Hotels handle payment card data across more touchpoints than almost any other business — room charges, restaurant and bar tabs, spa bookings, parking, gift shop purchases — each one a potential PCI DSS scope point. PCI DSS 4.0 raised the bar in 2026: hotels that passed a 2024 assessment but never implemented the newer mandatory controls are now failing reassessment. This checklist gives hotel IT and operations leaders a practical way to check where they actually stand.
Who this is for: hotel and hospitality group IT managers, operations directors, and owners responsible for PCI compliance across PMS, POS, and booking systems.
Before You Start: Scope Your Cardholder Data Environment
- [ ] Map every system that touches payment card data: PMS, POS (restaurant, bar, spa, gift shop), online booking engine, call center/phone payments, parking systems.
- [ ] Identify your merchant level based on annual transaction volume — this determines your specific assessment requirements (SAQ vs. QSA-led audit).
- [ ] List every third-party vendor with access to cardholder data (payment processors, PMS vendor, booking engine, loyalty program integrations).
Network Security and Segmentation
- [ ] Confirm your PMS and POS systems are segmented from guest Wi-Fi and general corporate networks with properly configured firewalls.
- [ ] Verify wireless networks carrying payment traffic use strong encryption (WPA2/WPA3) and aren't broadcasting default SSIDs or credentials.
- [ ] Review firewall rule sets at least quarterly and document any changes.
- [ ] Confirm remote access to payment systems (for vendors or support) requires multi-factor authentication and is logged.
Data Protection and Encryption
- [ ] Encrypt cardholder data both in transit and at rest across all systems that touch it.
- [ ] Confirm sensitive authentication data (CVV, full magnetic stripe/chip data) is never stored after authorization — this is a common and serious violation.
- [ ] Mask the PAN (primary account number) everywhere it's displayed, showing only the first six and last four digits at most.
- [ ] Verify tokenization is used where possible so raw card data touches as few systems as possible.
Multi-Factor Authentication (Now Mandatory Under 4.0)
- [ ] Confirm MFA is enforced for all administrative access to systems in the cardholder data environment, not just remote access.
- [ ] Verify MFA covers every individual account with access — shared logins are both a security and compliance risk.
- [ ] Check that payment page scripts are monitored for unauthorized changes — a new requirement under PCI DSS 4.0 aimed at catching web skimming attacks.
Vendor and Third-Party Management
- [ ] Confirm every payment vendor and integration partner provides evidence of their own PCI compliance (AOC — Attestation of Compliance).
- [ ] Review contracts to confirm liability and breach-notification responsibilities are clearly assigned.
- [ ] Reassess vendor access annually — PMS and booking integrations accumulate over time and unused access is a common audit finding.
Ongoing Compliance (Not a One-Time Certification)
- [ ] Schedule vulnerability scans on a defined cadence (quarterly at minimum, per PCI requirements).
- [ ] Run penetration tests annually and after any significant infrastructure change.
- [ ] Maintain and test an incident response plan specific to a payment data breach scenario.
- [ ] Keep staff training current — front desk and F&B staff handling physical cards need refreshed training at least annually.
- [ ] Reassess your SAQ or full audit annually — PCI compliance lapses the moment your environment changes without a reassessment.
Red Flags to Watch For
Systems still storing CVV data after authorization, POS terminals on the same network as guest Wi-Fi, vendors who can't produce a current AOC, and MFA gaps on administrative accounts are the findings that most commonly fail a 2026 reassessment under PCI DSS 4.0's stricter requirements.
How to Use This Checklist
Start with scoping and network segmentation — these determine how much of your environment is actually in scope for the rest of the checklist. Then work through encryption, MFA, and vendor management before scheduling your formal assessment, so gaps get fixed before an auditor finds them.