Point of Sale (POS)
A point of sale (POS) is the time and place where a customer completes a purchase, as well as the combination of hardware and software a business uses to process that transaction. Depending on the setup, a POS may handle card and cash payments, record sales data, and manage inventory. The term can refer either to the moment of sale itself or to the system that facilitates it.
Point of Sale (POS) refers both to the location and moment at which a retail transaction is completed and to the integrated hardware and software system used to process card or cash payments at that time and place. POS systems typically capture payment data, initiate transaction processing, and may also support functions such as sales data management and inventory control across in-store and, in some implementations, online environments. Because POS systems commonly capture and transmit cardholder data during acceptance, their configuration, connected components, and data flows are relevant to determining PCI DSS scope; readers should assess scope based on the specific implementation and validate against the current published standard rather than assuming POS involvement dictates a fixed set of requirements. Note that this evidence describes the general commercial function of POS and does not establish specific security control details.
Why it matters
The point of sale is where cardholder data most commonly enters a merchant's environment during payment acceptance. Because POS systems capture and transmit payment data at the moment of the transaction, they and their connected components frequently fall within PCI DSS scope. How that scope is defined depends on the specific implementation, the data flows involved, and the way the POS is segmented from other systems, so scope should be assessed against the current published standard rather than assumed from the presence of a POS alone.
POS environments have historically been an attractive target because they are a concentration point for cardholder data during acceptance. The evidence digest here describes only the general commercial function of POS systems and does not establish specific attack techniques, breach figures, or control requirements, so specifics of any given threat should be evaluated against dedicated security guidance and validated sources.
Because the term POS can refer either to the moment of sale or to the hardware and software system that facilitates it, precision matters when scoping controls, drafting compliance documentation, or investigating incidents. Distinguishing the transaction event from the system that processes it helps teams communicate clearly about where data resides, how it moves, and which components require assessment.
Who it's relevant to
Inside POS
Common questions
Answers to the questions practitioners most commonly ask about POS.