Security Operations

PCI DSS

Secure card data and evidence the quarterly scans without gaps

Anyone processing payment card data rarely fails on the scan itself but on what surrounds it. The PCI DSS module keeps the requirement catalog with 12 requirements across six goal areas as an OSCAL catalog and shows tool coverage and fulfilment level per requirement in the cockpit, with manual override. Added to this is management of the cardholder data environment: scan scope with mandatory justification for excluded components, quarterly scans with rescan chains and 90 days of validity, findings following the scoring rules of the ASV Program Guide, observations requiring explanation, attestations and report storage. Due-date reminders run 30, 14 and 7 days ahead and on overdue.

PCI DSS v4.0.1ASV Program Guide v4.0
Features

Your benefits

1

Requirements with coverage, not a checklist

The 12 requirements across six goal areas come as an OSCAL catalog. The cockpit shows which tools already evidence a requirement and where the fulfilment level is still open.

2

A scan scope that is justified

The cardholder data environment is kept with its components. Whoever excludes something from the scan scope must justify it, and that justification is exactly what an assessor asks for.

3

The chain of quarterly scans holds

A result is valid for 90 days. Rescan chains run until a passing scan, attestations and reports are filed, and reminders arrive 30, 14 and 7 days before the due date rather than after.

4

Scoring by the Program Guide rules

Findings are scored to the rules: CVSS threshold, automatic failures, the exception for denial-of-service checks and accepted clarifications. Observations require an explanation.

Capabilities

All capabilities at a glance

  • Requirement catalog: 12 requirements across 6 goal areas (OSCAL)
  • Cockpit with tool coverage, fulfilment level & manual override
  • Cardholder data environments (CDE) with components
  • Scan scope with mandatory justification for exceptions
  • Quarterly scans with rescan chains & 90 days validity
  • Finding assessment per ASV Program Guide (CVSS threshold, automatic failures, DoS exception)
  • Observations requiring explanation & accepted clarifications
  • Attestations and report storage
  • Due-date reminders 30/14/7 days ahead and on overdue
  • Readiness comparison against attack surface management (read-only)
Result

PCI DSS evidence no longer depends on the next scan but exists as a managed chain: scope justified, findings treated, attestations on file.

Experience PCI DSS live

Schedule a no-obligation demo – we will show you the module with your own use cases.