PCI Compliance Release 6.7
July 24, 2026
We are introducing the following new features and enhancements for PCI Compliance.
View Consolidated Findings from PCI and TAS Scans
We enhanced the PCI Compliance - TotalAppSec (TAS) integration to merge vulnerability findings from both the PCI and TAS scans for IP or DNS assets. This enhancement provides a consolidated view of unique vulnerabilities detected in both scans and ensures that no critical findings are overlooked during remediation.
Previously, the Compliance Report and PCI Compliance user interface only reported the vulnerability findings from the latest scan.
The enhanced PCI Compliance - TAS Integration provides the following benefits:
- Compliance reports now provide complete visibility into the security posture of your assets by combining vulnerability findings from PCI Compliance and TAS scans.
- Compliance reports skip the duplicate vulnerabilities detected on the asset and provide an accurate count of vulnerabilities.
- Provides consistent compliance status, asset counts, and vulnerability summaries across the user interface, reports, and API responses.
To learn more about this feature, refer to the PCI Compliance-TAS Integration.
Optimize Resource Consumption by Automatic Data Purge Support
We optimized the PCI Scan data retention policy to purge the old, irrelevant PCI scan data. PCI Compliance now automatically purges all the scan data older than three years. The new data retention policy also provides a 180-day recovery window after the data is purged.
This enhancement reduces resource consumption and improves performance by permanently deleting old scan data.
The automatic data purge feature is not available by default. Contact Qualys Support to activate it for your subscription.
View PCI Scan Results from Email Notification
We have updated scan links shared in scan launch and scan summary emails to support direct access to the scan status and scan report in the PCI Compliance user interface. You can now access the PCI scan status and results directly from the scan launch and scan summary emails, respectively.
Previously, links from scan notification emails directed users to a PCI Merchant login page, and users had to manually navigate to the scan reports tab.
Issues Addressed
The following important and notable customer issues are fixed in this release.
| Component/Category | Description |
|---|---|
| Vulnerability Reporting | Fixed an issue where historical vulnerability findings detected during older scans were displayed in the Vulnerabilities tab after latest scan. Now, older vulnerability detections are not included, and only vulnerabilities from the current scans are displayed in the Vulnerabilities tab. |