Skip to content

How to audit software and hardware

Brock
Brock Bingham|Updated August 26, 2026
Product2 2026
Product2 2026

TL;DR: A software and hardware audit verifies the devices, operating systems, updates, applications, and configurations in your environment. PDQ helps you collect current endpoint inventory, identify outdated or unexpected systems, and compare device data against the security and compliance requirements your organization uses.

A software and hardware audit gives you an accurate picture of the devices, operating systems, applications, and configurations in your environment. PDQ can collect that inventory centrally, helping you prepare audit evidence without manually checking every endpoint.

Better yet, you can do it from the comfort of your meticulously contoured derriere cushion. No walking required.

What should you check before a security audit?

The exact evidence you need depends on your organization's policies and compliance requirements, but most security audits start with a few common endpoint checks. PDQ can help you collect this information and identify devices that need further review.

Audit check

What to review in PDQ

What to look for

Asset inventory

Device name, manufacturer, model, serial number, and operating system

Unknown, missing, duplicate, or unexpected devices

Inventory freshness

Last seen and device status

Devices that haven’t checked in recently or may no longer be active

Operating systems

OS edition and OS version

Unsupported, outdated, or unapproved operating systems

Windows updates

Windows updates inventory and installation status

Not installed, failed, pending reboot, or unexpectedly in-progress updates

Software inventory

Installed applications and versions

Unapproved, missing, or outdated software

Vulnerability exposure

Vulnerabilities, affected devices, risk scores, CVSS scores, known exploits, and remediation status

Unresolved vulnerabilities, especially high-risk or known-exploited vulnerabilities

Security software

Installed software or custom scanner data

Missing, outdated, disabled, or unexpected endpoint security tools

Configuration data

Custom PowerShell or Registry Scanner results

Devices that don’t match your organization’s required configuration

Storage health

Disk free space

Devices with critically low disk space that could interfere with updates or other maintenance

These checks do not determine whether your organization complies with a specific framework. Instead, they give you endpoint inventory and configuration evidence you can compare against the controls and policies that apply to your environment.

How to identify devices that need attention automatically

Dynamic groups and scheduled reports can help you continuously identify endpoints that fall outside your organization's requirements instead of rebuilding the same audit every time.

  1. Create a dynamic group for the condition you want to monitor. For example, you might group devices with low disk space, an outdated application, or an operating system version your organization no longer supports.

  2. Create a report for the devices or group you want to monitor. Include the device and inventory columns that explain why each endpoint needs attention.

  3. Schedule the relevant report to run on a recurring basis. Add the appropriate email recipients so PDQ automatically sends updated results to the people responsible for reviewing them.

  4. Remediate devices when appropriate. You can target device groups with deployments or automations to update software, uninstall unwanted applications, or run other approved remediation packages. For missing Windows updates, use the Windows updates tab to review update status and initiate installations.

  5. Export audit evidence when needed. Open a relevant report and select Export.csv from the kebab menu in the upper right corner to save the current results for an auditor or another reporting system.

For cross-tool workflows, PDQ integrates directly with ITSM and ticketing platforms such as Jira, Freshdesk, Freshservice, ServiceNow, Zendesk, and Halo. PDQ also integrates with Zapier, which can connect PDQ with thousands of other applications, such as Slack, to automate workflows across your stack. For example, you could notify your team when devices meet certain criteria or create a ticket for follow-up.

ConnectIcon CTA

Manage Windows & macOS devices from anywhere

With PDQ Connect, get real-time visibility into remote and local devices, deploy software, remediate vulnerabilities, automate routine maintenance, and remotely troubleshoot endpoints from one easy-to-use platform.

What should you include in a software and hardware audit?

Before a software and hardware audit, define the audit objective, the endpoint data you need, and the format required for your results. Collect only the information needed to answer the audit requirements so you do not create unnecessary work for your team or the auditor.

It’s very easy to start an audit by collecting way more information than necessary. But overwhelming yourself, or an auditor, with too much data only creates more work in the long run, which is the opposite of what we want. And I would never recommend intentionally overwhelming an auditor with more information than they need in hopes they’ll overlook some shortcomings you didn’t want them to see (not based on a real-life experience).

For this article, we’ll do a general audit of endpoint hardware and software, identifying needs and uses. Here are some of the data points we’re interested in gathering for our general audit:

  • Endpoint count

  • Hardware types

  • Operating systems

  • Disk usage

  • Critical disk usage

  • App installs

How to track endpoint counts with PDQ

PDQ gives you a current count of the workstations, servers, and other endpoints you manage from the Devices page. An accurate endpoint count helps with audit evidence, capacity planning, licensing, and understanding how many devices your IT team supports.

Gathering accurate computer and server counts without the right tools can be a painstaking task involving phone calls, detective work, and walking (shudders). But with a network inventory management tool like PDQ, it’s super easy, barely an inconvenience.

To check your endpoint count:

1. In PDQ, click Devices in the left navigation.

2. Review the devices currently managed in your environment.

3. Use filters or device groups if you need a count for a specific subset of endpoints, such as servers, workstations, or devices in a particular location.

If you need to document or share your endpoint inventory for an audit, you can also create a report:

1. Click Reports in the left navigation.

2. Select Create report.

3. Name your report and select Standard.

4. Add the device columns you need and select the devices or groups you want to include.

5. Set a schedule if you want the report to run automatically, then click Save and run.

How to track hardware makes and models with PDQ

As your organization grows, you will accumulate many different makes and models of computers. PDQ simplifies tracking the various devices deployed on your network.

On the Devices page, you can display the Manufacturer and Model columns to see this information across your managed devices.

Or, to generate a report:

1. Go to Reports > Create report

2. Name your report and select Standard.

3. Include the following columns:

  • Device: Name

  • Device: Manufacturer

  • Device: Model

5. Select your target.

6. Click Save and run.

How to audit operating systems with PDQ

An operating systems report can be a great resource when auditing your operating systems, especially when you have devices running operating systems reaching their end-of-life date.

1. In PDQ, click Reports in the left navigation.

2. Click Create Report.

3. Give the report a name, such as Operating Systems Report.

4. For Type, select Standard.

5. Click Select columns.

6. Add these Device columns:

  • Device: Name

  • Device: OS edition

  • Device: OS version

  • Device: SP/Release

7. To make the report easier to scan, select Group by for OS version or OS edition. This groups devices running the same operating system together.

8. Leave the target set to All Devices unless you only want to report on a specific group.

9. Click Save and run.

How to monitor disk usage with PDQ

Low disk space can cause all sorts of problems, from failed updates to sluggish performance. PDQ makes it easy to find devices that are running short on storage so you can address them before users start filing tickets.

1. In PDQ, go to Devices.

2. Click Filter.

3. Add a Disk partition filter and select free %.

4. Set the filter to show devices with less than your preferred amount of free disk space, such as:

  • Less than 20% for an early warning.

  • Less than 10% for devices that need more immediate attention.

5. Apply the filter and review the devices that are running low on disk space.

6. To monitor these devices over time, create a dynamic group using the same Disk free % criterion.

7. Give the group a clear name, such as Less than 20% free disk space.

PDQ automatically updates the dynamic group as devices meet or no longer meet the filter criteria, giving you an easy way to keep an eye on systems that are running low on storage.

If you’d rather export or share this information, go to Reports > Create report, select Standard, and add the relevant device and disk partition columns. Add a result filter for your free-space threshold, then choose your target devices or groups and click Save and run.

How to track software installs with PDQ

Keeping track of software across your environment can get messy fast. PDQ simplifies the process by inventorying installed applications and giving you a centralized view of what’s installed, what’s missing, and which versions are outdated.

1. In PDQ, open the Software page.

2. Find the application you want to check. Review the application counts for:

  • Installed: Any version of the application is installed.

  • Latest: The latest version is installed.

  • Outdated: An older version is installed.

  • Not installed: The application is missing from a device with a compatible operating system.

3. Click any of the counts to see the corresponding software installations and devices.

Note: Installed, Latest, and Outdated are counts of software installations, so a device with multiple versions of the same application may be counted more than once. Not installed represents a device count.

4. Use the filters or search options to narrow the results if needed.

This gives you a quick way to answer questions like, "Which devices have Chrome installed?" or "Which devices are still running an outdated version of 7-Zip?"

If you need a more detailed or exportable view, you can also create a Standard report. Go to Reports, create a new report, and select Software as the additional column source. Add the software and device columns you need, then group the results by application name, version, or device. You can also export the finished report as a CSV.

Software and hardware audit FAQs

What should you look for in an endpoint management tool for security audits?

An endpoint management tool for security audits should provide current hardware and software inventory, operating system and patch data, configurable device groups, reporting, and exportable evidence. PDQ helps IT teams collect this endpoint data, identify devices that need attention, and prepare audit evidence from a centralized platform.

How can I prepare devices for a security or compliance audit?

Prepare devices for a security or compliance audit by verifying your asset inventory, identifying unsupported operating systems and outdated software, reviewing patch status, checking required configurations, remediating exceptions, and exporting supporting evidence. For frameworks such as SOC 2 or FedRAMP, compare that evidence against the specific controls and requirements that apply to your environment.

How do you prove patch compliance for a SOC 2 audit?

To support patch compliance during a SOC 2 audit, maintain evidence showing which devices were in scope, which missing updates or vulnerabilities were identified, what remediation occurred, when patches were deployed, and whether deployment succeeded. Document approved exceptions and map the evidence to the controls included in your SOC 2 examination.

Don’t let audits get you down

The best way to approach an audit is to have everything ready before the process even starts. PDQ makes it easy to create the groups and reports you need to be successful in your next audit. Best of all, you can do it all from the comfort of your office chair.

If you’ve got an audit coming up, it’s not too late. You can try PDQ for free for 14 days. You’ll be up and running in minutes and have plenty of time left over to think about all the awkward conversations with coworkers that you’ll be able to avoid thanks to PDQ.

Brock
Brock Bingham

Brock Bingham is a systems administrator with 15 years of experience managing endpoints and servers, with a strong focus on automation, patching, security, and maintaining stable environments at scale. After years of hands-on IT work, he now creates content and teaches, helping other admins learn through practical, real-world guidance.

Related articles