Binoy Koonammavu
After passing an ASV scan, most of the hard work, the actual security testing, is behind you. But a passing result isn’t the end of the compliance cycle; it’s where testing hands off to administration, and that handoff has its own steps that are easy to skip once the pressure of the scan is gone. This guide covers everything that happens between a passing scan and your next one: which document to review and submit, who receives it and how, what “valid” actually means for a passing result, what you’re still on the hook to remediate, and what PCI ASV record keeping actually requires you to retain.
Attestation of Scan Compliance (AoSC): The formal, short-form document an ASV issues once a scan passes, certifying that your in-scope external systems met the PCI DSS threshold. This is the document most acquirers and payment brands are set up to receive.
Detailed/Technical Report: The full findings document listing every system scanned, including resolved and lower-severity issues. Useful for internal security review; not typically what your acquirer asks for.
Quarterly scan cycle: The recurring window under PCI DSS Requirement 11.3.2 requiring an external ASV scan at least once every three months.
Four-quarter evidence window: What acquirers and QSAs actually check: a passing scan in each of the trailing four quarters (12 months), not just your most recent result.
Significant change: Any material network or system change (new infrastructure, firewall changes, new payment integrations) that triggers an additional out-of-cycle scan under Requirement 11.3.2.1.
After passing an ASV scan, review the full technical report (not just the AoSC), confirm every in-scope IP address and domain was actually included, and route both documents to the people who need to see them internally before anything goes external.
A pass confirms no high-severity vulnerabilities were found; it doesn’t confirm the scan covered everything it should have. If your environment changed since the last scan (new servers, expanded IP ranges, added cloud infrastructure), check that those additions were captured. A scan that passes but quietly excludes a new asset creates a scope gap that surfaces later, usually during a QSA review rather than when it’s easy to fix.
It’s also worth reading past the pass/fail line. A passing result means no CVSS 4.0+ findings;66 medium- and low-severity issues can still be sitting in the report, and they’re worth tracking rather than ignoring until they escalate into a future failure.
Before anything gets submitted externally, loop in whoever owns compliance on your side, IT security, a compliance officer, or your QSA if you use one for annual assessments. Scan results are evidence your QSA will reference later; keeping them in the loop as results come in is lighter work than reconstructing a paper trail at assessment time.
We'll confirm the right document for your acquirer and help you get it submitted correctly the first time.
For ASV scan report submission, send the Attestation of Scan Compliance, not the full technical report, unless your acquirer specifically asks for the detailed version. The AoSC is the summary document built for this exact purpose.
Your acquiring bank or payment processor is the primary recipient; the PCI SSC sets the standard and certifies ASVs but doesn't typically receive individual merchant scan reports directly. If you're completing a full Report on Compliance, your QSA will also want a copy as supporting evidence.
Submission channels vary by acquirer: some use a dedicated compliance portal, others accept email submissions or route through a relationship manager. Confirm the exact process with your acquirer’s compliance team rather than assuming; a report sent to the wrong inbox is a common, entirely avoidable delay. For merchants on SAQ A or SAQ A-EP, the scan result combined with the completed SAQ is usually sufficient for annual validation; higher-tier merchants folding a ROC together with a QSA will treat the scan as one piece of a larger evidence package.
There's no PCI-mandated "expiration date" stamped on a passing result, but in practice, it needs to be followed by another passing scan within 90 days, because PCI DSS evaluates compliance as four passing scans across the trailing 12 months, not a single point-in-time result.
This distinction matters more than it sounds like it should. A merchant with three clean scans and one missed quarter hasn’t met the requirement, even if their most recent scan passed cleanly, the gap doesn’t disappear just because the next result came back clean. Treat the ASV scan validity period as a rolling 90-day commitment rather than a hard deadline you’re racing against: most well-run compliance programmes schedule the next scan 80–85 days after the last one, leaving buffer room if remediation or a rescan is needed before the window closes.
Passing this quarter doesn’t guarantee a clean result next time; new vulnerabilities surface, software changes, and infrastructure evolves. If your next scan comes back with a high-severity finding, remediate it and request a rescan before the quarter closes. The 90-day clock doesn’t pause for remediation, which is exactly why the buffer matters more than the calendar reminder itself.
Set up recurring quarterly ASV scans with Secusy so your next cycle books itself, with buffer built in.
Book your next scan roughly 80–85 days out, set a recurring reminder tied to the actual scan date rather than a fixed calendar quarter, and flag any planned infrastructure changes that could trigger an earlier out-of-cycle scan.
A few habits make each cycle noticeably less stressful than the last:
Retain your AoSC and detailed report for each of the last four quarters (12 months) at minimum, since that's the window acquirers and QSAs check, including documentation for any failed scans and the passing rescans that followed. Many organizations keep records for up to three years to align with typical audit cycles.
Good PCI ASV record-keeping isn’t just about having files somewhere; it’s about being able to produce them quickly. A simple folder structure organised by quarter, containing the AoSC, the full report, and any exception documentation, covers most needs. If your ASV’s portal only retains reports for a limited window before archiving them, download your own copies rather than relying on the vendor to hold them indefinitely.
If a scan flags something that turns out not to be a real vulnerability in your environment, due to a compensating control or scanner limitation, your ASV can document that as an exception with justification. Keep that documentation with the report it applies to. A properly documented false positive doesn’t undermine a passing result, but an undocumented one looks like an unresolved finding if anyone reviews the record later.
Passing your PCI ASV scan is most of the work, but not all of it. After passing an ASV scan, the right document needs to reach your acquirer, lower-severity findings still deserve attention, your next scan needs a date on the calendar before the window gets tight, and four quarters of evidence need to be retrievable on request. None of this is complicated, but it’s exactly the kind of follow-through that slips once the pressure of the scan itself is off, which is usually when a gap shows up in the record.
We'll help you pull together your last four quarters of reports for an acquirer or QSA request.
Review the full report (not just the pass/fail result), confirm all in-scope assets were included, and share both the report and the Attestation of Scan Compliance with your internal compliance team before submitting externally.
Your acquiring bank or payment processor, the PCI SSC certifies ASVs but doesn't typically receive individual scan reports directly. Your QSA also needs a copy if you're completing a full Report on Compliance.
Yes. A pass means no high-severity (CVSS 4.0+) findings; medium- and low-severity issues can still appear in the report and are worth remediating before they compound.
Yes, a significant change (new infrastructure, firewall changes, new payment integrations) triggers an additional scan under Requirement 11.3.2.1, independent of your regular quarterly schedule.

Binoy Koonammavu, is the Founder and CEO of Secusy ASV, where he helps SMBs and fintech companies meet PCI DSS scanning requirements without the complexity of enterprise-grade tools. His writing focuses on making ASV compliance straightforward for growing businesses.
Subscribe now to keep reading and get access to the full archive.