PCI Compliance Release 6.6

June 15, 2026

With this release of PCI Compliance, we are introducing the following new features and enhancements.

Access PCI Compliance with SAML SSO

PCI Compliance now supports the Identity Provider (IdP) initiated Security Assertion Markup Language Single Sign-on (SAML SSO) authentication. SAML SSO provides secure and easy access to Qualys PCI Compliance using your corporate credentials. This simplifies credential management as you no longer need to maintain separate credentials for PCI access and ensures authorized access to PCI compliance by mapping each user to the specific access token.

 Contact Qualys Support to activate SAML SSO for the Point of Contact (POC) user. Only the POC users can enable or disable SAML SSO for sub-users.

You can also specify the SAML exit URL for the subscription. All the sub-users in the subscription are redirected to this URL after they log out. The exit URL ensures the security of cardholder data and provides compliance to PCI DSS Requirements 3 and 6. If the configured exit URL does not work, sub-users are redirected to the Qualys-specified default exit URL.

 If you have Symantec VIP (Validation and ID Protection) access, you cannot use SAML SSO. These authentication methods are mutually exclusive. 

SAML SSO is supported for PCI Merchant and Bank users. To learn more about enabling this feature, refer to:

Link SAML-enabled PCI Merchants to Qualys VM

PCI Compliance is enhanced to support linking SAML SSO-enabled PCI Merchant users to Qualys Vulnerability Management (VM). Linking PCI Merchants to VM ensures security and compliance by providing the following benefits:

  • Delivers verified vulnerability scan evidence
  • Prevents audit failures by automated compliance reporting
  • Provides a trusted risk remediation view for PCI merchants

Previously, only the PCI merchants using basic authentication were linked to the VM. Now, SAML SSO-enabled users can generate a token to link their accounts to VM, enabling enhanced security, accurate reporting, and efficient remediation.

To link a PCI Merchant account to VM, navigate to the Scans > Setup > PCI Accounts Links.  In the Add Existing PCI Account > Link to Existing PCI Service window, enter the user login and SAML token.

To learn more about linking PCI Merchants to VM, refer to How to Link SAML-enabled PCI Merchants to Qualys VM.

View Multi-factor Authentication Details on PCI Compliance UI

We have enhanced the PCI Compliance user interface to display the multi-factor authentication (MFA) details for PCI Merchant, Bank, and Admin users. These details help you identify the authentication method used for each user upfront. Previously, no authentication method details were available in the user interface.

Check the Mfa column on the Users tab of the PCI Compliance UI to view the MFA service implemented for a user, such as VIP, SSO, and Open ID Connect (OIDC).

Issues Addressed

There are no notable and important customer issues for this release.