Scrutineer.ai

Scrutineer · By framework

PCI compliance software for PCI DSS compliance management and audit readiness

PCI DSS compliance lives and dies on scope and evidence: define the cardholder data environment too loosely and the assessment balloons, leave evidence uncollected and you fail on documentation rather than security. Scrutineer maps the PCI DSS requirements to your controls and helps you keep the cardholder data environment tightly and clearly scoped.

The platform collects evidence for each requirement automatically and flags gaps such as a firewall rule that drifted, an unpatched in-scope system or a missing log. You see a live view of readiness per requirement, so the assessment is a confirmation, not a discovery. Scrutineer gets you assessment-ready; a Qualified Security Assessor performs the formal validation.

or try it below ↓

Control-mapped findings · linked evidence · you decide what to remediate

The Scrutiny Desk

Interactive walkthrough on a sample company, not a scan of your systems.

Worked example with sample findings, not a scrutiny of your environment. Not an audit attestation.

SOC 2 ISO 27001 HIPAA GDPR PCI DSS

Controls in evidence-linked report out

AI scrutinizes you decide

Why it works

What you get with PCI DSS

Requirements mapped

Scrutineer maps your controls to the PCI DSS requirements, so you see coverage requirement by requirement instead of reconstructing it at assessment time.

Scope kept tight

The platform helps you define and watch the cardholder data environment, so scope creep does not quietly expand your assessment and your risk.

Evidence per requirement

Evidence is collected automatically and attached to the requirement it proves, with drifted rules and unpatched in-scope systems flagged early.

What it handles

Controls in, an evidence-linked report out

Point Scrutineer at a framework or a vendor and it maps every control, pulls the evidence it can find, flags the gaps and scores the risk, returning a report with linked evidence and a prioritized remediation list. Scrutineer is decision support for readiness, an accredited auditor still issues the attestation.

  • Maps controls to PCI DSS requirements
  • Helps scope the cardholder data environment
  • Collects evidence for each requirement
  • Flags drifted firewall and access rules
  • Surfaces unpatched in-scope systems
  • Keeps readiness organized for your QSA
PCI DSS readiness_report
Readiness 82%
ACCESS CONTROL 91

evidence · MFA enforced and access reviews evidenced.

CHANGE MGMT 78

evidence · Mostly covered; one approval log left untested.

VENDOR RISK 64

evidence · Two subprocessors missing a current review.

ENCRYPTION 86

evidence · Data encrypted in transit and at rest, evidenced.

Every finding links to the evidence behind it

Why Scrutineer

One platform that maps controls and scores risk

Not a static questionnaire, not a pass-fail black box, and not a spreadsheet you maintain by hand. Live control mapping across SOC 2, ISO 27001, HIPAA, GDPR and PCI, automatic evidence and a prioritized gap list, returned as a report you can act on. The AI scrutinizes, you decide.

Mapped to real controls

Every framework is broken down into the controls it actually requires, each scored on a red to amber to green scale, so readiness stays transparent and consistent.

Evidence behind every finding

Each control links to the exact evidence that satisfies it, the policy, the config, the log line, so the finding is auditable and your readiness is defensible.

A prioritized gap list

Open gaps roll up into a ranked remediation list, so the highest-risk findings sit at the top and your team fixes what matters before the audit begins.

Merchant level reference

The four PCI DSS merchant levels and how each one validates

Your level is set by annual card transaction volume, and it decides whether you validate with a self-assessment questionnaire or a full Report on Compliance signed by a Qualified Security Assessor. The thresholds below follow the widely used Visa bands.

Level Annual card transactions How you validate
Level 1 More than 6 million Annual Report on Compliance from a Qualified Security Assessor, or an internal assessor where the brand permits it, plus quarterly external scans by an Approved Scanning Vendor and an Attestation of Compliance.
Level 2 1 million to 6 million Annual self-assessment questionnaire and Attestation of Compliance, plus quarterly external scans. Some brands and acquirers require a QSA anyway, so confirm before you plan the year.
Level 3 20,000 to 1 million ecommerce Annual self-assessment questionnaire, Attestation of Compliance and quarterly external scans.
Level 4 Under 20,000 ecommerce, or up to 1 million total Annual self-assessment questionnaire and quarterly scans where the acquirer requires them. Requirements at this level are set by your acquiring bank rather than the card brand.

Levels are defined by the card brands and thresholds differ slightly between Visa, Mastercard, Amex and Discover. Your acquiring bank can also escalate you above your volume band after a breach, a high chargeback rate, or because of your industry. Always confirm your validation requirement with the acquirer. A QSA validates PCI DSS; Scrutineer gets the evidence ready for that review.

Good questions

Questions about PCI DSS

No. Formal PCI DSS validation is performed by a Qualified Security Assessor, or via the appropriate self-assessment questionnaire. Scrutineer maps requirements to controls, manages scope and organizes evidence so that validation goes smoothly.
Yes, in full. PCI DSS v4.0.1 replaced v4.0 on December 31, 2024 and is the active version, and the 51 future-dated requirements introduced in v4.x stopped being best practice and became mandatory on March 31, 2025. That date is worth checking against your own program, because a large share of published PCI guidance still describes those requirements as upcoming. If your last assessment treated them as future work, the gap is live now.
Two requirements do most of the work in practice. Requirement 6.4.3 says every script loaded on a payment page must be authorized, integrity-checked and inventoried. Requirement 11.6.1 requires a tamper-detection mechanism that alerts on unauthorized changes to HTTP headers and payment page content as the browser receives them. Both target digital skimming, both need tooling on the page itself, and both have been mandatory since March 31, 2025.
Published figures range too widely to quote one, and the spread is driven by scope rather than by vendor. The drivers that matter: your merchant level and whether you need a QSA-led Report on Compliance or a self-assessment, how much of the cardholder data environment you have segmented away, whether you use validated point-to-point encryption, quarterly ASV scanning, and remediating whatever the first gap analysis turns up. Scope reduction is the only lever that lowers all of them at once.
They group into six control objectives. Build and maintain a secure network covers requirements 1 and 2. Protect account data covers 3 and 4. Maintain a vulnerability management program covers 5 and 6. Implement strong access control covers 7, 8 and 9. Regularly monitor and test networks covers 10 and 11. Maintain an information security policy is 12. Version 4.x restructured the wording and added the customized approach, but the twelve headline requirements are unchanged.
Any organization that stores, processes or transmits cardholder data, plus service providers who can affect the security of a card transaction. It is a contractual obligation to the card brands and your acquiring bank rather than a federal law, which is why enforcement arrives as fees passed through your acquirer instead of a regulator. Several states do reference PCI DSS in statute, so it is not purely contractual everywhere.
You rarely fail outright. The usual outcome is a Report on Compliance with findings, a remediation window agreed with your QSA and acquirer, and re-testing of the items that failed. The expensive part comes later: monthly non-compliance fees from the acquirer, higher transaction rates, and, if a breach follows, forensic investigation and card brand assessments that dwarf what remediation would have cost.
It helps you define the cardholder data environment and watches the systems inside it, flagging when something new touches card data. Keeping scope tight and visible reduces both your assessment effort and your actual exposure.
PCI compliance software maps the PCI DSS requirements to the controls you actually run, collects the evidence that proves each one is operating, and flags gaps such as a drifted firewall rule or an unpatched in-scope system before an assessor finds them. It manages the cardholder data environment scope continuously rather than reconstructing it once a year. It does not perform the validation itself.
PCI DSS is a contractual requirement imposed by the card brands and your acquiring bank rather than a US federal law. That distinction matters less than it sounds: non-compliance can trigger fines passed down through your acquirer, higher transaction fees, or loss of the ability to accept cards. A few states, Nevada among them, have also written PCI DSS into statute for businesses handling card data.
Merchants fall into four levels based on annual card transaction volume. Level 1 covers merchants above roughly 6 million transactions a year and requires a Report on Compliance from a Qualified Security Assessor. Level 2 covers 1 million to 6 million, Level 3 covers 20,000 to 1 million ecommerce transactions, and Level 4 covers the smallest merchants. Levels 2 to 4 usually validate through the appropriate self-assessment questionnaire.
It depends on your merchant level and your acquirer. Level 1 merchants need a Qualified Security Assessor to produce a Report on Compliance. Lower levels typically complete the self-assessment questionnaire that matches how they take payments, from SAQ A for fully outsourced ecommerce through SAQ D for everyone else. Your acquiring bank has the final word, so confirm the expected validation route with them before you scope the work.
The SAQ follows how you accept payments, not how many transactions you take. SAQ A is for ecommerce merchants who fully outsource payment pages to a compliant provider. SAQ A-EP is for ecommerce sites that never touch card data but control the payment page. SAQ B and B-IP cover standalone terminals, dial-out and IP connected respectively. SAQ C and C-VT cover internet-connected payment applications and virtual terminals. SAQ P2PE covers validated point-to-point encryption solutions. SAQ D is the catch-all, and it is the longest. Separate versions exist for merchants and for service providers.

Keep reading

Guides that go deeper on PCI DSS

Explore more

More ways to scrutinize compliance and risk with Scrutineer

Stop guessing about readiness. Scrutinize on real evidence.

Point Scrutineer at a framework or a vendor and it maps every control, gathers evidence and scores the risk, returning an evidence-linked report and a prioritized gap list. The AI scrutinizes, you decide.

See pricing

SOC 2, ISO 27001, HIPAA, GDPR & PCI · evidence-linked controls · readiness, not certification