Requirements with coverage, not a checklist
The 12 requirements across six goal areas come as an OSCAL catalog. The cockpit shows which tools already evidence a requirement and where the fulfilment level is still open.
Secure card data and evidence the quarterly scans without gaps
Anyone processing payment card data rarely fails on the scan itself but on what surrounds it. The PCI DSS module keeps the requirement catalog with 12 requirements across six goal areas as an OSCAL catalog and shows tool coverage and fulfilment level per requirement in the cockpit, with manual override. Added to this is management of the cardholder data environment: scan scope with mandatory justification for excluded components, quarterly scans with rescan chains and 90 days of validity, findings following the scoring rules of the ASV Program Guide, observations requiring explanation, attestations and report storage. Due-date reminders run 30, 14 and 7 days ahead and on overdue.
The 12 requirements across six goal areas come as an OSCAL catalog. The cockpit shows which tools already evidence a requirement and where the fulfilment level is still open.
The cardholder data environment is kept with its components. Whoever excludes something from the scan scope must justify it, and that justification is exactly what an assessor asks for.
A result is valid for 90 days. Rescan chains run until a passing scan, attestations and reports are filed, and reminders arrive 30, 14 and 7 days before the due date rather than after.
Findings are scored to the rules: CVSS threshold, automatic failures, the exception for denial-of-service checks and accepted clarifications. Observations require an explanation.
PCI DSS evidence no longer depends on the next scan but exists as a managed chain: scope justified, findings treated, attestations on file.
Schedule a no-obligation demo – we will show you the module with your own use cases.