Third-Party Software
PCIComplianceHubLast updated
Software an entity acquired rather than had written for it: purchased, open source, freeware or shareware. It is the counterpart of bespoke and custom software, and it carries the Requirement 6 obligations that apply to any software plus one about knowing where it came from.
Applies to. Every in-scope system, since every one runs some.
Example. An open-source web framework, a bought database engine and a vendor's payment SDK are third-party software. 6.3.1 requires their vulnerabilities to be identified from industry sources and risk-ranked; 6.3.3 requires patches for critical ones within a month. Where the entity's own software incorporates third-party components, 6.3.2 requires an inventory of them.
Limits. Acquiring software does not outsource its security: the vendor's patch is the entity's to apply. 6.3.2's component inventory, mandatory since 31 March 2025, is the control most entities had never kept, and it is what lets a newly announced library vulnerability be matched to the systems that carry it. Software the entity paid a third party to write for it is bespoke, not third-party, and falls under 6.2 as well.