PCI-DSS v4.0

PCI-DSS
Requirement 6 Vulnerability Management.

PCI-DSS version 4.0 tightens Requirement 6 on protecting systems and software from attacks, with specific patching SLAs and vulnerability scanning mandates. Centraleyezer automates compliance tracking across all six sub-requirements.

How Centraleyezer covers PCI-DSS

Centraleyezer maps directly to the technical requirements — with built-in evidence collection so audits are fast.

6.2

Bespoke and custom software security

Centraleyezer tracks vulnerabilities in custom software components (SAST/DAST integrations), ensuring bespoke code enters the same risk-based remediation queue as third-party vulnerabilities.

6.3.3

All software protected from known vulnerabilities

Continuous vulnerability scanning and real-time threat intelligence ensure your cardholder data environment (CDE) coverage is always current. Scan coverage metrics are reported by scope.

6.3.1

Security patch and update process

Centraleyezer enforces PCI-DSS patching SLAs: critical vulnerabilities (1 month), high (3 months). Automatic escalation triggers when SLAs approach, with full audit trail for QSAs.

6.4

Web-facing applications protected

Web application vulnerabilities are flagged and tracked separately, with internet-exposure factored into the contextual risk score — ensuring WAF gaps are prioritised accordingly.

QSA Evidence

Quarterly scan and annual penetration test evidence

Centraleyezer exports the data your QSA needs: scan results, vulnerability age analysis, SLA adherence rates, and remediation timelines — packaged per PCI assessment period. Centraleyezer does not produce the Report on Compliance itself; that comes from your QSA.

Read more

Glossary

Other regulations

PCI-DSS v4.0 compliance requires documented vulnerability SLAs and quarterly scan evidence. Book a demo to see how Centraleyezer automates your QSA evidence collection.

PCI-DSS Compliance — Requirement 6 Vulnerability Management | Centraleyezer