Compliance · PCI DSS
Know exactly what's in scope.
Payment Card Industry Data Security Standard
The Payment Card Industry Data Security Standard asks for a current inventory of the system components in scope and what each one is for. The hard part is never the list you already know about. It is the machine somebody stood up that quietly reaches the cardholder data environment. KeyCaliber finds both.
What PCI DSS expects.
- A current inventory of in-scope system components
- What each component is for
- Confirmation that scope is still accurate
- Security controls confirmed across the environment
What KeyCaliber gives you.
The full component list
Every system your tools can see, deduplicated, with the sources that reported it.
Scope creep, caught
The systems reaching into the cardholder data environment that nobody added to the diagram.
Controls checked
Where endpoint protection, scanning and identity coverage are present, and where they are not.
Ready for the assessor
Filter to the environment in question and export it with the evidence attached.
Find out what is really in scope.
Connect the tools you already run and see your own picture.
Request a demo