Use case · Payment devices

Every payment device,
tracked and provable.

Meet PCI DSS Requirement 9 with confidence. Tag every card terminal and PED with a tamper-evident QR code, enforce scheduled check-ins, and keep an immutable audit trail your assessor can't argue with.

PCI DSS Req. 9 Tamper-evident tags Immutable audit trail
app.qr-inventory.com / device / PED-00731
PED-00731 · Card payment terminal

Ingenico Move/5000

Checked in Seal intact
LocationStore 042 — Lane 3
SerialSN 19-4471-882
Last check-in02 Jun 2026 · 08:11
Next due09 Jun 2026
Device activity
Weekly check-in — seal verified intact
02 Jun 2026 · 08:11 · R. Okafor
Returned from authorised repair
28 May 2026 · 14:30
Deployed to Store 042, Lane 3
11 Apr 2026 · 09:02
Check-in rate
100% this period
Seal status
Tamper-evident

Trusted by retailers, hospitality groups and payment operators who get assessed

KayOne Industries Sirona Care & Health Gummifabriken Värnamo AB The Jamie Lloyd Company
PCI DSS Requirement 9

A device inventory that holds up under assessment.

PCI DSS requires you to maintain an accurate inventory of every card-reading device, inspect it for tampering and substitution, and periodically verify each one is where it should be. A spreadsheet of serial numbers won't survive a QSA's questions. QR-Inventory turns each PED into a self-documenting record — scanned, checked and sealed.

Why it matters

A complete, current device register

Every POS terminal, card reader and PIN-entry device in one authoritative list — model, serial, firmware, location and custodian. Each device carries a unique tamper-evident QR tag, so identifying and verifying one takes a single scan, not a stock-take.

Why it matters

Evidence of monitoring, not just intent

Scheduled check-ins prove devices are inspected on a defined cadence. Every scan, seal-check, move and repair is written to an immutable log — so when an assessor asks "show me", you produce a dated history instead of a promise.

Capabilities

Everything you need for payment-device compliance.

Device inventory management

POS terminals, card readers and PIN-entry devices, each with a unique tamper-evident QR tag for instant identification.

Scheduled check-ins

Weekly or monthly verification reminders confirm each device is present, sealed and operational — on a cadence you set.

Immutable audit trail

Every location, check-in, repair and status change is appended and time-stamped — ready for any PCI DSS assessment.

Device lifecycle tracking

Record when devices are deployed, sent for authorised repair, swapped or decommissioned — a complete chain of custody.

Tamper-evident security

Metalised, tamper-evident QR labels leave clear visual evidence of any attempt to remove or alter the seal.

Compliance reporting

Device inventories, check-in compliance rates and full audit trails, exported in the formats your assessor expects.

Requirements we address

Mapped to PCI DSS Requirement 9.5.1.

PCI DSS v4.0.1 is specific about how point-of-interaction (POI) devices that capture card data via direct physical interaction must be inventoried, inspected and protected. Here's where QR-Inventory does the heavy lifting.

9.5.1
Requirement 9.5.1

Protect POI devices

POI devices that capture payment card data are protected from tampering and unauthorised substitution, with evidence captured whenever a device changes.

9.5.1.1
Requirement 9.5.1.1

Up-to-date device list

Maintain a current inventory of every POI device — make and model, location, and serial number or other unique identifier — kept accurate as devices are added, moved or retired.

9.5.1.2
Requirement 9.5.1.2 / 9.5.1.2.1

Periodic inspections

Surfaces of POI devices are inspected periodically to detect tampering and substitution, at a frequency defined by a targeted risk analysis performed under Requirement 12.3.1.

9.5.1.3
Requirement 9.5.1.3

Staff training

Personnel in POI environments are trained to be aware of attempted tampering or replacement, with clear procedures and an auditable record of device checks.

QR-Inventory produces the defensible record that proves your device inventory was kept current and your inspections happened. It does not, by itself, make you PCI DSS compliant — requirement references here are indicative, and your scope, inspection frequency and validation route should be confirmed with your QSA or acquiring bank.

Tamper-evident QR-Inventory tag on a card payment terminal (PED)
Tamper-evident tags

If a seal is broken, you'll know.

Our metalised QR labels are engineered to fracture on removal, leaving unmistakable visual evidence of tampering. Bound to the device record, each tag turns a routine scan into a documented integrity check.

  • Visible, irreversible evidence of seal removal
  • Each tag uniquely bound to one device record
  • Seal status captured at every check-in scan
  • Alerts raised the moment a tamper is reported
Chain of custody

An unbroken record, written as it happens.

Nothing is editable after the fact. Every inspection, seal check, redeployment and repair is appended, attributed and sealed — so the device history you hand an assessor is the history that actually happened.

Tamper-evident by design

Each entry is hashed and chained to the last. Any alteration is detectable.

Time-stamped & attributed

Who, what, where and when — captured automatically at the point of scan.

Defensible in any PCI DSS assessment

Export a complete, signed evidence pack for one terminal or every device in scope.

PED-00731 · Immutable ledger Sealed
02 Jun 08:11
Check-in Weekly inspection — surfaces, ports & seal intact (R. Okafor)
sha256 · c1f4…90ab
28 May 14:30
Return Returned from authorised repair — serial re-verified
sha256 · 7b22…4e1d
19 May 08:04
Check-in Weekly inspection — pass, photo attached
sha256 · a908…5c77
11 Apr 09:02
Deployed Device registered & deployed to Store 042, Lane 3 by System
sha256 · 0000…root
Why QR-Inventory

Compliance that deploys in an afternoon.

Built for teams who need to be audit-ready quickly — and stay that way as they scale.

Instant implementation

Apply the tags, register the devices, start tracking. No heavy rollout, no new hardware and no integration project standing between you and a current inventory.

Mobile-first check-ins

Staff scan with any phone or tablet, on the shop floor or behind the counter — so the inspection happens where the device is, not back in an office.

Works with patchy signal

Scanning and check-in capture work offline in basements, stockrooms and back-of-house, then sync automatically once a connection returns.

Scales 10 to 10,000

From a single store to a national estate — one register, one set of controls and one place to see which sites are behind on their inspections.

Expert support

A team that understands PCI DSS device requirements and can configure check-in cadences to the scope you have agreed with your QSA.

Exception-led dashboards

Check-in rates by site and device class, with overdue inspections surfaced first — so you fix the gap before it becomes a finding.

How it works

Tag it. Check it. Prove it.

The terminal becomes the front door to its own record — no logins to hunt for, no device spreadsheet to find.

STEP 01

Tag & register

We map your device estate on a scoping call. You apply a tamper-evident QR tag to every terminal and register its make, model, serial and location.

STEP 02

Check in

Set the cadence your risk analysis supports. Staff scan each device to confirm it is present, inspect its surfaces and record that the seal is intact.

STEP 03

Prove

Track check-in rates, catch exceptions early, and export a dated inspection history for one terminal or every device in scope.

Who it's for

Built for card-present environments.

Retail & convenience

Every lane, every store, one register.

Tills, handheld readers and unattended terminals tracked across every branch, with check-in rates per store — so a site that quietly stops inspecting surfaces on your dashboard, not in an assessment.

  • Per-store device registers and check-in rates
  • Serial and location kept current as devices move
  • Seal state captured at every scan
  • Exception dashboard for branches falling behind
Pricing

One subscription. The whole ledger.

Every plan includes unlimited check-ins, the immutable audit trail and evidence-pack exports. You scale by devices and people — not by feature paywalls.

Starter
For small teams getting their register audit-ready.
£49/ mo, billed yearly
  • Up to 250 assets, 5 users
  • Inspections, certificates & audit trail
  • £59 / month if billed monthly
Enterprise & bespoke
For estates, public bodies and safety-critical operators.
Custom
  • Unlimited assets, SSO / SAML & SCIM
  • API & ERP/CAFM integrations
  • Bespoke builds for non-standard operations

All prices exclude VAT. Compare plans in full →

Security & governance

Enterprise controls. Public-sector grade.

The record is only as valuable as it is trustworthy. QR-Inventory is built to satisfy procurement, IT and audit from day one.

Immutable audit log

Append-only, hash-chained events that cannot be altered or back-dated.

Role-based access

Granular permissions by team, store and device class. Least-privilege by default.

SSO & SAML

Connect your identity provider — Microsoft Entra, Okta or Google Workspace.

UK data residency

Data hosted in the UK, processed in line with UK GDPR.

Open API & exports

Your data is yours. Sync to your ERP/CAFM or export in full at any time.

Backups & uptime

Continuous backups and a 99.9% uptime commitment on Business plans and above.

ISO 27001 aligned UK GDPR Cyber Essentials aligned UK data centres
FAQ

PCI DSS device tracking, answered.

Does QR-Inventory make us PCI DSS compliant?
No tool does. QR-Inventory gives you the current device inventory and the dated, attributed inspection evidence that Requirement 9.5.1 asks you to produce. Your scope and validation route are confirmed with your QSA or acquiring bank.
How often do POI devices need inspecting for tampering?
PCI DSS does not fix one frequency. Under Requirement 9.5.1.2 the inspection frequency comes from a targeted risk analysis performed under Requirement 12.3.1. QR-Inventory lets you set the cadence you have justified — weekly, monthly or otherwise — and then evidences that it was actually kept.
What has to be in the device inventory?
Requirement 9.5.1.1 asks for a list of POI devices covering make and model, location, and serial number or other unique identifier, kept accurate as devices are added, moved or retired. Each QR tag carries that record, so updating it is a scan rather than a spreadsheet edit.
How does a tamper-evident tag help with the inspection itself?
The metalised label is engineered to fracture on removal, so a substituted or opened device leaves visible evidence. Because the tag is bound to one device record, scanning it captures the seal state, the time, the location and the person inspecting — turning a visual check into a logged one.
Can we prove staff were trained to spot tampering?
Yes. Requirement 9.5.1.3 covers awareness training for personnel in POI environments. Training records sit against each person, and every check-in is attributed to whoever performed it — so you can show both the training and the checks it led to.

Make PCI DSS device tracking a non-event.

See how QR-Inventory keeps every payment terminal inventoried, inspected and provable — in a 30-minute walkthrough with our team.