Urgency & PCI Requirements
NEW requirements under PCI DSS v4.0.1 mandate that organizations:
- Perform authenticated internal vulnerability scanning
(Req. 11.3.1.2) - Define patch timelines using a formal Targeted Risk Analysis (TRA)
(Req. 12.3.1) - Address all vulnerabilities, not just critical or high, in alignment with internal risk rankings (Req. 11.3.1.1)
And with exploitation of known vulnerabilities now being the #1 initial access method for nation-state actors (Verizon DBIR 2025), it’s more important than ever to close vulnerabilities that attackers could use as an entrance.
Download the Guide
