ASV Scan Cost Per IP: How Many IPs Do You Actually Need Scanned?

Published on

Updated on

Key Takeaways
  • The ASV scan cost per IP is driven by how many internet-facing IPs sit inside your PCI cardholder data environment (CDE), not by your total network size.
  • Most vendors price per IP or in IP-count tiers, and PCI DSS requires at least four scans a year, so your per-IP rate is effectively charged quarterly.
  • Correct PCI ASV IP scope almost always comes out smaller than businesses first assume; many SMBs land between one and ten in-scope IPs.
  • Network segmentation is the single biggest lever for reducing both your scan cost and your compliance workload.
  • A failed scan requires remediation and a rescan before it counts toward compliance; budgeting for this cycle avoids surprise costs.
  • Getting an accurate IP count before requesting a quote is the fastest way to stop over- or under-paying for ASV scanning.

The ASV scan cost per IP is the number every business researching PCI compliance eventually runs into, and almost nobody explains where that number actually comes from. Providers quote a per-IP rate, but the real driver of your total cost isn’t the rate itself; it’s how many IP addresses genuinely fall inside your PCI scope. Many business owners approach ASV scanning assuming it covers “the whole network”, which makes compliance feel expensive before a single scan is even run.  That assumption is almost always wrong. PCI DSS external vulnerability scanning applies specifically to internet-facing systems within your cardholder data environment (CDE), not your internal office network, not employee laptops, and not every server your business happens to run.

This guide walks through exactly how ASV scan cost per IP is structured, which IPs actually count toward your PCI ASV IP scope, how to count them yourself, and how that number multiplies across your required quarterly scans, so you can budget accurately instead of guessing. For current published rates, see our ASV scan cost breakdown.

Key Definitions

ASV (Approved Scanning Vendor): An organisation approved by the PCI Security Standards Council (PCI SSC) to perform the external vulnerability scans required under PCI DSS Requirement 11.3.2. Only ASV-conducted scans are accepted for compliance validation.

Cardholder Data Environment (CDE): The people, processes, and technology that store, process, or transmit cardholder data, plus any system connected to or capable of impacting the security of those systems.

PCI ASV IP Scope: The specific set of internet-facing IPs and domains connected to your CDE that must be included in your quarterly ASV scan.

External Vulnerability Scan: A scan run from outside your network perimeter to identify vulnerabilities visible to an attacker on the public internet.

Dynamic IP: An address that changes or is reassigned automatically, common in cloud autoscaling, containers, and DHCP-based environments.

For a full glossary of ASV terminology, see our PCI ASV glossary.

What Counts as an In-Scope IP for PCI ASV Scanning?

Only internet-facing IPs connected to your cardholder data environment count toward the PCI ASV IP scope; internal systems and networks with no path to the CDE are excluded.

Determining your PCI ASV IP scope is the foundation of an accurate ASV scan cost per IP estimate, and it’s where most businesses either overpay or unknowingly leave a gap. PCI DSS doesn’t require you to scan every IP your organisation owns; it requires you to scan the external-facing components of your CDE: the systems an attacker could reach over the public internet that are connected to storing, processing, or transmitting cardholder data.

In practice, this usually includes:

  • Public-facing web servers, checkout pages, and payment gateway endpoints
  • Load balancers or reverse proxies sitting in front of the CDE
  • VPN endpoints or jump boxes providing access into the CDE
  • Third-party integration points (hosted iframes, processor callbacks) that are externally reachable and connected to card data flows

 

It typically excludes:

  • Internal-only IPs with no external route
  • Corporate or marketing sites fully segmented from the CDE, with segmentation validated
  • Network segments with no logical or physical path to cardholder data

 

Network segmentation is the biggest lever here. A business that has properly isolated its CDE from the rest of its network can shrink its in-scope IP count significantly, which lowers both scan cost and remediation effort quarter over quarter. Before requesting a quote, document exactly which systems and IPs sit inside your CDE with your IT team or a qualified assessor. For the full scope definition, see our ASV scan requirements guide.

Not Sure What Your Real IP Count Is?

Get a clear picture of your PCI ASV IP scope before you budget for a scan.

How Is ASV Scan Cost Per IP Structured?

Most ASV vendors price scans either as flat-rate IP-count tiers or as a straight per-IP rate, with cost scaling directly as your in-scope IP count grows.

An ASV scan isn’t a simple automated ping; it’s a structured external vulnerability assessment run on PCI SSC-validated infrastructure, producing a pass/fail report against PCI DSS requirements. What you’re paying for is the scanning technology, the accuracy of the reporting, and any dispute or remediation support included.

Two common pricing structures show up across the market:

  1. Tiered flat-rate packages: a set price covering up to a defined number of IPs (e.g., up to 5, up to 20, up to 50). Predictable and easy to budget, common with SMB-focused vendors.
  2. Per-IP pricing: a fixed rate per IP or domain added to scope. Scales more granularly for businesses that sit between standard tier thresholds; this is the model behind most ASV scan cost per ip quotes.

 

What actually moves your price within either model:

  • Raw IP count: the most direct driver; two in-scope IPs cost far less than fifteen, regardless of vendor.
  • Scan frequency: PCI DSS mandates at least quarterly scanning, so bundled annual packages covering four scans are generally more cost-effective than one-off purchases.
  • Included support: entry-level packages may hand you a raw report; more complete offerings include help interpreting findings, dispute support for false positives, and remediation guidance. For SMBs without in-house security staff, this support is often the difference between a scan result that moves compliance forward and one that stalls it.

 

See our ASV pricing models breakdown for how these structures compare in practice.

How Many IPs Need PCI Scanning? A Practical Counting Framework

The number of IPs that need PCI scanning depends on how many internet-facing systems connect to your CDE; for most SMBs, this lands between one and ten IPs, well below what they initially assume.

The right question isn’t “how many public IPs does our business have?” It’s “how many of those IPs are connected to systems that store, process, or transmit cardholder data”? The gap between those two answers is real money.

A workable counting process:

  1. Map your payment data flow. Trace where cardholder data enters your environment (checkout, point of sale) and follow it through every system until it exits to a processor or storage. Anything with an internet-facing IP on that path is in scope.
  2. Pull your firewall’s public NAT/port-forwarding rules. Any external IP with an active rule into your environment is a candidate.
  3. Check your cloud provider’s public IP inventory. AWS Elastic IPs, Azure Public IPs, and GCP external addresses are commonly undercounted because they’re provisioned outside the original network diagram.
  4. List subdomains resolving to separate IPs. A DNS lookup across your subdomains catches infrastructure that lives outside your main hosting.
  5. Filter against your CDE boundary. Remove anything confirmed segmented away from cardholder data; provided your segmentation testing actually supports that.

 

Typical scenarios:

  • A small e-commerce business using a hosted, redirect-based checkout: often just 1–3 in-scope IPs.
  • A business running its own payment application on a dedicated server: typically 3–8 IPs.
  • A mid-market company with multiple locations and dedicated processing infrastructure: 10–30+ IPs, requiring more deliberate documentation.

 

Use our pre-scan scoping checklist to work through this before requesting a quote, and check ‘Do I Need PCI ASV Scanning?’ if you’re unsure whether you need scanning at all.

Dynamic and Cloud IP Considerations

Cloud and dynamic IPs still need to be scoped even though they change — you scan what's live and externally reachable at scan time, and your ASV should support rescoping as your environment shifts.

This is where IP counts get miscounted in both directions:

  • Autoscaling groups can spin up multiple public IPs under load, all technically in scope while active.
  • Load balancers are usually a single external IP even when distributing traffic to many backend instances; don’t double-count backend nodes that aren’t independently reachable.
  • For CDN-fronted assets: if the origin isn’t independently reachable behind the CDN, the CDN edge is generally what’s scanned, not every origin server.
  • Ephemeral containers exposed via public load balancer services can introduce IPs that weren’t present during your last scoping review.

 

Scope by what’s externally reachable right now, and revisit that list before each quarterly scan rather than assuming last quarter’s count still holds. See our Azure-specific ASV scanning guide if your environment is cloud-native.

Quarterly Scanning Requirements: Frequency, Passing Results, and Rescans

PCI DSS requires external vulnerability scans at least once per quarter by a PCI SSC-approved ASV, and a passing result is required before that period counts toward compliance validation.

The quarterly cadence is non-negotiable: four scans per year minimum, each needing a passing result. A scan that surfaces high-severity vulnerabilities produces a failing report, meaning remediation and a rescan are required before a valid passing result exists. This remediation-and-rescan cycle is a normal part of the process, and reputable ASVs build rescans into their packages rather than billing separately for each attempt; see our rescan cost policy for how this typically works.

Because the requirement is recurring, the ASV scan cost is a yearly line item, not a one-time purchase. Annual packages covering four quarterly scans (often with rescans included) tend to offer better value than buying scans individually and make budgeting predictable across the year. It’s also normal for a first scan to surface more findings than later ones simply because previously unseen issues become visible; this isn’t a red flag; it’s the environment tightening over successive cycles. If a scan fails, see what to do after a failed ASV scan for the remediation path.

Ready for Exact, No-Surprise Pricing?

See what your actual in-scope IP count means for your ASV scan cost.

How IP Count Multiplies Your Annual ASV Scan Cost

Your per-scan cost is (in-scope IPs × per-IP rate), and because PCI DSS requires four scans a year, that rate is effectively charged quarterly, so small scoping errors compound fast.

At an $80/IP rate, here’s how that plays out annually:
In-Scope IPs
Cost per Scan
Cost per Year (4 scans)
1
$80
$320
5
$400
$1,600
20
$1,600
$6,400
50
$4,000
$16,000
This is why scoping accuracy matters more than shopping the per-IP rate alone. Overcounting by even five IPs adds $1,600/year at this rate; undercounting risks incomplete compliance evidence with your acquirer.

Common Scoping Mistakes That Inflate or Hide Your Cost

The most frequent errors are counting internal IPs that don't need scanning, and missing cloud or subdomain IPs that do.

  • Treating every server on the office network as in scope, when only the externally-facing edge matters
  • Forgetting decommissioned but still routable IPs from a previous hosting provider
  • Assuming a CDN or WAF removes an IP from scope without confirming the origin isn’t independently reachable
  • Not re-checking scope after a cloud migration, new SaaS integration, or new subdomain launch
  • Choosing a vendor that scans whatever IPs you hand them instead of helping you validate true scope first; see how to choose an ASV vendor for what to look for

Conclusion

ASV scan cost per IP isn’t really a pricing question; it’s a scoping question. Once you know which IPs are genuinely externally reachable and connected to your CDE, the per-IP rate becomes simple multiplication, and you can budget for it across all four required scans a year instead of being surprised by an invoice. Accurate PCI ASV IP scope, done once and revisited each quarter, is the single most effective way to control what you pay for compliance, without cutting corners on it.

Want the Full Requirements First?

Understand exactly what PCI DSS expects before you scope your environment.

Frequently Asked Questions

Pricing isn't standardized industry-wide, but most vendors use tiered IP-count packages or a straight per-IP rate, with cost scaling as your in-scope IP count grows. Annual packages covering four quarterly scans typically offer better value than one-off purchases.

The main drivers are your total in-scope IP count, scan frequency (PCI DSS requires quarterly), and the level of support included: remediation guidance, rescan allowances, and dispute support all affect the true total cost.

Only internet-facing IPs connected to your cardholder data environment. Most SMBs land between one and ten in-scope IPs once internal systems and properly segmented networks are excluded.

Typically one; the externally reachable address. Backend instances behind it usually aren't counted separately unless they're independently reachable from the internet.

Yes. Isolating your CDE from the rest of your network reduces the number of IPs that fall in scope, which lowers both scan cost and remediation workload each quarter.

At least once per quarter, by a PCI SSC-approved ASV. A failing result requires remediation and a rescan before that period counts toward compliance, reputable vendors include rescans in their packages.

Yes. Autoscaling, load balancers, and containerized services can change what's externally reachable between scans, so scope should be revisited each quarter rather than assumed static.
Yes. Vendors that price by IP count let SMBs with a small, well-defined scope pay proportionally less. Accurately defining your in-scope IPs before requesting a quote is the most reliable way to avoid overpaying.

Authored by

Binoy Koonammavu blog image

Binoy Koonammavu, is the Founder and CEO of Secusy ASV, where he helps SMBs and fintech companies meet PCI DSS scanning requirements without the complexity of enterprise-grade tools. His writing focuses on making ASV compliance straightforward for growing businesses.

Share:

Related Post

 

Discover more from Secusy ASV

Subscribe now to keep reading and get access to the full archive.

Continue reading