| Requirement 6 — Vulnerability identification and remediation | Identify vulnerabilities in systems and software, prioritize and remediate them over time, not just at a single scan | Internal and external vulnerability scanning with findings prioritized by actual exploitability and business risk, plus tracking of whether identified vulnerabilities actually get closed over time |
| Requirement 11.3.1 — Internal vulnerability scanning | Quarterly internal vulnerability scans | Continuous internal scanning that satisfies and exceeds the quarterly minimum |
| Requirement 11.3.2 — External vulnerability scanning | External scan of internet-facing systems at least once every three months | Continuous external scanning that runs alongside your approved scanning vendor's quarterly assessment, supplementing coverage between scan cycles and keeping visibility current in between |
| Standard-wide theme — Continuous compliance / business-as-usual | Evidence that controls operate continuously, not just at assessment time | This is the core of FortifyData's approach across every module: always-on assessment in place of a once-a-year reconstruction of your posture |
| Requirement 12.8 — Managing PCI DSS compliance of Third-Party Service Providers | Due diligence and ongoing monitoring of TPSPs' PCI DSS compliance status | Vendor questionnaire responses auto-validated against live technical assessment data, in a single vendor-evidence repository, instead of a folder of PDFs collected once a year |
| Requirement 12.3.1 / 12.3.2 — Targeted Risk Analysis and Customized Approach (verify exact numbering against your licensed copy of the standard) | A documented, defensible risk analysis behind any chosen control frequency or Customized Approach control | FortifyData can scope multiple, customer-specific Targeted Risk Analyses, giving teams a structured way to justify chosen frequencies and alternative controls rather than building that justification from scratch |
| Requirement 8.4 — Multi-factor authentication | MFA enforced on all access into the cardholder data environment | Documentation and evidence can be centrally housed in the Controls and Compliance module |
| Requirements 12.1 / 12.7 — Security policy and personnel screening documentation | Documented policies and background-check records | Centralized storage and organization of this evidence alongside everything FortifyData generates directly |
| Cross-framework — Risk Register | Consolidated visibility across compliance obligations | Findings from PCI-related assessments land in the same Risk Register as third-party risk and attack surface findings, rather than a PCI-only silo |