If you handle card payments, sooner or later you will run into the term Approved Scanning Vendor, usually because your PCI DSS requirements include one. An Approved Scanning Vendor, or ASV, is an organisation approved by the PCI Security Standards Council to perform the external vulnerability scans that PCI DSS requires. This guide explains what a PCI ASV is, why you need one, and what an ASV scan involves.
External vulnerability scanning is one of the core security services PCI DSS mandates for merchants and service providers with internet-facing systems. The PCI data security framework requires specific tools and ASV qualification requirements to be met. Skipping or improperly fulfilling this requirement is a common and avoidable compliance gap.
What an ASV is
An ASV is a company that the PCI Security Standards Council, the body that maintains the payment card industry data security standard, has validated and approved to perform external vulnerability scanning of the internet-facing systems in your cardholder data environment. To become and remain an ASV, the organisation has to meet the Council's ASV qualification requirements and pass its testing, which is why PCI DSS specifies that these scans come from a PCI approved scanning vendor rather than any scanning tool.
The list of approved scanning vendors is published by the PCI SSC. Only organisations on that list are authorised ASVs; using a non-approved tool or service does not satisfy the PCI DSS compliance requirement. The PCI Security Standards Council maintains ASV quality standards and can remove ASV companies that fail to meet requirements. This approval process is what distinguishes an ASV from an internal vulnerability scanner or a generic third-party tool. To conduct external vulnerability scanning that counts toward PCI DSS compliance, the vendor must meet PCI DSS requirements for ASV qualification and be on the current PCI SSC list.
Why PCI DSS requires an ASV
PCI DSS requires merchants and service providers whose systems are accessible from the internet to have their external-facing systems scanned for vulnerabilities, at least quarterly, and to pass. The point is to maintain PCI compliance by catching the internet-exposed weaknesses an attacker could use to reach cardholder data.
Requiring the scan to come from a PCI approved scanning vendor ensures the external vulnerability scanning is performed to consistent, validated scanning requirements rather than with whatever tool a merchant happens to own. The PCI SSC sets ASV qualification requirements that approved scanning vendors must meet and maintain. This matters because the quality and scope of a vulnerability scan varies considerably between tools; an ASV scan is validated to find the class of vulnerabilities that PCI DSS is specifically concerned with in internet-facing environments.
Are your PCI scanning obligations on track?
Run the free security self-assessment to get an instant read on your compliance posture.
What an ASV scan involves
An ASV scan is an external vulnerability scan of your internet-facing IP addresses and domains in scope for PCI. The ASV runs the scan against your external-facing environment without accessing your internal network; it examines what is visible from the internet. You then receive an ASV scan report showing any vulnerabilities discovered.
The process typically follows these steps:
- Scope confirmation. You provide the ASV with the IP addresses and domain names of your internet-facing systems that are in scope for PCI. Scoping this correctly matters; missing assets means gaps in coverage.
- Scan execution. The ASV runs the external scan and produces a scan report. This includes vulnerability listings with severity ratings.
- Review and remediation. Your information security team reviews the results, remediates any failing vulnerabilities (those above the threshold PCI DSS sets for a passing result), and prepares for a rescan if needed.
- Dispute of false positives. The scan report may include false positives. You can submit evidence to the ASV to dispute these; the ASV reviews the evidence and can adjust findings accordingly.
- Passing scan result. Once all actual vulnerabilities are remediated, the ASV issues a passing scan report. This document is your evidence of compliance for this requirement.
The required cadence is at least quarterly, with 90 days between scans as a practical maximum, and you also rescan after significant changes to your external-facing environment. "Significant change" includes adding new IP addresses to your cardholder data environment, changing firewall rules affecting external systems, or migrating to new hosting infrastructure. The ASV uses a scan solution that has been validated to meet PCI DSS Requirement 11.3.2 for external scanning; some ASVs also provide guidance on internal network scanning that references Requirement 11.2.2. An ASV scan solution must meet the external scanning requirements published in the PCI SSC's ASV Program Guide. ASVs can also scan customers' environments across many organisations, helping information security teams across their client base with remediation guidance and security and compliance documentation.
ASV scan vs. penetration test: key differences
ASV scans and penetration tests are often confused, but they are distinct obligations under PCI DSS and one does not substitute for the other.
| Aspect | ASV scan | Penetration test |
|---|---|---|
| What it is | Automated external vulnerability scan | Manual, in-depth security assessment |
| Frequency | At least quarterly | At least annually and after significant changes |
| Who performs it | A PCI SSC-approved scanning vendor | A qualified penetration tester (internal or external) |
| Scope | External-facing systems only | External and internal systems, per PCI DSS testing methodology |
| Output | Scan report with pass/fail result | Penetration test report documenting findings and exploitation paths |
| Can it satisfy the other requirement? | No | No |
| PCI DSS reference | Requirement 11.3.2 | Requirement 11.4 |
Both are required under PCI DSS Requirement 11. An ASV scan that passes does not mean your internal environment is secure or that a manual tester could not find exploitable paths that the automated scan missed. PCI DSS compliance requires both; treating quarterly scans as penetration tests is a real compliance gap.
What a passing and failing scan means
A passing ASV scan result means that, at the time of the scan, no vulnerabilities above the severity threshold defined in the ASV Program Guide were found in your external-facing systems. Vulnerabilities rated at CVSS score 4.0 or higher generally constitute a failing result, with some exceptions defined in the PCI SSC's ASV Program Guide.
A failing scan is common the first time, especially for environments that have not previously been scanned. The process is to remediate the identified vulnerabilities and rescan. There is no fixed limit on rescans; the requirement is to achieve a passing result within the quarterly window and maintain it across subsequent scans.
False positives are a normal part of the process. If the ASV flags a vulnerability that does not actually apply to your environment, because of how a service is configured or what version is deployed, you can submit a dispute with documented evidence. The ASV reviews the evidence and determines whether the finding stands.
How to choose an ASV
All ASVs on the PCI SSC's approved list meet the same minimum qualification requirements, but there are practical differences worth considering. An ASV is an organization (or company) that the PCI SSC has tested and approved to conduct external vulnerability scanning services; it is not a tool or a product, but a validated service provider. Compliance scans performed by an applicable ASV count toward your PCI DSS compliance obligations; scans by non-approved tools do not. The PCI council maintains this list and confirms whether an ASV is currently approved and in good standing. Scans by an ASV that has been removed from the approved list after your scan was completed may not be accepted by your acquirer, so it is worth verifying ASV status at the time of each scan.
Scan accuracy. Different scan engines produce different false-positive rates and may vary in their detection of specific vulnerability classes. A scan that floods you with false positives increases your remediation review effort without improving security.
Ease of dispute handling. False positive disputes require submitting evidence to the ASV for review. Some ASVs make this process straightforward; others are slower or less responsive. A failed scan with a well-handled dispute process is far less disruptive than one where the dispute takes weeks.
Scope management. Managing which IP addresses and domains are in scope across quarterly scans requires clear communication with the ASV. A good ASV makes scope changes simple to handle. Using scanning tools that can scan customers across many environments means ASVs often have efficient processes for multi-site scope management.
Integration with your compliance workflow. An ASV that can provide guidance on remediation, security services and tools, and network security issues identified in the scan output reduces the effort of moving from a failed scan to a passing one. Compliance with PCI DSS depends on achieving passing scans; integrating remediation guidance into the scan workflow keeps the process moving.
Card industry data security standards alignment. The ASV program is built around the external scanning requirements of PCI DSS. Confirm that the ASV's scanning methodology is current with the applicable PCI DSS version, including PCI DSS 4.0 requirements where applicable, and that they protect cardholder data in how they handle your scan data.
What happens after the scan
Once you have a passing ASV scan result, you retain the scan report as evidence of compliance. For the SAQ types and compliance levels that require quarterly ASV scanning, these reports are part of the documentation package your acquirer or QSA may review during your compliance validation cycle.
You then need to repeat the scan within 90 days, regardless of whether anything has changed in your environment. The quarterly cadence is non-negotiable. Letting scans lapse, even briefly, means you have a period of non-compliance that creates risk and may need to be disclosed.
After significant changes to your external-facing environment, you must also rescan. This ensures that new infrastructure or configuration changes have not introduced vulnerabilities that would not be caught until the next scheduled quarterly scan.
The bottom line
An Approved Scanning Vendor is a PCI Security Standards Council-approved organisation that performs the external vulnerability scanning PCI DSS requires, at least quarterly, for internet-facing systems in your cardholder data environment. You need a PCI ASV because PCI DSS specifies that these scans come from an approved vendor meeting ASV qualification requirements, not any generic tool. You must also meet the separate annual penetration testing requirement; the two obligations are distinct and neither satisfies the other.
How Onyx helps
Onyx provides PCI DSS ASV scanning as a managed service, handling scope confirmation, quarterly scan execution, dispute management for false positives, and the passing scan report you need as evidence for your compliance package. Because the annual penetration test required by PCI DSS is a separate obligation, we coordinate both under the same programme so the scan output informs the penetration test scope and the two deliverables arrive on schedule. For merchants going through SAQ completion or preparing for a Level 1 QSA assessment, having both obligations handled by a single provider simplifies the evidence trail. We scope your PCI obligations on a short call.
See also: PCI DSS SAQ types explained, PCI compliance cost, PCI DSS Level 1: what it takes, and our PCI DSS ASV scans service.
Need quarterly ASV scans and a penetration test coordinated?
We scope your PCI DSS scanning and testing obligations on a 30-minute call. No obligation.
FAQ
What is an Approved Scanning Vendor (ASV)?
An ASV is an organisation approved by the PCI Security Standards Council to perform the external vulnerability scanning that PCI DSS requires for internet-facing systems in a cardholder data environment. The Council validates ASVs against published ASV qualification requirements so the scans meet a consistent standard. Only organisations on the PCI SSC's approved list qualify.
Why does PCI DSS require an Approved Scanning Vendor?
Because PCI DSS requires regular external vulnerability scanning of internet-facing systems, and specifies that those scans come from a PCI approved scanning vendor rather than any tool, to ensure they are performed to a validated, consistent standard. Using a non-approved tool does not satisfy the scanning requirements.
How often is an ASV scan required?
At least quarterly for merchants and service providers with internet-facing systems in scope, with 90 days between scans as a practical maximum. You must also rescan after significant changes to the external environment. You must achieve a passing ASV scan result and keep the scan report as evidence of PCI DSS compliance.
Is an ASV scan the same as a penetration test?
No. An ASV scan is automated external vulnerability scanning to meet a specific PCI DSS requirement. PCI DSS separately requires penetration testing at least annually and after significant changes, which is a manual, in-depth engagement. PCI ASV scans and penetration tests are both required; one does not satisfy the other.
What happens if my ASV scan fails?
You remediate the failing vulnerabilities and rescan until you achieve a passing result, then keep the ASV scan report as evidence of compliance. False positives can be disputed with the ASV. Failing a scan is common at first; the requirement is to fix the issues and pass on a regular, at least quarterly, basis to maintain PCI compliance.
What is the difference between an ASV scan and an internal scan?
An ASV scan is an external scan performed from outside your network by a PCI SSC-approved vendor; it shows what is visible and exploitable from the internet. An internal scan examines your internal network for vulnerabilities accessible to an insider or an attacker who has already reached your internal environment. PCI DSS has separate requirements for each; some SAQ and compliance level combinations require both.
