Binoy Koonammavu
The ASV scan cost per IP is the number every business researching PCI compliance eventually runs into, and almost nobody explains where that number actually comes from. Providers quote a per-IP rate, but the real driver of your total cost isn’t the rate itself; it’s how many IP addresses genuinely fall inside your PCI scope. Many business owners approach ASV scanning assuming it covers “the whole network”, which makes compliance feel expensive before a single scan is even run. That assumption is almost always wrong. PCI DSS external vulnerability scanning applies specifically to internet-facing systems within your cardholder data environment (CDE), not your internal office network, not employee laptops, and not every server your business happens to run.
This guide walks through exactly how ASV scan cost per IP is structured, which IPs actually count toward your PCI ASV IP scope, how to count them yourself, and how that number multiplies across your required quarterly scans, so you can budget accurately instead of guessing. For current published rates, see our ASV scan cost breakdown.
ASV (Approved Scanning Vendor): An organisation approved by the PCI Security Standards Council (PCI SSC) to perform the external vulnerability scans required under PCI DSS Requirement 11.3.2. Only ASV-conducted scans are accepted for compliance validation.
Cardholder Data Environment (CDE): The people, processes, and technology that store, process, or transmit cardholder data, plus any system connected to or capable of impacting the security of those systems.
PCI ASV IP Scope: The specific set of internet-facing IPs and domains connected to your CDE that must be included in your quarterly ASV scan.
External Vulnerability Scan: A scan run from outside your network perimeter to identify vulnerabilities visible to an attacker on the public internet.
Dynamic IP: An address that changes or is reassigned automatically, common in cloud autoscaling, containers, and DHCP-based environments.
For a full glossary of ASV terminology, see our PCI ASV glossary.
Only internet-facing IPs connected to your cardholder data environment count toward the PCI ASV IP scope; internal systems and networks with no path to the CDE are excluded.
Determining your PCI ASV IP scope is the foundation of an accurate ASV scan cost per IP estimate, and it’s where most businesses either overpay or unknowingly leave a gap. PCI DSS doesn’t require you to scan every IP your organisation owns; it requires you to scan the external-facing components of your CDE: the systems an attacker could reach over the public internet that are connected to storing, processing, or transmitting cardholder data.
In practice, this usually includes:
It typically excludes:
Network segmentation is the biggest lever here. A business that has properly isolated its CDE from the rest of its network can shrink its in-scope IP count significantly, which lowers both scan cost and remediation effort quarter over quarter. Before requesting a quote, document exactly which systems and IPs sit inside your CDE with your IT team or a qualified assessor. For the full scope definition, see our ASV scan requirements guide.
Get a clear picture of your PCI ASV IP scope before you budget for a scan.
Most ASV vendors price scans either as flat-rate IP-count tiers or as a straight per-IP rate, with cost scaling directly as your in-scope IP count grows.
An ASV scan isn’t a simple automated ping; it’s a structured external vulnerability assessment run on PCI SSC-validated infrastructure, producing a pass/fail report against PCI DSS requirements. What you’re paying for is the scanning technology, the accuracy of the reporting, and any dispute or remediation support included.
Two common pricing structures show up across the market:
What actually moves your price within either model:
See our ASV pricing models breakdown for how these structures compare in practice.
The number of IPs that need PCI scanning depends on how many internet-facing systems connect to your CDE; for most SMBs, this lands between one and ten IPs, well below what they initially assume.
The right question isn’t “how many public IPs does our business have?” It’s “how many of those IPs are connected to systems that store, process, or transmit cardholder data”? The gap between those two answers is real money.
A workable counting process:
Typical scenarios:
Use our pre-scan scoping checklist to work through this before requesting a quote, and check ‘Do I Need PCI ASV Scanning?’ if you’re unsure whether you need scanning at all.
Cloud and dynamic IPs still need to be scoped even though they change — you scan what's live and externally reachable at scan time, and your ASV should support rescoping as your environment shifts.
This is where IP counts get miscounted in both directions:
Scope by what’s externally reachable right now, and revisit that list before each quarterly scan rather than assuming last quarter’s count still holds. See our Azure-specific ASV scanning guide if your environment is cloud-native.
PCI DSS requires external vulnerability scans at least once per quarter by a PCI SSC-approved ASV, and a passing result is required before that period counts toward compliance validation.
The quarterly cadence is non-negotiable: four scans per year minimum, each needing a passing result. A scan that surfaces high-severity vulnerabilities produces a failing report, meaning remediation and a rescan are required before a valid passing result exists. This remediation-and-rescan cycle is a normal part of the process, and reputable ASVs build rescans into their packages rather than billing separately for each attempt; see our rescan cost policy for how this typically works.
Because the requirement is recurring, the ASV scan cost is a yearly line item, not a one-time purchase. Annual packages covering four quarterly scans (often with rescans included) tend to offer better value than buying scans individually and make budgeting predictable across the year. It’s also normal for a first scan to surface more findings than later ones simply because previously unseen issues become visible; this isn’t a red flag; it’s the environment tightening over successive cycles. If a scan fails, see what to do after a failed ASV scan for the remediation path.
See what your actual in-scope IP count means for your ASV scan cost.
Your per-scan cost is (in-scope IPs × per-IP rate), and because PCI DSS requires four scans a year, that rate is effectively charged quarterly, so small scoping errors compound fast.
|
In-Scope IPs
|
Cost per Scan
|
Cost per Year (4 scans)
|
|---|---|---|
|
1
|
$80
|
$320
|
|
5
|
$400
|
$1,600
|
|
20
|
$1,600
|
$6,400
|
|
50
|
$4,000
|
$16,000
|
The most frequent errors are counting internal IPs that don't need scanning, and missing cloud or subdomain IPs that do.
ASV scan cost per IP isn’t really a pricing question; it’s a scoping question. Once you know which IPs are genuinely externally reachable and connected to your CDE, the per-IP rate becomes simple multiplication, and you can budget for it across all four required scans a year instead of being surprised by an invoice. Accurate PCI ASV IP scope, done once and revisited each quarter, is the single most effective way to control what you pay for compliance, without cutting corners on it.
Understand exactly what PCI DSS expects before you scope your environment.
The main drivers are your total in-scope IP count, scan frequency (PCI DSS requires quarterly), and the level of support included: remediation guidance, rescan allowances, and dispute support all affect the true total cost.
Typically one; the externally reachable address. Backend instances behind it usually aren't counted separately unless they're independently reachable from the internet.
At least once per quarter, by a PCI SSC-approved ASV. A failing result requires remediation and a rescan before that period counts toward compliance, reputable vendors include rescans in their packages.
Binoy Koonammavu, is the Founder and CEO of Secusy ASV, where he helps SMBs and fintech companies meet PCI DSS scanning requirements without the complexity of enterprise-grade tools. His writing focuses on making ASV compliance straightforward for growing businesses.
Subscribe now to keep reading and get access to the full archive.