// SECURITY COMPLIANCE
PCI COMPLIANCE
REMEDIATION MANAGER

The authoritative system for tracking, managing, and remediating PCI DSS vulnerability findings. Import daily Nessus scan files, fingerprint every finding, track remediation progress across your entire environment, and generate executive-ready compliance reports.

PCRM uses a strict two-layer model: every raw scan row is stored exactly as imported and never altered, while a deduplicated analytical layer drives all dashboards, assignments, and reports.

🔒 Launch PCRM See How It Works Learn More 📂 Upload Scan
// HOW IT WORKS — WALKTHROUGH
Daily PCI Scan Pipeline

From a raw Nessus export to assigned, tracked remediation: PCRM keeps every imported row untouched as the source of truth, fingerprints findings into a deduplicated analytical layer, and drives dashboards, assignments, and executive reports from there.

01
Upload Scan File
Import Nessus CSV, TSV, XLSX, or TXT. Every row stored exactly as imported; duplicate files are caught via SHA-256.
02
Store & Fingerprint
Raw rows kept as source of truth; a deduped clean layer fingerprints each finding by Hostname + Plugin ID + Port.
03
Delta Analysis
Automatically identifies New, Resolved, and Reopened findings vs the previous scan batch.
04
Track & Assign
Assign findings to teams, set due dates, track status through the full remediation lifecycle.
05
Report & Notify
Generate executive summaries, aging reports, and remediation emails. Daily digest via cron.
// FEATURES
Full Remediation Lifecycle
📊
Executive Dashboard
Compliance score, risk breakdown, monthly trend charts, aging analysis, and per-environment open counts.
🔍
Finding Tracker
Filter by environment, risk, status, team, or host. Full audit trail, evidence attachments, and risk exceptions on every finding.
🗃️
Raw Source of Truth
Every row of every scan is stored exactly as imported — informational rows and duplicates included. The source is never altered.
🖥
Per-Server Summary
Sortable host grid with Critical/High/Medium/Low breakdown. Environment auto-detected from the FQDN. LAN/AD enrichment cards.
📈
Live Import Progress
Real-time progress bar with record counts, phase labels, stall detection, and a SHA-256 duplicate-file guard.
👥
Bulk Assignment
Assign hundreds of findings at once by environment, severity, or server. Preview count before applying.
📄
6 Report Types
Environment Summary, Executive, Technical, Aging, Audit Trail, and Scan Comparison reports with CSV export.
✉️
Email Composer
Generate professional remediation emails by environment, team, or severity. Saved to history. AI-assisted ServiceNow ticket generation.
// SCREENSHOTS
Inside PCRM
Live views from the running application — captured at 1280px width.
PCRM executive dashboard
Executive Dashboard
Compliance score, risk breakdown, SLA overdue counts, and monthly remediation trend at a glance.
PCRM scan batches list
Scan Batches
Every imported Nessus scan with record counts, import status, and delta analysis against the prior batch.
PCRM per-server summary
Per-Server Summary
Sortable grid of every host with its Critical/High/Medium/Low breakdown and auto-detected environment.
PCRM environment summary report
Environment Summary Report
Compliance posture rolled up by environment — production, staging, and more — ready for export.
PCRM findings tracker
Findings Tracker
Filter findings by environment, risk, status, and team, with a full audit trail on every entry.
// SCAN FILE FORMATS
Import from Nessus

PCRM accepts scan exports from Nessus in CSV, TSV, XLSX, and TXT formats. Format is auto-detected from file extension and content. The original file is always retained for audit purposes.

CSV TSV XLSX TXT
// GET STARTED

Ready to take control
of PCI compliance?

🔒 Launch PCRM