Card payments and compliance: a personal WiFi key per terminal, provably apart on its own VLAN
Auditors want proof that the network is separated, and a slide is not proof. Every register, card terminal and clinical device gets a personal WiFi key (xPSK, iPSK, PPSK) bound to its MAC and placed on its own VLAN, staff sit on the secure network, guests on the open one, and every authentication lands in one log.
- ISO 27001 and Cyber Essentials Plus
- JPMorgan runs staff WiFi on Purple across 5,000 branches
- 99.9% RADIUS uptime SLA
The problem
"Provably apart" is a test, and a shared password fails it
Segmentation is only as strong as the evidence for it. When payment terminals and staff phones share one passphrase, there is nothing to hand an assessor but an assurance.
- Registers, card terminals and back-office PCs share a passphrase with staff phones, so the network cannot show which device was which.
- Guests, staff and payment devices reach one another until someone proves they cannot, which is a manual test per site.
- The control that is written down is often the one that is not exercised: PCI DSS v4.0.1 Req 2.3.2 says wireless keys must change when anyone who knows them leaves.
- Clinical devices that cannot hold a certificate sit on the staff network because nothing else was available to them.
- Each authentication log is on a different controller, so evidence for one quarter is an export per site.
How it works
Define the scope once, then let the log prove it
Separation has two halves, and each is testable on its own: where RADIUS places a device, and what your gateway allows between VLANs.
Name the classes that must be apart
List the device classes, such as card terminals, clinical devices and back-office PCs, and give each a VLAN and its own keys, issued in bulk from the console or the Purple API. Managed laptops and phones take EAP-TLS on the secure network.
Bind and place, so a terminal can only land one way
Each key is bound to its device by MAC and RADIUS returns the class VLAN, so a card terminal lands on the payments VLAN and nowhere else. Purple does not route: your firewall rules between VLANs are the other half of the separation.
Log every authentication as evidence
Every accept and reject carries the key, VLAN, method and reason in one log, streamed to your SIEM and mapped to ISO 27001 A.5.15, A.5.18, A.8.15 and A.8.16, Cyber Essentials, and PCI DSS Req 8 and 10.
Rotate the keys that matter, and nothing else
When someone who knows a key leaves, one key is rotated and the rest stay connected, with RADIUS CoA ending the live session on access points that support it. The event stays in the log.
Open, secure or xPSK
Which of the three networks, for which system an assessor will ask about
| Who or what connects | Network | Authentication | Placement | What starts and ends access |
|---|---|---|---|---|
| Shoppers, patients and visitors | Open | Captive portal sign-in, consent recorded | A guest VLAN with client isolation on | Session and consent recorded at sign-in |
| Care-planning tablets and back-office PCs | Secure | EAP-TLS, certificate from your MDM over SCEP | A care or back-office VLAN, apart from guests and payments | Certificate delivered and renewed by your MDM |
| Staff laptops and phones | Secure | EAP-TLS, certificate from your MDM over SCEP | VLAN by directory group | Account disabled in the directory ends access |
| Registers and card terminals | xPSK | Individual key, MAC-bound | A payments VLAN, apart from guests, staff and back-office | One key per device, rotated or revoked alone |
| Infusion pumps, telemetry and other clinical devices | xPSK | Individual key, MAC-bound | A locked-down clinical device VLAN | Revoked with the device when it is replaced |
| Fit-out and maintenance contractors | xPSK | Individual key, MAC-bound (time-limited, no MDM) | One site's or one unit's VLAN only | Ends on the date set |
Placement is what RADIUS returns at authentication: a VLAN, or a role or group policy, depending on your vendor. Your access points and gateway enforce it. VLAN numbers on the illustrations are examples.
What it covers
What you can do with it
A VLAN map an assessor can test
Which class lands on which VLAN, and which keys sit on it. We hand your QSA the VLAN map and the authentication log to test against.A key per terminal, not a payment password
Req 2.3.2 turns into rotating the keys a leaver could have known, while every other terminal stays connected.One log mapped to named controls
ISO 27001 A.5.15, A.5.18, A.8.15 and A.8.16, Cyber Essentials user access control, and PCI DSS Req 8 and 10, from the same authentication log.Patients and shoppers private from each other
The open network runs with client isolation on, so a guest cannot see another guest or a clinical or payment VLAN.Evidence for inspections and the Data Security and Protection Toolkit
Network separation evidence for care inspections.
Where it matters
The industries that run into this most
Shopping malls
Each retailer is its own merchant with its own assessor on the landlord's access points, so each gets a VLAN and key set to test.Retail chains
Card terminals kept away from staff phones and guest WiFi, from one key and VLAN template for every store.Hospitals and healthcare
Infusion pumps and telemetry on locked-down keys, with patients and visitors private from each other and from clinical systems.Care homes
Care-planning tablets and eMAR devices kept apart from resident and guest traffic, with agency staff on keys that end with the booking.
Proof
Regulated estates run on it
Purple holds ISO 27001 and Cyber Essentials Plus, and JPMorgan runs staff WiFi on Purple across 5,000 branches.
- ISO 27001
- and Cyber Essentials Plus, held by Purple
- 5,000
- JPMorgan branches on Purple staff WiFi
- 99.9%
- cloud RADIUS uptime SLA, in your contract
FAQ
Questions IT leads ask
Does xPSK take our WiFi out of PCI scope?
Purple never touches payment card data. Each register and card machine sits on its own key and its own VLAN, apart from guests and staff, and every authentication is logged as evidence for PCI DSS Req 8 and 10. We hand your QSA the VLAN map and the authentication log to test against.
Does segmentation by itself take WiFi out of PCI scope?
No platform does that alone. It reduces and evidences the scope: card terminals on their own keys and VLAN, everything else apart, and an authentication log for Req 8 and 10. Your QSA decides the scope, and we give them the VLAN map and the log to test against.
How does Req 2.3.2 work with a key per device?
PCI DSS v4.0.1 Req 2.3.2 says wireless keys must change when anyone who knows them leaves. With a key per device, you rotate the keys the leaver could have known, and every other device stays connected.
Is a VLAN enough to keep payments apart?
The VLAN separates at layer 2 and your gateway or firewall decides what may cross it. Purple decides which VLAN each connection lands in and logs why, so the two halves can be tested separately.
Where do payment and clinical devices sit among the three networks?
Terminals and clinical devices that cannot hold a certificate sit on xPSK, managed tablets and laptops on the secure network with EAP-TLS, and shoppers, patients and visitors on the open network, each on its own VLAN.
Will our registers and payment terminals work with a key each?
Yes. To a register, its xPSK key is an ordinary WPA2-Personal passphrase, so nothing on the register changes. The per-device key lives on the access point side, whether it is Cisco iPSK on Meraki or HPE Aruba MPSK, and Purple runs every vendor's version on one mixed estate.
Do we need new access points?
No. Purple Access is a cloud overlay on the access points your sites already run: Cisco Meraki, HPE Aruba, Ruckus, Juniper Mist, Ubiquiti UniFi, Cambium, Extreme and Fortinet. Mixed estates are supported.
Book a demo: we issue and revoke a key on a live network
Bring your payment and clinical device lists and the audit questions you dread. We place one device class on its own key and VLAN and show the log an assessor would read.
- Tell us what connectsYour SSIDs, your access points and the devices nobody wants to talk about.
- We issue a key and revoke it liveOne device, one key, its own VLAN, then switched off while you watch the log.
- You leave with the three-network planWhich of your groups sit on open, secure and xPSK, and what to pilot first.
Your design session
Your live key demo
A Purple network engineer runs the demo with you, on your kind of estate.