PCI DSS: the scan is only the beginning
Anyone processing payment card data needs more than a passing scan: a defined scope, justified exceptions, documented clarifications and evidence that the chain of quarterly scans has not broken. isidaten brings the requirement catalog, environment and scan management together.
What PCI DSS requires
PCI DSS applies to every entity that stores, processes or transmits cardholder data. The standard comprises 12 requirements bundled into six goal areas, from network security through protection of account data to the information security policy. For the external attack surface, requirement 11.3.2 mandates quarterly vulnerability scans by an Approved Scanning Vendor. In practice compliance rarely fails on the scan itself but on what surrounds it: a scope that is not justified, excluded components without explanation, or a gap between two quarters.
How isidaten maps PCI DSS
Each requirement meets a module that runs on the same object base as the risk register, so the evidence stays connected instead of copied across tools.
Assess and evidence requirements
The requirement catalog is available OSCAL-natively. The cockpit shows tool coverage and fulfilment level per requirement, with manual override where an assessment differs on professional grounds.
View module: Security AutomationKnow your attack surface before the ASV scans
The readiness comparison places your own view of the external attack surface next to the scan scope. What is missing surfaces before the quarterly scan, not after.
View module: Attack Surface ManagementEvidence network segmentation
Document firewall rules across multiple vendors, because the boundary of the cardholder data environment stands and falls with them.
View module: Firewall ManagementHandle vulnerabilities
Assess findings from scans and document their treatment instead of merely collecting them.
View module: Vulnerability ManagementKeep systems hardened
Check configurations continuously against hardening benchmarks, including a PCI DSS profile, instead of once a year.
View module: Security Configuration ManagementManage policies
Keep the information security policy and its accompanying rules as controlled documents with approval and acknowledgement.
View module: Policy ManagementFrequently asked questions
Who does PCI DSS apply to?
To every entity that stores, processes or transmits cardholder data, merchants as well as service providers. The extent of the evidence obligations depends on the level and transaction volume; the requirements for securing the cardholder data environment apply regardless.
What is an ASV scan?
An external vulnerability scan by a provider approved by the PCI Security Standards Council, an Approved Scanning Vendor. Requirement 11.3.2 mandates it quarterly and after significant changes. A result is valid for 90 days, after which the next scan is due.
Does isidaten replace the ASV?
No. The scan is still performed by an approved vendor. isidaten manages what surrounds it: scan scope with justification for exceptions, findings with the scoring rules, rescan chains, attestations, report storage and reminders 30, 14 and 7 days before the due date.
Does the catalog contain the original PCI SSC texts?
No. Only the official numbering is adopted; the requirement texts are our own German summaries. Licensed original texts can be added through the OSCAL catalog management. PCI DSS is a trademark of the PCI Security Standards Council, LLC.
Ready to simplify your compliance?
Schedule a no-obligation demo and experience isidaten with your own use cases – personally and without commitment.