Compliance · International & Privacy
PCI DSS testing evidence, continuously generated.
The obligation
What PCI DSS v4.0 asks of you.
PCI DSS v4.0 requires organizations handling cardholder data to run internal and external penetration testing at least annually and after any significant change to the cardholder data environment, alongside quarterly ASV vulnerability scans and ongoing segmentation testing to confirm the CDE is actually isolated from the rest of the network — not just documented as isolated in a network diagram that's drifted out of date.
How TriNetra maps to it
PTaaS engagements are scoped specifically to CDE boundaries and segmentation testing rather than a generic infrastructure pentest, with the Coverage tab tracking methodology completion against PCI's own testing requirements.
ASM's continuous monitoring covers the "after any significant change" trigger that catches most organizations off guard — a new subdomain or exposed service touching the CDE gets flagged as it appears — and CCV maps PCI DSS controls alongside SOC 2 and ISO 27001, so a single control test satisfies multiple audits at once.
Keep evidence current between audits with Continuous Controls Validation.
Ready when you are
Bring your framework. Leave with a plan.
Tell us which regulators govern you. We'll show you — on live platform data — exactly which modules produce the evidence each one asks for.
