HelpCenter

Explore
Vending PCI Implementation Guide
Updated

Purpose 

This document will guide an Operator through securely implementing 365 Retail Markets’ vending products, including PicoVend and PayPlus devices, in a PCI-compliant manner. It also includes information about security controls used by 365 Retail Markets. Please contact security@365rm.com with any questions related to this guide.
 

Operator PCI Implementation Guide  

This section outlines the Operator’s responsibilities in securely implementing 365 PicoVend and PayPlus devices.
 

Networks

The PicoVend / PayPlus devices require a persistent “always on” network connection to the internet for credit card processing and receiving updates. The Operator is responsible for providing the internet connection and following this guide to ensure it is implemented in a PCI-compliant manner.
 

SIM Cards 

Your device supports the installation of a SIM card to provide a dedicated cellular network connection. This option provides a simple and secure means to ensure your device is segmented in a Card Data Business Environment from other devices and remains PCI compliant.
 

Network Connectivity Options

PicoVend/PayPlus devices support both wired and wireless networks, if the network is configured as a Card Data Business Environment.  Never connect your device to an Untrusted Environment or Non-Card Data Business Environment.  For example, never connect your devices to a “guest” Wi-Fi network.  

If you are not comfortable creating a network following this guide, or cannot validate the client’s network follows PCI DSS guidelines, 365 Retail Markets offers several solutions to assist with network connectivity.  Contact your account manager for more information on ordering a PCI DSS compliant firewall (router) or “Connect Kit”.  
 

Corporate Versus Dedicated Networks

If you have chosen NOT to use a SIM card, Operators have two primary options for establishing network connectivity at most client locations: Corporate or Dedicated Networks.

Many corporate environments (offices, hospitals, etc.) contain existing networks to provide Internet connectivity throughout the building. These Corporate Networks often restrict the types of information that can be transmitted on them. Corporate Networks are typically managed by a dedicated team member who can advise on the feasibility of allowing your market to operate on their existing Internet connection.

A Dedicated Network is a completely separate network that Operators would install, which circumvents many challenges that a Corporate Network may present. A Dedicated Network could consist of a broadband line, 4G/5G cellular modem, or other dedicated high-speed connection. As the market owner, the Operator would need to organize this dedicated service to be installed into the client’s environment.

*Corporate Network **Dedicated Network
Pros Pros
Internet service already in place. No additional cost to the Operator. No need to ask client IT staff to open access or run wiring to a new location.
Network is typically very fast and stable. The Operator owns the network, and therefore requires less coordination to ensure PCI best practices are being followed.
Managed by dedicated personnel with knowledge of troubleshooting and secure networking protocols. If cellular is chosen, Operators have the added mobility to move the kiosk and internet together on an as-needed basis.
Cons Cons
The Operator may need to coordinate with the  client IT staff or network administrator to ensure correct and secure settings/requirements are implemented. The Operator needs to organize, implement, and pay for internet service.
Wiring is typically ran to a single location, making kiosk mobility challenging. Network connectivity (especially cellular) may be slower than a corporate network.
The Operator is responsible for ensuring the corporate network follows PCI standards, which often requires more coordination with client IT staff. When service is interrupted or requires maintenance (power surge, severe weather, modem resets, connection stability), the Operator is responsible for responding in-person to troubleshoot the outage.
  May require an Operator resource with IT and networking knowledge to ensure best practices in this guide are followed. (365 staff is available to assist with secure network setup.)

*If the Operator chooses to use a Corporate Network, it is the Operator’s responsibility to ensure this guide is followed by the client network administrator.  Be sure to supply them a copy of this guide early in the implementation process, paying special attention to the Networks section. 

**If the Operator chooses to use a Dedicated Network, it is your responsibility to ensure the best practices outlined in this guide are followed.
 

Network Segmentation for Corporate Networks

For deploying on a Corporate Network, segmenting the devices into a secure card data business environment is required.  Network segmentation is a strategy intended to simplify PCI DSS compliance of your network and to help you protect your business from hackers. At the most basic level, there are three zones representing three levels of risk.

  • Untrusted Environment – Network connections that anonymous sources have access to be considered “untrusted.” They should have no network access to your business computers and POS equipment. Business computers should never be connected directly to this zone. Common untrusted networks are the internet connection itself, customer wireless internet access, and visitor network connections. This is the highest risk zone because anybody can connect to it anonymously. 
     
  • Non-Card Data Business Environment – Systems not used for payment processing but are still business-owned fit into this segment. These are systems that can be used for email, web browsing, and other higher-risk activity that you would never want to perform on your payment processing systems. On occasion, these systems will almost certainly become infected with malware and viruses. Once a computer in this zone is infected, the hacker or infection will spread to other systems if they’re not protected by a firewall. Note that if any systems in this zone handle credit card data, that data is being put at risk. This is a medium-risk zone due to risk of occasional infection. By segmenting these systems into their own zone, the breach is contained. The hacker, malware, or virus doesn’t reach your firewall-protected payment processing zone. 
     
  • Card Data Business Environment – Systems used for payment processing fit into this segment. These systems should only be used for POS activity and should NEVER be used for any other reason. Should these computers become infected with malware or viruses, sophisticated hacking tools can potentially steal sensitive data such as credit cards. This is a low-risk zone because it’s protected from the other two zones and high-risk activities such as web browsing and email do not occur inside it. The chance that hackers, malware, or viruses spread to these systems is minimal.
     

In summary, to segment your network for security you should:

  • Protect both business environments from the untrusted environment.
     
  • Protect your card data business environment from the non-card business environment.
     

Best Practices for Dedicated Networks

  • Always change vendor-supplied passwords on DSL or cellular modems.  Do not leave default passwords on any of your network devices.  
     
  • Keep your network devices (modems, switches, routers) in a secure, locked area.
     
  • Disable all Wi-Fi broadcasts when using a wired network. 
     
  • Upgrade the firmware on your devices regularly.  Manufacturers often deploy security patches to their devices.  You are responsible for ensuring your device firmware stays up to date.
     
  • A Dedicated Network is your Card Data Business Environment.  Do not use it for any purposes other than those critical to your business. This includes only the services outlined in the Technical Network Requirements document.  

Cellular Network

Vending PCI Implementation Guide - Cellular Network.png

Wireless Network

Vending PCI Implementation Guide - Wireless Network.png

Wired Network

Vending PCI Implementation Guide - Wired Network.png

Physical Security 

Operators are responsible for the physical security of devices, routers, switches, modems, and peripherals.    

  • The PicoVend/PayPlus devices must always remain secured in place unless service is being performed. 
     
  • Network devices external to the PicoVend/PayPlus device must be kept in a locked, secure environment.
     
  • Devices must be inspected regularly for tampering. 
    • Inspect the card reader. Does it look natural? Does it appear that it has been altered? 
    • Gently pull on the card reader. Be sure that no foreign device has been installed on top. 
    • Inspect the PicoVend/PayPlus device.  Has it been damaged?  Are the screws still in place?  Is the molding, bezel, and mounting intact? Any unfamiliar devices or cables connected?
       
  • Use DVR recording and regularly review.  
     

For more information, please visit the PICO and AirVend Physical Security Audit guide

If you suspect a physical compromise, contact 365 Support immediately to perform an Incident Response.
 

Access Controls 

Operators are responsible for onboarding and offboarding employee access to the PicoVend/PayPlus device environment.  This includes documented processes for:

  • Creating accounts and assigning appropriate permissions to employees with access to the PicoVend/PayPlus device environment (ADM, AV-Live, VMS, etc).
     
  • Revoking accounts when employees are terminated or quit. 
     
  • Regular audits of accounts to ensure access is still appropriate.  
     

Secure Disposal 

The PicoVend/PayPlus devices must be securely disposed of when they are no longer in service.  Physically destroying the hard drive and memory modules with a hammer or drill will ensure no sensitive data remains intact. Be sure to follow appropriate safety measures when destroying media.  
If you are not comfortable destroying the media yourself, please ship the devices back to 365 who will securely destroy them  at no cost.  
 

Employee Training 

Operators must organize and complete security awareness training for all individuals with access to the PicoVend/PayPlus device environment upon hire and annually thereafter and must document the completion of training. This is best accomplished as part of a comprehensive cyber security awareness training program.
 

365 Retail Markets Security Controls 

This section outlines many of the controls 365 Retail Markets has in place to protect sensitive data.  
 

Security of Device 

The PicoVend/PayPlus devices utilize a secure direct real-time connection to the card processor when items are checked out. The card readers in use have the security capability standard of PTS 5.X which conforms to the PCI security standards . The transactions are card present, with no cardholder data stored for later use. Transactions are needed to complete the purchase of items from the self-service, stand-alone, PicoVend/PayPlus devices and mini-retail shops where 365 Retail Markets provide their services. 

All data is encrypted by the card reader at time of card swipe, 365 Retail Markets does not have access to the encryption keys and cannot decrypt this encrypted cardholder data. This dramatically reduces the scope as 365 Retail Markets does not store, process, and/or transmit the PAN. (PAN data is encrypted during transmission, but 365 Retail Markets does not have access to keys.)
 

Credit Card Data 

365 Retail Markets is PCI DSS certified. Heartland Payment Systems is a PCI DSS certified gateway and supports advanced security features, like hardware card encryption, card tokenization, and EMV technology.  
 

Card Holder Data Processing  

Heartland 

Heartland operates as a payment gateway service.  TLS 1.2 or higher and a select suite of ciphers is the minimum requirement for using the service.   Heartland supports multiple methods of securing transmitted and stored data. 

The primary option is Heartland End-to-End Encryption (E3). E3 encrypts card data at the point of entry in a hardware solution such that the POS never handles data in the clear. Portico supports two methods of encryption for securing PAN and track information: Heartland E3 and AES using DUKPT. Heartland E3 is an implementation of the Voltage Identity-Based Encryption methodology offered by Heartland to allow card data to be encrypted from the moment it is obtained at the POS and throughout Heartland processing. 

Since software is vulnerable to intrusions, this technology is hardware-based. Using E3 hardware, the POS software never sees card data. It also allows the card data to remain encrypted throughout all of Heartland’s and 365’s systems. This not only removes intrusion threats; it also greatly reduces the PCI scope of 365’s POS.
 

Data Storage and Encryption 

The unencrypted credit card PAN is never stored by 365 Retail Markets.  

For non-CHD data:  

  • AWS (Amazon Web Services) is where all data from the PicoVend/PayPlus devices are stored. 
     
  • Vending uses SQL Server Instance running on an EC2 Windows Instance encrypted at rest.
     
  • TLS 1.2 or higher is used for data in transit.
     
  • Additional Certificates for AWS can be found here: https://aws.amazon.com/certification/.
     

Security Audits and Scans 

  • A PCI DSS audit is performed annually by an independent third-party QSA. 
     
  •  ASV scans are performed quarterly. 
     
  • Penetration tests are performed annually.
     

Business Resiliency – DR/BC 

  • Disaster Recovery plans tested annually.
     
  • RTO and RPO outlined in table below.
# Description Recovery Process/Method RTO RPO Consumer Impact Operator Impact
1 Normal Operations None N/A N/A None None
2 Primary DB Server Failure Failover to backup. 2 hrs Up to 24 hrs Unable to do CC/Coupon/GMA transactions. Operator portal not available for the duration of recovery. 
3 DB drive failure  New drive/restore from backup. 2 hrs 15 mins Unable to do CC/Coupon/GMA transactions. Operator portal unavailable for duration of recovery time. Lost sales due to payment limitations.
4 Primary Web Server Failure Failover to backup environment. 2 hrs Up to 24 hrs Unable to do CC/Coupon/GMA transactions. Operator portal unavailable for duration of recovery time. Lost sales due to payment limitations.
5 Natural Calamity impacting the entire AWS Oregon region  Failover to backup environment. 2 hrs Up to 24 hrs Unable to do CC/Coupon/GMA transactions. Operator portal unavailable for duration of recovery time. Lost sales due to payment limitations.

Privacy and Terms & Conditions Policies 

These policies can be located at the 365 Retail Markets Consumer Policy page.  
 

PCI-DSS Responsibility Matrix 

The matrix below outlines each PCI requirement and the party responsible for compliance.  

PCI Requirement 365 Responsibility Operator Responsibility
Requirement 1: Install and maintain a firewall configuration to protect cardholder data.
  • Encrypt cardholder data at the point of sale, and securely transmit it to the processor.
  • Ensure all 365 provided network equipment is PCI-DSS compliant with secure configurations.
  • Deploy devices into a segmented, dedicated Card Data Business Environment network according to this guide.
  • If using 365-supplied firewall, do not change secure configurations.
Requirement 2: Do not use vendor-supplied defaults for system passwords and other security parameters.
  • Encrypt cardholder data at the point of sale, and securely transmit it to the processor.
  • The MSRs are secured against any logical access and are locked down by the manufacturer.
  • All systems are hardened according to industry standards and managed by 365.

If network equipment was NOT supplied by 365:

  • Always change vendor-supplied defaults and remove or disable unnecessary default accounts before connecting the PicoVend/PayPlus to the network.
  • Develop configuration standards for all system components. Assure that these standards address all known security vulnerabilities and are consistent with industry-accepted system hardening standards.

If using 365-supplied firewall/router:

  • Do not change secure configurations of firewall.
Requirement 3: Protect stored cardholder data. Cardholder data is not stored by the MSR devices. None
Requirement 4: Encrypt transmission of cardholder data across open, public networks. The MSR device encrypts cardholder data at the point of sale, and securely transmits it to the processor using strong encryption. None
Requirement 5: Use and regularly update anti-virus software or programs.
  • The MSR device encrypts cardholder data at the point of sale, and securely transmits it to the processor following industry-accepted standards.
None
Requirement 6: Develop and maintain secure systems and applications.
  • Applications are developed following secure SDLC principles. 
  • Static and dynamic code analysis security scans are in place.
None
Requirement 7: Restrict access to cardholder data by business need-to-know.
  • 365 does not store, process and/or transmit unencrypted CHD, all sensitive CHD data is encrypted upon contact, and entities never have custody of the encryption keys.
  • All refunds are coordinated with the processor directly and do not require sensitive CHD.

 

If network equipment was NOT supplied by 365:

  • Limit access to network components to individuals whose job requires such access.
  • Establish an access control system for network components that restricts access based on a user’s need to know, and is set to “deny all” unless specifically allowed

If using 365-supplied firewall/router:

  • Do not change secure configurations of firewall.
Requirement 8: Identify and authenticate access to system components.
  • All 365 employees with computer access have unique IDs
  • Access to network resources follow a least privilege model with location-based restrictions, SSO, MFA and secure onboarding process. 

If network equipment was NOT supplied by 365:

  • Assign all users a unique ID before allowing them to access network components
  • Immediately revoke access for any terminated users
  • Remove/disable inactive user accounts within 90 days
  • Enforce MFA on network components
  • Enforce strong password rules
  • Do not use group, shared, or generic IDs, passwords, or other authentication methods on network equipment

If using 365-supplied firewall/router:

  • Do not change secure configurations of firewall.
Requirement 9: Restrict physical access to cardholder data.
  • The MSR is built into the device.
  • 365 does not store and/or transmit unencrypted card data on the device locally.
  • Deploy devices into a segmented, dedicated Card Data Business Environment network according to this guide.
  • Protect devices from tampering and substitution.
  • Maintain an inventory of all owned devices
  • Periodically inspect device surfaces to detect tampering (for example, addition of card skimmers to devices), or substitution (for example, by checking the serial number or other device characteristics to verify it has not been swapped with a fraudulent device).
  • Provide training for personnel to be aware of attempted tampering or replacement of devices.
  • Use either video cameras or access control mechanisms (or both) to monitor individual physical access to sensitive areas.
  • Restrict physical access to networking/communications hardware, and telecommunication lines.
  • Control physical access to devices.
  • Destroy media when it is no longer needed for business or legal reasons. 
  • Media must be rendered unrecoverable (e.g., via a secure wipe program in accordance with industry-accepted standards for secure deletion, or by physically destroying the media).
  • Ensure that security policies and operational procedures for restricting physical access to cardholder data are documented, in use, and known to all affected parties.
Requirement 10: Track and monitor all access to network resources and cardholder data.
  • The MSR device encrypts cardholder data at the point of sale and securely transmits it to the processor.   The MSR devices do not store cardholder data.
  • Access to network resources follow a least privilege model with location-based restrictions, SSO, MFA and secure onboarding process. 
  • All systems have centralized logging.  
None
Requirement 11: Regularly test security systems and processes.
  • The MSR device encrypts cardholder data at the point of sale, and securely transmits it to the processor.  
  • Systems are regularly pen tested and security scanned. 
  • Incident response procedures are in place.
None
Requirement 12: Maintain a policy that addresses information security for employees and contractors.
  • As the Merchant of Record and Service Provider, a risk assessment for the provided services is maintained by 365.
  • Security awareness training is provided to all 365 employees.
  • Operators must organize and complete security awareness training for all individuals with access to the devices upon hire and annually thereafter and must document the completion of this training.

 

Change Log
Version Date Change Log
06012026 06/01/2026 Original Draft