Home / For Business / Device inventory template
Most businesses have a half-finished list of their card readers — a few serials in a notebook, the rest in someone’s head. This free template gives you a clean starting point: one row per reader, spares included. No sign-up, no email, nothing to install — fill it in once and it imports straight into SkimGuard. It’s also the device list PCI asks for (Requirement 9.5.1.1).
Why it matters
It’s just an up-to-date list of the card readers you run — detailed enough that anyone can tell one from another and confirm the reader in front of them is the one that’s supposed to be there. That’s what PCI’s 9.5.1.1 asks for.
That last part is the whole point. If you can’t say which serial number belongs in which spot, someone could swap a reader for a tampered one and you’d never know. The list isn’t paperwork for its own sake — it’s what makes catching a swap possible at all.
What goes in the list
Here are the columns in the template, in the order the importer reads them. The header names aren’t fussy — serial, serialNumber, serial_number and SN all mean the same thing, and anything it doesn’t recognise is simply ignored — but these are the names the download comes with.
What is not a column
You pick the location when you run the import, so one file covers one site. Keep a separate file per site and the mapping stays obvious.
Also chosen at import time — a file goes in either as devices deployed into positions, or straight into your spares pool. So run two imports per site: one for what is on the floor, one for what is in the cupboard.
Inspection cadence is not set per row. It resolves from an org-wide baseline, overridden per location and then per device only where the risk genuinely differs. Set the baseline once. Not sure what yours should be? The free inspection cadence assessment gives you the written justification 9.5.1.2.1 expects.
The part people miss
This covers every reader you own — not just the ones plugged in right now.
A reader sitting in a back-office drawer as a spare is still yours, still has a serial, and could still be swapped for a tampered one before it goes into service. Same goes for readers out for repair, ones in transit between sites, and ones you’ve retired but haven’t destroyed yet.
A lot of businesses list the readers on the floor and stop there. Then a spare goes into a lane, its serial doesn’t match anything on the list, and the swap check quietly stops working. Import your spares as their own file, so every reader you own has a record from day one. After that, putting one into service just updates the record it already has — and its history follows it.
Where a spreadsheet runs out
A spreadsheet can get a single site through an assessment. It gets harder at ten sites — and it stops working the moment someone asks you to prove the file wasn’t edited after the fact. SkimGuard’s business plans include an inspection logbook that holds this same list, follows each reader through deploy, move, repair, spare, and retirement with a history that can’t be changed, and keeps a who-did-what-when record of the kind PCI 10.2 and 10.3 look for — exportable to CSV or PDF for your assessor. It’s included in every plan at no extra cost, and this template uses the exact columns the importer reads, so importing what you’ve already filled in is the whole setup.
Questions
Yes. The rule (9.5.1.1) covers every reader you operate — including spares, ones out for repair, ones in transit, and retired ones you still have. Give each one a record; with this template, import your spares as a separate file so they exist from the start.
Enough to tell one reader from another and tie it to a place: at least the make, the model, the serial number (or another unique ID), and where it is. Most businesses also add an internal asset tag and the exact spot the reader sits in — that’s what makes a swapped device stand out.
The rule doesn’t require any particular tool, and a spreadsheet is a fine place to start for one site. The catch is proof: a spreadsheet can be edited without a trace, so it shows what you believe today — it doesn’t prove what was recorded and when. Businesses with several sites, or an assessor who asks how the record is protected, usually move to a system that keeps a history that can’t be changed.
The list is what makes an inspection worth anything. PCI 9.5.1.2 asks you to check readers regularly for tampering and swaps — and you can only spot a swap if you already know which serial belongs in which spot. Build the list first; the inspection routine sits on top of it.
Yes, free to download, use, modify and share, with no account and no email required.
SkimGuard, Inc. is not a Qualified Security Assessor and does not perform PCI assessments. This template and page are intended to help you document and evidence device-inventory activity under PCI DSS v4.0.1 Requirement 9.5.1.1. They are not an attestation or certification of PCI compliance and do not cover the other requirements in your cardholder-data environment. Your compliance is assessed by your QSA or acquirer.