen images and sends keystrokes. Card data isn't stored on the endpoint, which makes Requirement 12.3.10 far easier to meet.

VDI doesn't automatically take the endpoint out of scope, though. Keystrokes typed into a virtual desktop still pass through the home device, and that device connects to systems that touch card data. Company-managed thin clients or locked-down laptops give you much more control than personal computers. Check with your QSA how your specific design is scoped before you rely on it.

How should staff take phone payments from home?

Phone payments raise the most specific remote-work questions. The PCI SSC's telephone payments information supplement is the most useful reference here.

Softphones and VoIP

A softphone running on a workstation that's used to capture card data brings that workstation into scope, and probably the network it's connected to as well. Voice streams carrying card data over public networks must be encrypted with strong cryptography under Requirement 4.1. Confirm that your softphone and telephony platform encrypt both signaling and media.

DTMF masking

With DTMF masking, the customer enters their card number on their phone keypad instead of reading it aloud. The tones are replaced with flat or random tones before they reach the agent, so the agent never hears or sees the number. According to the information supplement, a properly designed and deployed DTMF masking solution can take the telephony environment, the agent environment and the CRM system out of scope.

Test it carefully. The supplement warns about "DTMF bleed," where the start of a tone isn't masked and could be decoded. It also notes that recordings containing only flat tones that can't be converted back to card data don't need to be rendered unreadable under Requirement 3.4.

Call recordings

Sensitive authentication data, such as the card verification code, can't be stored after authorization, even if encrypted. If your calls are recorded, you need a way to keep that data out of recordings:

  • DTMF masking, so the data never enters the recording
  • Pause-and-resume, where recording stops while card details are given
  • Secure deletion of any sensitive authentication data captured anyway

If agents trigger pause-and-resume manually, the supplement recommends checking recordings regularly, preferably weekly, to confirm they don't contain card data. Any recordings that do contain PANs must be protected like other stored card data.

What about paper records at home?

Some agents write card numbers down during a call. At home, that paper sits outside every physical control you have in the office.

The cleanest rule is to prohibit writing card data down at all. If that's not realistic, Requirement 9 still applies:

  • Physically secure all media, including paper (9.5)
  • Maintain strict control over its distribution, storage and access (9.6, 9.7)
  • Destroy it when it's no longer needed (9.8)
  • Shred, incinerate or pulp hard-copy material so card data can't be reconstructed, and keep material awaiting destruction in a secured container (9.8.1)

In practice, that means a locked drawer and a good cross-cut shredder at home, or a secure way to return paper to the office for destruction. The PCI SSC's March post makes the same point: paper with card data must be stored securely and shredded when no longer needed.

How should you update security awareness training?

Requirement 12.6 requires a formal security awareness program. Personnel must be trained on hire and at least annually (12.6.1) and acknowledge the security policy at least annually (12.6.2). The telephone payments supplement adds that training for home workers taking card-not-present payments should address their responsibility for physical security.

Add home-specific content:

  • Take payment calls where they can't be overheard, and lock screens when stepping away
  • Never let family members use work devices
  • Never store card data locally or send it by email or chat
  • Report lost devices and suspected incidents immediately, and know who to call

Frequently asked questions

Is an employee's home network in PCI scope?

Treat it as an untrusted network, the same way PCI DSS treats the internet. That's why the controls focus on the device and the connection: strong encryption in transit, MFA for remote access and a personal firewall on the laptop. Your QSA will want to see how you've designed and documented this.

Can staff use personal computers to access the CDE?

Requirement 1.4 explicitly covers employee-owned devices, so it's not prohibited. But you'll still need to meet the firewall, anti-malware, patching and usage policy requirements on hardware you don't control. For CDE access, company-managed devices are far easier to defend.

Does moving staff home count as a significant change?

It may. Requirement 6.4.6 requires all relevant PCI DSS requirements to be in place on new or changed systems and networks after a significant change. A new VPN, new VDI platform or new telephony setup should go through that process. Discuss scope changes with your QSA or acquirer.

Does DTMF masking remove all our PCI obligations?

No. It can take agents, telephony and CRM systems out of scope if designed and deployed properly. But you still need to secure the masking solution's integration, confirm your provider's own compliance and cover any other channels that handle card data.

Key takeaways

  • Remote devices that access the CDE are in scope. Home working doesn't change that.
  • Enforce MFA for all remote network access (8.3.2) and set idle timeouts on endpoints and remote sessions (8.1.8, 12.3.8).
  • Issue managed devices with personal firewalls users can't disable (1.4), and prohibit local copies of card data (12.3.10).
  • Use VDI or thin clients to keep card data off endpoints, and confirm the scoping with your QSA.
  • For phone payments, consider DTMF masking, keep sensitive authentication data out of recordings and encrypt voice traffic.
  • Ban handwritten card data if you can. If you can't, apply Requirement 9 at home.
  • Update usage policies and training for home working.