PCI DSS

The PCI DSS policy pack maps the internal vulnerability-scanning requirements of the Payment Card Industry Data Security Standard (PCI DSS) v4.0.1 to checks that the Anchore Enterprise policy engine can evaluate against container images. The pack targets requirement 11.3.1 — internal vulnerability scans — and ships as a single bundle ready to import as a policy.

What’s in the Pack

  • Pack name: Anchore PCI 4 requirement 11.3.1
  • Frameworks covered: PCI DSS v4.0.1, requirement 11.3.1 (internal vulnerability scanning), including sub-requirement 11.3.1.1
  • Artifact coverage: container images. The pack ships container repository mappings that bind its rule sets to scanned images.
  • Rule set organization: rule sets are named by PCI requirement identifier (for example 11.3.1 Internal vulnerability scan), so the mapping from a bundle finding back to its underlying requirement is direct. The pack includes rule sets for the core 11.3.1 scan, Known Exploited Vulnerability (KEV) and EPSS-prioritized variants, sub-requirement 11.3.1.1, and feed-data availability checks (11.3.1.c Feed Data not available and 11.3.1c Outdated Feed Data).

The pack maps the portion of PCI DSS that is reachable from artifact content — the detection and ranking of vulnerabilities in scanned images — into rule sets the policy engine can evaluate. PCI DSS requirements that depend on organizational process, network segmentation, or cardholder-data handling are out of scope for a container-image policy and are not represented in the bundle.

How to Use the Pack

Import the pack like any other policy — see Manage Policies for the GUI, AnchoreCTL, and API workflows. Once imported, scope it to the registries and repositories it should apply to through Policy Mappings, and attach any allowlists you need before activating it as the account’s default policy.

The PCI DSS pack is intended as a starting point. Most teams customize mappings, attach allowlists for accepted risks, or layer additional rule sets on top before activating the pack against production registries.

Last modified August 11, 2026