Debian jessie upgrade OpenSSH server to latest
failing a PCI scan
Document for your auditor the version of the package installed. Reference security updates regarding OpenSSH, in this case from Debian. Possibly cross reference relevant CVEs.
Parsing a version number is fragile. Stable distros generally do not upgrade the version, but apply their own patches.