PCI Compliance Release 6.6

Limited Customer Release

June 15, 2026

PCI merchants can align compliance with fixed calendar quarters, replacing rolling 90‑day cycles. Quarterly expiration, dashboards, and reminders improve planning, while scans, reports, and attestation must be completed within each quarter.

Qualys Managed Tokens for API Access

PCI Compliance APIs now support authentication using Qualys-managed access tokens. This enhancement helps implement token-based authentication for the users not onboarded with any Identity Provider (IdP).

API authentication using Qualys-managed tokens provides the following benefits for secure API access:

  • Enables secure, token‑based API access without embedding usernames and passwords, using industry‑standard authentication.
  • Supports granular role‑based access control and complete tracking by mapping tokens to specific users.
  • Simplifies credential management using existing Qualys infrastructure.

This feature has limited availability. Contact Qualys Support to enable it for your account.

To set up Qualys-managed authentication, in the PCI Merchant user interface, navigate to the Account > Auth ID Token Management tab. Click New Token to generate Client ID and Client Secret

To learn more about this feature, refer to Auth ID Client Management.

Quarterly Compliance Cycles for PCI Merchants

We introduced support for fixed calendar-based quarterly compliance cycles for PCI merchants. This enhancement aligns PCI scan and compliance expiration with standard calendar quarters. This helps merchants to plan, track, and complete compliance activities on predictable quarterly schedules.

How to Enable Quarterly Compliance Cycle for PCI Merchants

The quarterly compliance cycle is disabled by default. Only the Super Admin users can enable this feature for PCI merchants. Contact Qualys Support to enable this feature for your account.

Quarterly compliance applies to the entire merchant account. You cannot enable it for specific IP ranges or sub-users.

How Quarterly Compliance Cycle Works

The following are the behavioral notes for PCI Merchants enabled using Quarterly Compliance Cycles

  • Merchants not enabled for this feature continue to follow the existing rolling 90‑day compliance model.
  • Merchants enabled for quarterly compliance cycles expire exactly at the quarter end, regardless of scan date. The following are the configured quarter timelines: 
    • Q1: January 1 – March 31
    • Q2: April 1 – June 30
    • Q3: July 1 – September 30
    • Q4: October 1 – December 31

    Quarterly compliance cycles are predefined. You cannot create custom compliance cycles.

  • Merchants enabled for quarterly compliance see a dashboard banner indicating their current quarterly compliance status.
  • PCI merchants must be scanned, reported, and attested within the same calendar quarter to remain compliant. You cannot scan, generate reports, and perform attestation after the expiry period for the merchants adopting quarterly compliance cycles.
  • We send automated quarter-end expiry notifications 15 days and 7 days before the quarter end. These reminders help merchants to track and complete compliance activities before the deadline.
  • False Positive (FP) justifications continue to expire 90 days from the last submission date. This behavior is unchanged and remains aligned with PCI Council guidelines.
  • Previously generated PCI reports remain available after expiration, consistent with existing 90‑day scan behavior.

Issues Addressed

There are no notable and important customer issues for this release.