Skip to content
Free PCI toolkit

Free tools for every PCI DSS requirement.

The open-source and no-cost tools that help you implement each of the 12 PCI DSS requirements — and exactly which requirements each one covers. Filter to your SAQ type to see only what applies.

These are examples to get you started, not endorsements. A tool helps you implement a control; you still complete and self-assess the SAQ. A few requirements (ASV scans, penetration testing) need a paid service — noted where they appear.

Requirement 1

Network security controls

Firewalls and equivalent controls that isolate and protect the systems that touch card data.

Open-source firewall/router for segmenting and protecting your network.

Covers: Req 1
Cloud security groups & NACLs

Built-in, free network controls in AWS/Azure/GCP to isolate the card-data environment.

Covers: Req 1
ufw / firewalld

Free host-based firewalls for individual servers.

Covers: Req 1

Free cloud security and configuration assessment (AWS/Azure/GCP).

Covers: Req 2, Req 1

Free network and port discovery for audits.

Covers: Req 11, Req 1
Requirement 2

Secure configurations

Harden systems, change vendor defaults, and remove unnecessary services and accounts.

Free hardening guides and an assessment tool for common systems.

Covers: Req 2

Free host security auditing and hardening checks for Linux/macOS.

Covers: Req 2, Req 6

Free configuration and vulnerability compliance scanning.

Covers: Req 2, Req 6

Free cloud security and configuration assessment (AWS/Azure/GCP).

Covers: Req 2, Req 1

Free vulnerability and misconfiguration scanner for containers, code, and IaC.

Covers: Req 6, Req 2
Requirement 3

Protect stored account data

Store as little card data as possible, and render anything you must keep unreadable.

Don’t store card data

The cheapest Requirement 3 control: outsource card handling to your PSP and store nothing.

Covers: Req 3

Free disk/volume encryption for data at rest.

Covers: Req 3
OS-native encryption (BitLocker / LUKS / FileVault)

Free full-disk encryption built into the operating system.

Covers: Req 3

Free file-level encryption and key management.

Covers: Req 3, Req 4
Requirement 4

Encrypt data in transit

Use strong cryptography whenever cardholder data crosses open or public networks.

Free file-level encryption and key management.

Covers: Req 3, Req 4

Free, automated TLS certificates so traffic is encrypted in transit.

Covers: Req 4

Free best-practice TLS server configuration.

Covers: Req 4

Free tools to test the strength of your TLS setup.

Covers: Req 4, Req 11
Requirement 5

Protect against malware

Run and maintain anti-malware on systems that are commonly affected.

Free, open-source anti-malware engine.

Covers: Req 5
Microsoft Defender Antivirus

Free, built-in anti-malware on Windows.

Covers: Req 5
Requirement 6

Secure systems & software

Patch known vulnerabilities promptly and build software securely.

Free host security auditing and hardening checks for Linux/macOS.

Covers: Req 2, Req 6

Free configuration and vulnerability compliance scanning.

Covers: Req 2, Req 6

Free automated dependency updates that fix known-vulnerable libraries.

Covers: Req 6

Free vulnerability and misconfiguration scanner for containers, code, and IaC.

Covers: Req 6, Req 2

Free static analysis (SAST) that catches insecure code patterns.

Covers: Req 6

Free secure-development guidance and verification standard.

Covers: Req 6

Free web-application security scanner (DAST).

Covers: Req 11, Req 6
Requirement 7

Restrict access (need-to-know)

Grant the least access required, by role and business need.

Native RBAC / cloud IAM

Free role-based access controls built into your OS and cloud.

Covers: Req 7

Free, open-source identity, policy, and access management.

Covers: Req 7, Req 8

Free, open-source identity provider with MFA and single sign-on.

Covers: Req 8, Req 7
Requirement 8

Identify & authenticate users

Unique IDs, strong authentication, and multi-factor for remote/admin access.

Free, open-source identity, policy, and access management.

Covers: Req 7, Req 8

Free TOTP multi-factor authentication.

Covers: Req 8

Free password managers for strong, unique credentials.

Covers: Req 8

Free, open-source identity provider with MFA and single sign-on.

Covers: Req 8, Req 7
Requirement 9

Restrict physical access

Control physical access to systems, media, and the premises that handle card data.

Free templates for physical-access procedures and logging.

Covers: Req 9, Req 12
Requirement 10

Log & monitor

Record access to systems and card data, protect the logs, and review them.

Free, open-source SIEM with log analysis and file-integrity monitoring.

Covers: Req 10, Req 11

Free log aggregation, search, and alerting.

Covers: Req 10

Free endpoint visibility and querying for monitoring.

Covers: Req 10

Free dashboards and alerting over logs and metrics.

Covers: Req 10

Free file-integrity monitoring.

Covers: Req 11, Req 10
Requirement 11

Test security regularly

Vulnerability scans, penetration tests, and file-integrity monitoring.

Free tools to test the strength of your TLS setup.

Covers: Req 4, Req 11

Free, open-source SIEM with log analysis and file-integrity monitoring.

Covers: Req 10, Req 11

Free internal vulnerability scanner.

Covers: Req 11

Free network and port discovery for audits.

Covers: Req 11, Req 1

Free web-application security scanner (DAST).

Covers: Req 11, Req 6

Free file-integrity monitoring.

Covers: Req 11, Req 10

Quarterly external scans must use a PCI SSC Approved Scanning Vendor, and pen testing is a paid service — not free, though some vendors offer trials. Start from the official ASV list.

Covers: Req 11
Requirement 12

Policies & program

Security policies, risk assessment, awareness training, and vendor management.

Free templates for physical-access procedures and logging.

Covers: Req 9, Req 12

Free, ready-to-adapt security policies, legal contracts, and audit-evidence templates.

Covers: Req 12

Free risk-register starting point and security-awareness materials.

Covers: Req 12

No matching requirements.

Not sure which SAQ you need? Find out →