Platform Features — PCI DSS v4.0.1

Everything you need to get compliant —
and stay that way.

Six purpose-built pillars that take you from your first SAQ to a year-round compliance operation. No consultant required. No enterprise budget needed.

✦ Try the Live Demo Start Free Setup →
🗓 Compliance Calendar 🔎 Findings Tracker 🔌 Integrations 🗂 Active Directory 🤖 AI Tools 💰 Built for Your Budget

Compliance Calendar &
Deadline Management

PCI DSS v4.0.1 is a year-round obligation, not an annual checkbox. PCINexus tracks every deadline automatically — so nothing expires quietly in the background while you're running a business.

Every deadline. Every requirement. One calendar.

Between quarterly scans, annual pen tests, daily log reviews, and recurring training obligations, a small business has dozens of active PCI DSS deadlines running simultaneously. Miss one and your compliance status is in jeopardy. PCINexus surfaces all of them in a single view — with alerts before they lapse.

  • Quarterly ASV scan tracking — Req 11.3. Expiry date tracked, renewal alert at 60 days.
  • Annual penetration test scheduling — Req 11.4. Assigned to owner, tracked through completion.
  • Certificate & document expiry alerts — SSL certs, vendor attestations, and policy documents flagged before they lapse.
  • Annual security awareness training — Req 12.6. Completion tracked per employee across all locations.
  • Daily log review obligations — Req 10.7. Dashboard reminder and evidence log to prove ongoing compliance.
  • 60-day cycle rollover prompt — Start your next compliance year before the current one expires.
🗓
Upcoming Compliance Deadlines
All locations · Next 90 days
ASV Scan — Downtown Flagship Overdue
SSL Certificate Renewal 12 days
Annual Pen Test — All Locations 28 days
Security Training — Northside On Track
Compliance Cycle Rollover 58 days

Findings & Remediation
Project Management

Every compliance gap is a project. PCINexus treats it that way — assigning findings to owners, tracking remediation progress, and generating the documentation trail your auditor needs to see.

Compliance gaps don't close themselves.

A QSA or an internal review will surface findings — requirements that aren't fully met, evidence that doesn't satisfy the standard, or controls that need to be implemented. Without a structured tracker, those findings get written down somewhere and forgotten. PCINexus turns every finding into an assigned, tracked, accountable work item.

  • Finding creation & classification — severity levels, affected requirement, affected location.
  • Owner assignment — each finding routed to the responsible person. No more ambiguity about who owns what.
  • Remediation status tracking — Open, In Progress, Resolved, Accepted Risk. Full audit trail of every status change.
  • Due date management — deadlines set, tracked, and escalated if missed.
  • Evidence attachment — resolution documentation uploaded directly to the finding record.
  • Executive summary view — L1 and L2 users see open findings count, severity breakdown, and overdue items across all locations at a glance.
🔎
Open Findings — All Locations
4 open · 2 in progress · 1 overdue
MFA not enforced — Admin accounts Critical
Firewall ruleset undocumented — Req 1.2 High
Stale accounts >90 days — Northside High
Patch policy documented — In Progress In Progress
Security training — Airport Terminal Resolved

Security Tool Integrations —
Free & Low-Cost First

You don't need a $50,000 security stack to be PCI DSS compliant. PCINexus integrates with the tools your business can actually afford — pulling evidence automatically so compliance doesn't require a dedicated IT team.

Our philosophy on vendor tools:

PCI DSS does not require expensive tools — it requires effective controls. Every integration in PCINexus was selected because it satisfies a specific PCI DSS requirement at the lowest possible cost. Open-source and free tools are always recommended first. Mid-market and enterprise tools are listed for organizations that already have them — never pushed as the default.

🔌
1 — Pull

PCINexus connects to your security tools via API, agent, or syslog and pulls raw data on demand or on a schedule you control.

🔍
2 — Review

Every data pull is presented for human review — mapped to its specific PCI DSS requirement with a plain-English summary of what was found.

3 — Approve

Only after explicit approval does data enter your compliance record. Nothing is auto-accepted. Your evidence trail stays clean and auditable.

Req 1 & 2 — Network Security & Configuration
Data pulled: firewall rules, config files, network topology, deny-all defaults

pfSense / OPNsense

Free / Open Source

Pulls firewall ruleset, interface config, and traffic logs. PCINexus maps rules against Req 1.2 requirements and flags missing deny-all defaults or undocumented rules.

Fortinet FortiGate

Mid-Market

Pulls firewall policy, FortiGuard threat logs, and configuration backup. Full Req 1 evidence package generated automatically from the API connection.

Syslog / Generic Push

Free / Universal

Any network device — router, switch, firewall — that supports syslog can feed PCINexus directly. Covers Req 1 and Req 10 simultaneously with zero additional tooling.

Cloudflare Gateway

Free Tier

DNS filtering and zero-trust network access. Pulls DNS query logs and blocked domain records for Req 1 perimeter evidence. Free tier covers most small merchant environments.

Pi-hole

Free / Open Source

Self-hosted DNS blocker. Pulls query logs and blocklist status to demonstrate DNS-level malware protection for Req 1 network defense evidence.

WireGuard / OpenVPN

Free / Open Source

VPN access logs pulled for Req 8 remote access evidence. Demonstrates encrypted tunnels for all remote administrative access to the CDE.

Req 5 — Anti-Malware & Endpoint Protection
Data pulled: AV status, threat detections, last scan time, policy compliance

Microsoft Defender

Built-In / Free

Already on every Windows machine. Pulls real-time protection status, last scan timestamp, threat detection history, and policy settings for Req 5 evidence with zero additional cost.

ClamAV

Free / Open Source

Antivirus for Linux-based POS systems, servers, and appliances. Pulls scan results and definition update status for Req 5 evidence on non-Windows endpoints.

CrowdStrike Falcon

Enterprise

For organizations already running Falcon. Pulls endpoint telemetry, threat intelligence, and detection events directly into Req 5 and Req 11 evidence records.

Req 6 — Vulnerability Management
Data pulled: scan results, CVE findings, severity ratings, patch status

OpenVAS / Greenbone

Free / Open Source

Full internal vulnerability scanner with no per-scan fees. PCINexus pulls scan reports, CVE findings, and remediation status directly into Req 6 and Req 11.3 evidence records.

Nessus Essentials

Free ≤ 16 IPs

Industry gold-standard scanner, free for up to 16 IPs. Covers the entire CDE for most small merchants. Auditors know the name immediately — high-credibility evidence source.

Qualys VMDR

Mid-Market

Cloud-managed scanning for organizations that prefer not to run their own scanner. Pulls scan reports, asset inventory, and patch status directly into PCINexus compliance records.

Req 7 & 8 — Access Control & Authentication
Data pulled: MFA status, user accounts, access logs, password policy, auth events

Active Directory / LDAP

Built-In / Free

Pulls user accounts, groups, stale accounts, password policy, and OU structure. Full Req 7 and Req 8 evidence package — account inventory, access groups, and policy compliance in one pull.

Duo Security

Free ≤ 10 Users

Pulls MFA enrollment status, authentication logs, and policy configuration. Req 8.4 requires MFA for all CDE access — Duo provides the evidence automatically.

Authelia

Free / Open Source

Self-hosted SSO and MFA gateway — no per-user fees. Pulls authentication events and policy config for Req 8 evidence. Best option for businesses with more than 10 users who can't afford Duo.

Bitwarden

Free / $3/mo Teams

Password manager with auditable vault. Pulls policy enforcement status and shared credential records to demonstrate Req 8.3 password management controls.

FreeRADIUS

Free / Open Source

RADIUS authentication server for network access control. Pulls authentication logs and policy data — demonstrates MFA enforcement for network device and VPN access under Req 8.

Req 10 — Logging & Monitoring
Data pulled: system logs, access events, admin actions, alert records, review confirmation

Wazuh

Free / Open Source

Central SIEM platform. Aggregates logs from every system, correlates events, and generates alerts. PCINexus pulls daily log review summaries and alert records directly for Req 10 evidence.

Security Onion

Free / Open Source

Bundles Wazuh + Suricata + Zeek into a single deployable stack. One install covers Req 10 and Req 11 completely. PCINexus pulls consolidated event data from the Security Onion API.

Zabbix

Free / Open Source

Network and system monitoring with alerting. Pulls uptime records, threshold alerts, and device availability logs for Req 10 continuity-of-monitoring evidence.

PRTG Network Monitor

Free ≤ 100 Sensors

Easiest-to-configure monitor on the list. Free tier covers most small environments. Pulls device status, bandwidth data, and alert history for Req 10 network monitoring evidence.

LibreNMS

Free / Open Source

Auto-discovers your network and monitors every device on it. Pulls network device logs, SNMP traps, and alert history into PCINexus for Req 10 continuous monitoring evidence.

Syslog / Generic Push

Free / Universal

Any device that can push syslog feeds directly into PCINexus. Zero additional tooling — if it logs, it connects. Covers any gap in your environment the dedicated tools don't reach.

Req 11 — Intrusion Detection & File Integrity
Data pulled: IDS alerts, FIM change records, scan results, anomaly events

Suricata

Free / Open Source

High-performance IDS/IPS. Pulls network intrusion alerts, signature matches, and anomaly events directly into Req 11.4 evidence records. Runs inline or passive — no disruption to operations.

Snort

Free / Open Source

The original network IDS — massive rule library, auditor-recognized name. Pulls detection events and rule match logs for Req 11.4 intrusion detection evidence.

Zeek (formerly Bro)

Free / Open Source

Network traffic analysis framework. Produces detailed connection logs, protocol summaries, and behavioral baselines that feed directly into Req 11 anomaly detection evidence.

Wazuh FIM

Free / Open Source

File Integrity Monitoring built into Wazuh. Detects unauthorized changes to critical system files — required under Req 11.5. If you're already running Wazuh, FIM is already active.

AIDE

Free / Open Source

Dedicated Linux file integrity monitor. Tracks changes to system binaries, config files, and CDE-relevant directories. Pulls change reports into Req 11.5 FIM evidence records.

Security Onion

Free / Open Source

Bundles Suricata + Zeek + Wazuh together. One deployment covers Req 10 log management and Req 11 intrusion detection simultaneously — the most efficient single tool for full coverage.

25+
integrated security tools
18
free or open source
$0
required tooling cost for full coverage

A complete PCI DSS v4.0.1 security stack is achievable at zero additional tooling cost. PCINexus connects to all of it — pulling data directly into your compliance record.

Active Directory &
User Management

Access control is one of the most scrutinized areas in any PCI DSS audit. PCINexus connects directly to your Active Directory — pulling users, groups, policies, and access data with full review before anything is imported.

Your AD is your compliance evidence. We make it usable.

Requirements 7 and 8 of PCI DSS v4.0.1 require demonstrating that access to cardholder data is restricted, that accounts are managed, that passwords meet policy, and that stale accounts are removed. Most businesses have this data in their Active Directory — but no way to pull it into a compliance record systematically. PCINexus does exactly that.

  • User account sync — active, disabled, and locked accounts pulled with full attribute data. Req 8.2.
  • Access group mapping — OU structure and group memberships documented for Req 7 access control evidence.
  • Stale account detection — accounts inactive for 90+ days flagged automatically. Req 8.2.6.
  • Password policy review — your current policy pulled and compared against PCI DSS v4.0.1 requirements. Req 8.3.
  • Service account inventory — non-human accounts documented and reviewed. Req 8.2.2.
  • Process owner approval — every AD import requires explicit approval before the data enters your compliance record.
🗂
Active Directory Sync
Last pulled 2 hours ago · Pending review
247 active user accounts pulled Ready
14 stale accounts (>90 days inactive) Action Needed
Password policy — min length 8 chars Below v4.0 Req
32 access groups mapped — Req 7 Ready
6 service accounts need review Pending

AI-Powered Evidence Review
& Compliance Guidance

PCINexus puts the equivalent of a PCI DSS specialist on your team — available 24 hours a day, at no extra cost. Two AI tools that work together to accelerate your path to compliance.

Stop guessing whether your evidence is good enough.

The two most common compliance problems for small businesses are (1) not knowing what evidence an auditor actually needs, and (2) submitting documents that don't satisfy the requirement. Both are expensive problems. The AI Evidence Review engine addresses both — instantly, on every upload, before you submit anything.

  • AI Evidence Review — upload any document and receive an instant PASS / FAIL / NEEDS REVIEW verdict with a plain-English explanation mapped to the specific PCI DSS v4.0.1 requirement.
  • Remediation recommendations — when evidence fails, the AI explains exactly what's missing and how to fix it.
  • AI Compliance Chat — ask any PCI DSS question in plain English. The assistant is locked exclusively to PCI DSS v4.0.1, so answers are always accurate and requirement-specific.
  • No hallucination risk — the chat assistant cannot wander into other standards or make up requirements. Scoped by design.
  • 24/7 availability — compliance questions don't wait for business hours. Neither does your AI assistant.
  • Powered by Anthropic Claude — the same AI that powers enterprise compliance tools, available to every PCINexus subscriber at every pricing tier.
🤖
AI Evidence Review
firewall_policy_march2026.pdf · Req 1.2
NEEDS REVIEW Req 1.2.1

The document describes firewall rules but does not include justification for each rule as required by Req 1.2.1. Add a business justification column to the rule table and resubmit.

PASS Req 1.3.2

Inbound and outbound traffic rules are documented with deny-all defaults confirmed. Satisfies network segmentation evidence requirement.

Built for your budget.
Not their bottom line.

Enterprise compliance tools were priced for enterprise budgets. The businesses that need PCI DSS compliance the most — independent restaurants, regional retailers, small hospitality groups — were never the intended customer. PCINexus was built specifically for them.

What you're probably doing now

QSA Consulting Firm

$6,500
per year · average for SMB merchants
  • Annual assessment only
  • No year-round management
  • You manage deadlines manually
  • Evidence scattered across email and folders
  • New consultant relationship every year
  • No platform to show your bank or auditor
PCINexus — Built for Main Street

PCINexus Starter

$125
per month · $750 for your first 6-month compliance cycle
  • Get compliant with the SAQ wizard
  • Year-round compliance calendar
  • AI evidence review on every upload
  • Findings & remediation tracker
  • Security tool integrations included
  • Centralized evidence portal
  • AI compliance chat — 24/7
  • Free setup — pay only when you go live
What everyone else is selling

Vanta / Drata / Secureframe

$499+
per month · minimum — if they'll even take your call
  • Built for cloud-native SaaS startups
  • Integrations built for AWS & GitHub
  • No SAQ workflow for physical merchants
  • No multi-location physical environment support
  • No Active Directory sync for on-prem
  • Budget designed for VC-funded companies

The math is straightforward. A QSA-assisted compliance program for a small merchant runs $3,000–$8,000 per year with no ongoing management platform and no evidence trail you own.
PCINexus replaces that with a purpose-built system at a fraction of the cost — and gives you something the consultant never could: a running compliance record your business owns, year after year.

Ready to see it in action?

The full platform is running live. Walk through a real compliance workflow for a multi-location restaurant group — no login required.

✦ Try the Live Demo Start Free Setup →