After Passing an ASV Scan: What Happens Next?

Published on

Updated on

Key Takeaways
  • After passing an ASV scan, you still need to confirm scope accuracy, get the right document to your acquirer, and calendar your next scan; passing doesn't close the compliance cycle; it restarts it.
  • Your ASV issues two distinct documents: the Attestation of Scan Compliance (AoSC), which is what your acquirer generally wants, and the full technical report, which is for your own internal review.
  • There's no fixed "expiration date" on a passing result the way a certificate expires; the real requirement is unbroken evidence of a passing scan every 90 days, evaluated across the trailing four quarters.
  • A pass means no high-severity (CVSS 4.0+) findings; it doesn't mean the report is empty. Medium- and low-severity findings should still be tracked and remediated before they compound into a future failure.
  • PCI ASV record-keeping isn't optional housekeeping: acquirers and QSAs expect to see your last four quarters of scan evidence on request, including any documented false-positive exceptions.

After passing an ASV scan, most of the hard work, the actual security testing, is behind you. But a passing result isn’t the end of the compliance cycle; it’s where testing hands off to administration, and that handoff has its own steps that are easy to skip once the pressure of the scan is gone. This guide covers everything that happens between a passing scan and your next one: which document to review and submit, who receives it and how, what “valid” actually means for a passing result, what you’re still on the hook to remediate, and what PCI ASV record keeping actually requires you to retain.

Key Definitions

Attestation of Scan Compliance (AoSC): The formal, short-form document an ASV issues once a scan passes, certifying that your in-scope external systems met the PCI DSS threshold. This is the document most acquirers and payment brands are set up to receive.

Detailed/Technical Report: The full findings document listing every system scanned, including resolved and lower-severity issues. Useful for internal security review; not typically what your acquirer asks for.

Quarterly scan cycle: The recurring window under PCI DSS Requirement 11.3.2 requiring an external ASV scan at least once every three months.

Four-quarter evidence window: What acquirers and QSAs actually check: a passing scan in each of the trailing four quarters (12 months), not just your most recent result.

Significant change: Any material network or system change (new infrastructure, firewall changes, new payment integrations) that triggers an additional out-of-cycle scan under Requirement 11.3.2.1.

What to Do Immediately After Passing an ASV Scan

After passing an ASV scan, review the full technical report (not just the AoSC), confirm every in-scope IP address and domain was actually included, and route both documents to the people who need to see them internally before anything goes external.

A pass confirms no high-severity vulnerabilities were found; it doesn’t confirm the scan covered everything it should have. If your environment changed since the last scan (new servers, expanded IP ranges, added cloud infrastructure), check that those additions were captured. A scan that passes but quietly excludes a new asset creates a scope gap that surfaces later, usually during a QSA review rather than when it’s easy to fix.

It’s also worth reading past the pass/fail line. A passing result means no CVSS 4.0+ findings;66 medium- and low-severity issues can still be sitting in the report, and they’re worth tracking rather than ignoring until they escalate into a future failure.

Notify the Right People Internally

Before anything gets submitted externally, loop in whoever owns compliance on your side, IT security, a compliance officer, or your QSA if you use one for annual assessments. Scan results are evidence your QSA will reference later; keeping them in the loop as results come in is lighter work than reconstructing a paper trail at assessment time.

Not Sure Which Report Your Acquirer Needs?

We'll confirm the right document for your acquirer and help you get it submitted correctly the first time.

ASV Scan Report Submission: Which Document Goes to Your Acquirer

For ASV scan report submission, send the Attestation of Scan Compliance, not the full technical report, unless your acquirer specifically asks for the detailed version. The AoSC is the summary document built for this exact purpose.

If you only have the detailed technical report on hand, go back to your ASV portal or ask your provider for the AoSC directly. Sending the full report in its place isn’t wrong, but for larger environments it buries the single page your acquirer needs under pages of resolved and lower-severity findings they don’t need to review.

Who Receives Your Passing ASV Scan Report?

Your acquiring bank or payment processor is the primary recipient; the PCI SSC sets the standard and certifies ASVs but doesn't typically receive individual merchant scan reports directly. If you're completing a full Report on Compliance, your QSA will also want a copy as supporting evidence.

Submission channels vary by acquirer: some use a dedicated compliance portal, others accept email submissions or route through a relationship manager. Confirm the exact process with your acquirer’s compliance team rather than assuming; a report sent to the wrong inbox is a common, entirely avoidable delay. For merchants on SAQ A or SAQ A-EP, the scan result combined with the completed SAQ is usually sufficient for annual validation; higher-tier merchants folding a ROC together with a QSA will treat the scan as one piece of a larger evidence package.

ASV Scan Validity Period: How Long Does a Passing Result Actually Cover You?

There's no PCI-mandated "expiration date" stamped on a passing result, but in practice, it needs to be followed by another passing scan within 90 days, because PCI DSS evaluates compliance as four passing scans across the trailing 12 months, not a single point-in-time result.

This distinction matters more than it sounds like it should. A merchant with three clean scans and one missed quarter hasn’t met the requirement, even if their most recent scan passed cleanly, the gap doesn’t disappear just because the next result came back clean. Treat the ASV scan validity period as a rolling 90-day commitment rather than a hard deadline you’re racing against: most well-run compliance programmes schedule the next scan 80–85 days after the last one, leaving buffer room if remediation or a rescan is needed before the window closes.

If Your Next Scan Fails

Passing this quarter doesn’t guarantee a clean result next time; new vulnerabilities surface, software changes, and infrastructure evolves. If your next scan comes back with a high-severity finding, remediate it and request a rescan before the quarter closes. The 90-day clock doesn’t pause for remediation, which is exactly why the buffer matters more than the calendar reminder itself.

Keep Your Next Scan on Schedule

Set up recurring quarterly ASV scans with Secusy so your next cycle books itself, with buffer built in.

Setting Up for Your Next Quarterly Cycle

Book your next scan roughly 80–85 days out, set a recurring reminder tied to the actual scan date rather than a fixed calendar quarter, and flag any planned infrastructure changes that could trigger an earlier out-of-cycle scan.

A few habits make each cycle noticeably less stressful than the last:

  • Anchor your reminder to the completed scan date, not “Q1/Q2”; fixed-quarter thinking is how scan dates quietly drift toward the deadline over time.
  • Note any planned changes between now and the next scan (new server, CDN migration, new payment integration) since these can require an earlier scan under Requirement 11.3.2.1, independent of your regular schedule.
  • If this quarter needed a rescan to pass, build that same buffer into next quarter’s plan rather than assuming a clean first attempt.
  • If your ASV supports on-demand scanning, use it to confirm a fix worked before spending your formal quarterly attempt on it.

PCI ASV Record Keeping: What to Retain and How to Organize It

Retain your AoSC and detailed report for each of the last four quarters (12 months) at minimum, since that's the window acquirers and QSAs check, including documentation for any failed scans and the passing rescans that followed. Many organizations keep records for up to three years to align with typical audit cycles.

Good PCI ASV record-keeping isn’t just about having files somewhere; it’s about being able to produce them quickly. A simple folder structure organised by quarter, containing the AoSC, the full report, and any exception documentation, covers most needs. If your ASV’s portal only retains reports for a limited window before archiving them, download your own copies rather than relying on the vendor to hold them indefinitely.

Documenting False Positives

If a scan flags something that turns out not to be a real vulnerability in your environment, due to a compensating control or scanner limitation, your ASV can document that as an exception with justification. Keep that documentation with the report it applies to. A properly documented false positive doesn’t undermine a passing result, but an undocumented one looks like an unresolved finding if anyone reviews the record later.

Conclusion

Passing your PCI ASV scan is most of the work, but not all of it. After passing an ASV scan, the right document needs to reach your acquirer, lower-severity findings still deserve attention, your next scan needs a date on the calendar before the window gets tight, and four quarters of evidence need to be retrievable on request. None of this is complicated, but it’s exactly the kind of follow-through that slips once the pressure of the scan itself is off, which is usually when a gap shows up in the record.

Need Your Past Scan Reports Organized?

We'll help you pull together your last four quarters of reports for an acquirer or QSA request.

Frequently Asked Questions

Review the full report (not just the pass/fail result), confirm all in-scope assets were included, and share both the report and the Attestation of Scan Compliance with your internal compliance team before submitting externally.

The Attestation of Scan Compliance (AoSC), not the full technical report, unless your acquirer specifically asks for more detail.

Your acquiring bank or payment processor, the PCI SSC certifies ASVs but doesn't typically receive individual scan reports directly. Your QSA also needs a copy if you're completing a full Report on Compliance.

There's no formal expiration stamped on a result, but PCI DSS expects a new passing scan within 90 days, evaluated as four passing scans across the trailing 12 months rather than one point-in-time result.

Yes. A pass means no high-severity (CVSS 4.0+) findings; medium- and low-severity issues can still appear in the report and are worth remediating before they compound.

Retain the AoSC and full report for at least the last four quarters (12 months), including documentation for any failed scans and the passing rescans that followed. Many organizations retain records for up to three years.
Around 80–85 days after your last passing scan, leaving buffer time for remediation or a rescan before the 90-day window closes.

Yes, a significant change (new infrastructure, firewall changes, new payment integrations) triggers an additional scan under Requirement 11.3.2.1, independent of your regular quarterly schedule.

Authored by

Binoy Koonammavu blog image

Binoy Koonammavu, is the Founder and CEO of Secusy ASV, where he helps SMBs and fintech companies meet PCI DSS scanning requirements without the complexity of enterprise-grade tools. His writing focuses on making ASV compliance straightforward for growing businesses.

Share:

Related Post

 

Discover more from Secusy ASV

Subscribe now to keep reading and get access to the full archive.

Continue reading