Scrutineer.ai

Scrutineer · By framework

PCI compliance software for PCI DSS compliance management and audit readiness

PCI DSS compliance lives and dies on scope and evidence: define the cardholder data environment too loosely and the assessment balloons, leave evidence uncollected and you fail on documentation rather than security. Scrutineer maps the PCI DSS requirements to your controls and helps you keep the cardholder data environment tightly and clearly scoped.

The platform collects evidence for each requirement automatically and flags gaps such as a firewall rule that drifted, an unpatched in-scope system or a missing log. You see a live view of readiness per requirement, so the assessment is a confirmation, not a discovery. Scrutineer gets you assessment-ready; a Qualified Security Assessor performs the formal validation.

or try it below ↓

Control-mapped findings · linked evidence · you decide what to remediate

The Scrutiny Desk

Illustrative sample · not an audit attestation

SOC 2 ISO 27001 HIPAA GDPR PCI DSS

Controls in evidence-linked report out

AI scrutinizes you decide

Why it works

What you get with PCI DSS

Requirements mapped

Scrutineer maps your controls to the PCI DSS requirements, so you see coverage requirement by requirement instead of reconstructing it at assessment time.

Scope kept tight

The platform helps you define and watch the cardholder data environment, so scope creep does not quietly expand your assessment and your risk.

Evidence per requirement

Evidence is collected automatically and attached to the requirement it proves, with drifted rules and unpatched in-scope systems flagged early.

What it handles

Controls in, an evidence-linked report out

Point Scrutineer at a framework or a vendor and it maps every control, pulls the evidence it can find, flags the gaps and scores the risk, returning a report with linked evidence and a prioritized remediation list. Scrutineer is decision support for readiness, an accredited auditor still issues the attestation.

  • Maps controls to PCI DSS requirements
  • Helps scope the cardholder data environment
  • Collects evidence for each requirement
  • Flags drifted firewall and access rules
  • Surfaces unpatched in-scope systems
  • Keeps readiness organized for your QSA
PCI DSS readiness_report
READINESS · 82%
ACCESS CONTROL 91

evidence · MFA enforced and access reviews evidenced.

CHANGE MGMT 78

evidence · Mostly covered; one approval log left untested.

VENDOR RISK 64

evidence · Two subprocessors missing a current review.

ENCRYPTION 86

evidence · Data encrypted in transit and at rest, evidenced.

Example report layout, not customer data

Why Scrutineer

One platform that maps controls and scores risk

Not a static questionnaire, not a pass-fail black box, and not a spreadsheet you maintain by hand. Live control mapping across SOC 2, ISO 27001, HIPAA, GDPR and PCI, automatic evidence and a prioritized gap list, returned as a report you can act on. The AI scrutinizes, you decide.

Mapped to real controls

Every framework is broken down into the controls it actually requires, each scored on a red to amber to green scale, so readiness stays transparent and consistent.

Evidence behind every finding

Each control links to the exact evidence that satisfies it, the policy, the config, the log line, so the finding is auditable and your readiness is defensible.

A prioritized gap list

Open gaps roll up into a ranked remediation list, so the highest-risk findings sit at the top and your team fixes what matters before the audit begins.

Merchant level reference

The four PCI DSS merchant levels and how each one validates

Your level is set by annual card transaction volume, and it decides whether you validate with a self-assessment questionnaire or a full Report on Compliance signed by a Qualified Security Assessor. The thresholds below follow the widely used Visa bands.

Level Annual card transactions How you validate
Level 1 More than 6 million Annual Report on Compliance from a Qualified Security Assessor, or an internal assessor where the brand permits it, plus quarterly external scans by an Approved Scanning Vendor and an Attestation of Compliance.
Level 2 1 million to 6 million Annual self-assessment questionnaire and Attestation of Compliance, plus quarterly external scans. Some brands and acquirers require a QSA anyway, so confirm before you plan the year.
Level 3 20,000 to 1 million ecommerce Annual self-assessment questionnaire, Attestation of Compliance and quarterly external scans.
Level 4 Under 20,000 ecommerce, or up to 1 million total Annual self-assessment questionnaire and quarterly scans where the acquirer requires them. Requirements at this level are set by your acquiring bank rather than the card brand.

Levels are defined by the card brands and thresholds differ slightly between Visa, Mastercard, Amex and Discover. Your acquiring bank can also escalate you above your volume band after a breach, a high chargeback rate, or because of your industry. Always confirm your validation requirement with the acquirer. A QSA validates PCI DSS; Scrutineer gets the evidence ready for that review.

Good questions

Questions about PCI DSS

No. Formal PCI DSS validation is performed by a Qualified Security Assessor, or via the appropriate self-assessment questionnaire. Scrutineer maps requirements to controls, manages scope and organizes evidence so that validation goes smoothly.
It helps you define the cardholder data environment and watches the systems inside it, flagging when something new touches card data. Keeping scope tight and visible reduces both your assessment effort and your actual exposure.
PCI compliance software maps the PCI DSS requirements to the controls you actually run, collects the evidence that proves each one is operating, and flags gaps such as a drifted firewall rule or an unpatched in-scope system before an assessor finds them. It manages the cardholder data environment scope continuously rather than reconstructing it once a year. It does not perform the validation itself.
PCI DSS is a contractual requirement imposed by the card brands and your acquiring bank rather than a US federal law. That distinction matters less than it sounds: non-compliance can trigger fines passed down through your acquirer, higher transaction fees, or loss of the ability to accept cards. A few states, Nevada among them, have also written PCI DSS into statute for businesses handling card data.
Merchants fall into four levels based on annual card transaction volume. Level 1 covers merchants above roughly 6 million transactions a year and requires a Report on Compliance from a Qualified Security Assessor. Level 2 covers 1 million to 6 million, Level 3 covers 20,000 to 1 million ecommerce transactions, and Level 4 covers the smallest merchants. Levels 2 to 4 usually validate through the appropriate self-assessment questionnaire.
It depends on your merchant level and your acquirer. Level 1 merchants need a Qualified Security Assessor to produce a Report on Compliance. Lower levels typically complete the self-assessment questionnaire that matches how they take payments, from SAQ A for fully outsourced ecommerce through SAQ D for everyone else. Your acquiring bank has the final word, so confirm the expected validation route with them before you scope the work.
The SAQ follows how you accept payments, not how many transactions you take. SAQ A is for ecommerce merchants who fully outsource payment pages to a compliant provider. SAQ A-EP is for ecommerce sites that never touch card data but control the payment page. SAQ B and B-IP cover standalone terminals, dial-out and IP connected respectively. SAQ C and C-VT cover internet-connected payment applications and virtual terminals. SAQ P2PE covers validated point-to-point encryption solutions. SAQ D is the catch-all, and it is the longest. Separate versions exist for merchants and for service providers.

Keep reading

Guides that go deeper on PCI DSS

Explore more

More ways to scrutinize compliance and risk with Scrutineer

Stop guessing about readiness. Scrutinize on real evidence.

Point Scrutineer at a framework or a vendor and it maps every control, gathers evidence and scores the risk, returning an evidence-linked report and a prioritized gap list. The AI scrutinizes, you decide.

See pricing

SOC 2, ISO 27001, HIPAA, GDPR & PCI · evidence-linked controls · readiness, not certification