PCI DSS

PCI DSS ASV Scans

Quarterly external vulnerability scanning by an Approved Scanning Vendor, routed through our accredited ASV partner or coordinated alongside your existing ASV. We manage the cadence, interpret the findings, and guide you to passing results every quarter.

Overview

PCI DSS requires external-facing systems within scope to be scanned by an Approved Scanning Vendor (ASV) at least once every 90 days and after any significant change. A PCI approved scanning vendor is a company listed on the PCI SSC (PCI Security Standards Council) ASV programme, which sets the ASV qualification requirements every ASV must meet. Passing ASV scans are required evidence behind your attestation. Failing to maintain the quarterly cadence is one of the most common gaps we find during PCI compliance reviews.

The pci asv scan requirement exists because external-facing systems, including public IPs, servers, and web application endpoints, are where external attackers probe for vulnerabilities. Quarterly external scanning helps ensure your payment environment does not develop exposure between assessments. We route quarterly pci compliance scans through our accredited ASV partner under your programme, disclosed in your sub-processor list. If you already work with an Approved Scanning Vendor, we coordinate alongside them rather than duplicating the engagement. Either way, we define the scan scope, manage the quarterly schedule, interpret the results in plain language, and guide your team on remediation so each quarter produces a passing pci asv scan on record.

What’s included

  • Definition of the external scan scope (in-scope public-facing IPs and domains)
  • Quarterly external vulnerability scans by a PCI approved scanning vendor, every 90 days
  • Re-scans after remediation to reach a passing result
  • Plain-language interpretation of findings, false positives review, and false-positive dispute handling with the ASV
  • ASV scan attestation records filed in your PCI evidence repository

How we work

  1. 01
    Scan scope definition

    We identify the external-facing assets that fall within your cardholder data environment and confirm the scope before the first scan runs. Scope accuracy prevents both gaps in your security scanning and unnecessary scan coverage. We verify which public IPs and servers are in scope and document the scope baseline for future quarters.

  2. 02
    Quarterly scanning

    Our ASV partner runs scans on a quarterly cadence and after any significant change to in-scope systems. The 90-day schedule is tracked so scans never lapse. Each scan covers your external network perimeter and validates that the security controls protecting your payment environment remain effective.

  3. 03
    Findings interpretation and remediation guidance

    We interpret results in plain language, manage false positives disputes with the ASV, and provide prioritised remediation guidance. Technical fixes, including server-level patches and network configuration changes, are applied by your team. We ensure you understand which findings are genuine data security risks versus false positives, so remediation effort is applied where it counts.

  4. 04
    Passing attestation

    We schedule re-scans after remediation until a passing result is achieved and file the scan attestation in your evidence repository, ready for your next compliance review. Each passing pci compliance scan is documented so your assessment evidence is complete.

What you get

  • Quarterly ASV scan reports for each 90-day period
  • Re-scan reports confirming passing results where remediation was required
  • Findings summary with prioritised remediation guidance and false positives assessment
  • ASV scan attestations filed in your PCI evidence repository

Already working with an ASV?

If you already have a PCI approved scanning vendor, we coordinate alongside them rather than replacing them. We define scope, interpret results, and manage the remediation cycle. If you do not have an ASV, we route the scans through our accredited partner, disclosed in your sub-processor list. Either way, our role is to ensure the quarterly requirement is met and every passing scan is on record.

ASV scans and penetration testing are separate requirements

PCI DSS requirements include both quarterly external ASV scans and annual penetration testing. ASV scans are automated external scanning solutions that check for known vulnerabilities in your external network. Penetration testing is a separate manual engagement conducted by a qualified assessor. Both are required for pci dss compliance. We offer penetration testing as a distinct service, so you can meet both requirements through a single relationship.

Frequently asked questions

How often does PCI DSS require ASV scans?

PCI DSS requirements specify passing external ASV scans at least once every 90 days and after any significant change to in-scope external-facing systems. The quarterly cadence applies regardless of transaction volume or SAQ type.

What happens if a quarterly scan fails?

A failed initial scan is not unusual. We interpret the findings, manage false positives disputes with the ASV, provide remediation guidance to your team, and arrange re-scans until a passing result is on record. Technical fixes inside your environment are carried out by your team.

Do ASV scans replace penetration testing?

No. ASV scans are automated external vulnerability scans of your public-facing attack surface. PCI DSS also requires penetration testing, which is a separate manual engagement conducted by a qualified tester. We offer penetration testing as a distinct service.

Who counts as an Approved Scanning Vendor?

A PCI ASV is a company approved by the PCI SSC to perform external vulnerability scanning services under the ASV qualification requirements. We route pci compliance scans through our accredited ASV partner. If you already have a relationship with a PCI approved scanning vendor, we coordinate alongside them.

What is the difference between a pci asv scan and a network scan I run internally?

The PCI DSS requirement is for external scanning by an approved vendor. An internal network scan you run yourself does not meet the requirement, even if it uses the same scanning solutions. The scan must be conducted by a company that holds ASV status from the PCI SSC, and the results must be attested by that ASV. We ensure your scanning is performed by an accredited provider and the attestation is correctly filed.

Credentials held by our team

ISO/IEC 27001 Lead Auditor
CISM
CISA
COBIT 2019
CEH
CRTP
eCPPT
CSA
CCNA
ITIL
Free tool · about 3 minutes · instant score

How ready is your security and compliance?

Answer 15 quick questions across the controls auditors actually check, and get an instant readiness score with tailored next steps. No call required.

Start the free assessment

Ready to simplify security and compliance?

Pick a service, book a scope call, or ask a question. Whatever order works.