All solutions Solution · PCI DSS

PCI DSS: the scan is only the beginning

Anyone processing payment card data needs more than a passing scan: a defined scope, justified exceptions, documented clarifications and evidence that the chain of quarterly scans has not broken. isidaten brings the requirement catalog, environment and scan management together.

Request a demo
Background

What PCI DSS requires

PCI DSS applies to every entity that stores, processes or transmits cardholder data. The standard comprises 12 requirements bundled into six goal areas, from network security through protection of account data to the information security policy. For the external attack surface, requirement 11.3.2 mandates quarterly vulnerability scans by an Approved Scanning Vendor. In practice compliance rarely fails on the scan itself but on what surrounds it: a scope that is not justified, excluded components without explanation, or a gap between two quarters.

12 requirements across six goal areas (PCI DSS v4.0.1)Defined cardholder data environment (CDE)Quarterly external ASV scans (requirement 11.3.2)Justification for components excluded from the scan scopeRescans until a passing result, attestations on fileAn unbroken chain of quarterly scans across the year
FAQ

Frequently asked questions

Who does PCI DSS apply to?

To every entity that stores, processes or transmits cardholder data, merchants as well as service providers. The extent of the evidence obligations depends on the level and transaction volume; the requirements for securing the cardholder data environment apply regardless.

What is an ASV scan?

An external vulnerability scan by a provider approved by the PCI Security Standards Council, an Approved Scanning Vendor. Requirement 11.3.2 mandates it quarterly and after significant changes. A result is valid for 90 days, after which the next scan is due.

Does isidaten replace the ASV?

No. The scan is still performed by an approved vendor. isidaten manages what surrounds it: scan scope with justification for exceptions, findings with the scoring rules, rescan chains, attestations, report storage and reminders 30, 14 and 7 days before the due date.

Does the catalog contain the original PCI SSC texts?

No. Only the official numbering is adopted; the requirement texts are our own German summaries. Licensed original texts can be added through the OSCAL catalog management. PCI DSS is a trademark of the PCI Security Standards Council, LLC.

Ready to simplify your compliance?

Schedule a no-obligation demo and experience isidaten with your own use cases – personally and without commitment.