Education

What is PCI DSS?

PCI DSS is the Payment Card Industry Data Security Standard — a set of security requirements for organizations that store, process, or transmit cardholder data. This page is education. Secure Assess ships PCI DSS 11.3 vulnerability assessment and ASV-readiness PASS/FAIL — not a full PCI DSS 4.0 compliance program.

PCI DSS in plain terms

Merchants and service providers that handle payment card data are expected to meet PCI DSS controls across network security, access, monitoring, and testing. Version 4.0 is the current major revision of those standards. Meeting the full standard usually involves policies, technology, and assessments beyond any single scan product.

Where requirement 11.3 fits

Requirement 11.3 addresses vulnerability assessment — regularly identifying and addressing vulnerabilities in systems in scope. That is the shipping claim for Secure Assess: defensive external and credentialed VA, findings mapped to 11.3, scheduled scans, AI-triaged results, and a PDF report.

Requirement 11.4 addresses penetration testing — a different activity. Secure Assess does not perform PCI 11.4 pen testing.

What a vulnerability assessment can and cannot tell you

A VA can surface technical findings on systems you authorize: reachable services, versions, configuration issues, missing patches (when credentialed), ranked advice, and an ASV-readiness PASS or FAIL against the shape of an ASV scan.

A VA cannot replace a QSA or auditor determination, cannot certify you “PCI compliant,” cannot file an official ASV attestation with a card brand, and cannot prove that no vulnerabilities exist. It also does not invent a complete cardholder-data (CHD) inventory — Secure Assess does not claim CHD discovery.

PCI DSS 4.0 and “PCI standards” (background only)

PCI DSS 4.0 and broader PCI standards language matter for program planning. If you are evaluating Secure Assess commercially, lead with 11.3 vulnerability assessment and ASV-readiness PASS/FAIL. Do not treat this product as a full 4.0 readiness checklist or end-to-end compliance program.

Next step

Ready for the shipping product? Read PCI DSS 11.3 vulnerability assessment & ASV-readiness or start in the app.

Also: vulnerability assessment · PCI scan planning · pen testing vs VA · FAQ.

From education to 11.3 assessment

Secure Assess covers PCI DSS 11.3 VA and ASV-readiness PASS/FAIL. Sign up in the app when you are ready to scan.