Compliance
PCI DSS 4.0.1 with PuReAI
PCI DSS 4.0.1 pushed third-party service provider oversight and continuous monitoring from annual paperwork to an ongoing obligation. That is exactly what an external, always-on view produces.
Where PuReAI fits
PuReAI does not perform ASV scanning or penetration testing. It is the continuous external picture around your CDE, plus the TPSP evidence Requirement 12.8 asks for.
Requirement → module → evidence
Each row is a control or requirement, the PuReAI module that produces relevant signal, and the artefact you can put in front of an auditor.
| Requirement | Module | Evidence produced |
|---|---|---|
| 6.3.1 — Security vulnerabilities identified and risk-ranked | Vulnerability | Externally observable products and versions matched to NVD and CISA KEV, ranked by severity and confidence. |
| 4.2.1 — Strong cryptography for transmission | Certificate, Misconfiguration | TLS certificates, issuers, expiry and weak configuration across every discovered host. |
| 11.3.2 — External vulnerability awareness | Vulnerability, IP | Continuous external findings between formal ASV scans — a complement, not a substitute. |
| 12.5.1 — Inventory of in-scope system components | Domain, IP, Technology | External inventory that surfaces forgotten hosts and shadow services near the CDE. |
| 12.8.4 — Monitoring TPSP compliance status | Supply Chain | Continuous provider scoring with dated evidence per provider. |
| 12.10 — Incident response readiness | News / Threats | Actor and campaign intelligence relevant to payments and your technology stack. |
Scope and limits
- Requirement 11.3.2 mandates quarterly ASV scans by an approved vendor. PuReAI is not an ASV and does not replace that scan.
- Nothing PuReAI does is intrusive: no exploitation, no authentication, no agents inside the CDE.
Questions we get asked
Is PuReAI an approved scanning vendor?
No. PuReAI is passive external intelligence. Your quarterly external scans must still be run by an ASV.
How does it help with Requirement 12.8?
It scores every identified service provider continuously and dates each finding, so provider monitoring is evidenced rather than asserted.
See the evidence for your own domain
Start with a free domain report, or read the full scoring methodology.