Binoy Koonammavu
If your business processes, stores, or transmits cardholder data in the UK, understanding PCI ASV scan costs is one of the most practical questions you can ask before your next compliance cycle. PCI DSS Requirement 11.3.2 makes quarterly external vulnerability scanning mandatory for every in-scope merchant and service provider; it isn’t optional, and it isn’t a one-off cost.
What’s harder to pin down from most vendor websites is what that scan actually costs once IP count, rescan policy, and VAT are factored in. This guide gives you a grounded 2026 view of PCI ASV scan costs UK businesses are realistically paying, what drives the price up or down, and how ASV scanning fits into your wider PCI compliance cost UK picture, so you can budget with confidence instead of guessing from a US price list.
PCI DSS (Payment Card Industry Data Security Standard): The global security framework that sets technical and operational requirements for any organisation that stores, processes, or transmits payment card data.
ASV (Approved Scanning Vendor): A company certified by the PCI Security Standards Council (PCI SSC) to run the external vulnerability scans required under PCI DSS. Only PCI SSC-approved vendors' scans satisfy Requirement 11.3.
External vulnerability scan: A non-intrusive, automated scan run from outside your network perimeter, looking for exploitable weaknesses in internet-facing systems, web servers, firewalls, and hosted applications.
In-scope IP address: A public-facing IP that touches, or sits close to, your cardholder data environment. IP count is the single biggest driver of ASV scan pricing.
Rescan: A follow-up scan run after a failed quarterly scan, once the flagged issue has been remediated, needed to get a passing report for that quarter.
Most UK businesses pay somewhere between £100 and £500+ per quarter for PCI ASV scanning (around £450–£4,500+ annualised), with the number of public-facing IPs in scope as the main driver of where you land in that range.
At the entry level, a small business with a minimal internet footprint; one or two IPs tied to a hosted payment page or a single web server, can typically access fully compliant scanning for well under £150 a quarter. These entry-level packages exist specifically for businesses that need genuine compliance without an enterprise-sized budget.
Mid-market businesses running multiple domains, hosted applications, remote access infrastructure, or an e-commerce platform with several public-facing components will usually see £200–£500 per quarter. At this level, the price generally reflects a wider scan scope, plus, often, more detailed reporting and remediation guidance when vulnerabilities are flagged.
UK government procurement listings give a useful sense-check on these numbers: quarterly external ASV scanning packages from established UK security vendors have appeared on public-sector digital marketplace frameworks at roughly £800 per unit per year, with unit-based add-ons for larger environments scaling upward from there. Treat these as reference points rather than universal prices; always confirm against your own IP count and scope.
Not all ASV packages are equivalent, so it’s worth knowing what you’re paying for. A baseline package produces a pass/fail compliance report for your in-scope IPs. Higher-tier packages often add unlimited rescans within the billing period, vulnerability prioritisation, human-reviewed reports, and dedicated support to help you interpret findings and remediate. For businesses without in-house security staff, most UK SMBs that remediate support are frequently worth more than the scan itself. Our guide to how ASV pricing models work breaks down these package structures in more detail.
Get a clear, IP-based quote for PCI ASV scanning, no opaque pricing, no surprise rescan fees.
ASV scan pricing UK vendors charge is driven primarily by IP count, with scan frequency, reporting depth, remediation support, and rescan policy all affecting the final number.
Almost every ASV provider prices around IP blocks; for example, one to five IPs, six to fifteen, and so on. A small footprint keeps you in the lowest tier; a growing environment moves you up. Periodically auditing your IP scope to remove anything no longer genuinely in scope is one of the more effective ways to manage cost over time. Our rescan cost policy guide and pricing model breakdown both cover how scope changes flow through to your bill.
If you use a fully hosted payment solution, where a payment service provider handles card data entirely on its own infrastructure, your own scan scope for that component may be minimal or zero, since the scanning obligation shifts to the hosted provider. Any internet-facing systems that still connect to your cardholder data flows, however, remain in scope and need scanning by your own ASV.
Businesses running on AWS, Azure, or Google Cloud need to factor in each platform's own scanning policies; some require advance notice, and certain IP ranges may need pre-authorisation before a scan can run. A good ASV provider walks you through these requirements rather than leaving you to find out the hard way mid-scan.
This is where UK businesses most often get caught out. Some ASVs include unlimited rescans in the annual fee; others charge per rescan. A single misconfigured open port can turn one quarter's scan into two or three billable rescans if your provider charges separately. Confirm the rescan policy before you sign; it's the single easiest way to avoid an unexpectedly large invoice. See our rescan cost policy explainer for a full breakdown.
Paying annually rather than quarterly often reduces the effective per-scan cost. For a stable environment with a mature compliance programme, committing annually is a straightforward way to bring the line item down without reducing coverage.
ASV scanning is one part of your total PCI compliance cost in the UK, and usually the more predictable, budget-friendly part; the bulk of the spend for Level 1 merchants sits in QSA fees, penetration testing, and remediation rather than in the ASV line item itself.
Total compliance cost varies significantly by merchant level, the tier your acquiring bank assigns based on annual transaction volume. Level 1 merchants, the highest-volume tier, need a formal Report on Compliance from a Qualified Security Assessor and can face five- or six-figure annual compliance costs once QSA fees, penetration testing, and remediation are included. Most UK businesses, however, sit at Levels 2 to 4, where compliance runs primarily through a Self-Assessment Questionnaire plus quarterly ASV scanning.
For a Level 4 merchant, the tier covering most UK SMBs, the total compliance cost is manageable when structured well: the appropriate SAQ can usually be completed in-house, internal vulnerability scanning tools are widely affordable, and quarterly ASV scanning adds one predictable, transparent line to the budget. Set against the potential cost of a card-data breach, card scheme fines, forensic investigation, legal exposure, and possible loss of the ability to accept card payments, that line item is small.
Choosing an unapproved scanning vendor to save money is a false economy: PCI DSS is explicit that only scans from a vendor on the PCI SSC’s approved scanning vendor list satisfy Requirement 11.3. A cheap scan from the wrong vendor buys you nothing toward compliance. Incomplete remediation carries its own cost too; a failed scan left unresolved before your compliance window closes can trigger extra scrutiny from your acquirer or push you toward a higher assessment level. Our guide on reducing ASV and PCI DSS scan costs covers how to cut spend without cutting the corners that create these problems.
See how quarterly, annual, and bundled internal-scan packages compare for businesses your size.
Affordable, fully PCI SSC-approved ASV scanning is genuinely accessible to UK SMBs; entry-level pricing has brought real compliance within reach of small businesses with limited IT budgets, provided you check for the right things beyond price alone.
Price shouldn’t be the only factor when comparing providers. Look for:
For a side-by-side view of vendors built for this end of the market, see our low-cost ASV scan providers comparison and our guide to choosing an ASV vendor if you’re evaluating options from scratch.
A few things that don’t always show up on a vendor’s headline price:
Budget £100–£500+ per quarter (roughly £450–£4,500+ a year) for PCI ASV scanning in the UK, with your exact position in that range set mainly by how many IPs are in scope. Watch for rescan fees, confirm whether VAT is included, and check PCI SSC approval status before price, a cheap scan from an unapproved vendor is money spent with nothing to show for it on your compliance record. Get the scope and the provider right, and PCI ASV scan cost becomes one of the smallest, most predictable line items in your entire PCI compliance budget.
PCI SSC-approved scanning with clear remediation guidance and a rescan policy that won't blindside your budget.
At minimum, once per quarter, four times a year, plus after any significant change to internet-facing systems or network infrastructure.
Yes. Entry-level packages from PCI SSC-approved vendors are priced for small IP environments and can sit well under £150 a quarter. The non-negotiable requirement is PCI SSC approval; a cheap scan from an unapproved vendor satisfies no compliance obligation.
ASV scanning is usually the smallest, most predictable part of PCI compliance cost. Bigger cost drivers, QSA fees, penetration testing, remediation, apply mainly to higher-volume Level 1 and Level 2 merchants; most UK SMBs at Level 4 manage compliance with an in-house SAQ plus quarterly ASV scanning.
The fastest path to a first-time pass is running your own Nmap scan 2–3 weeks before your ASV scan date, then remediating everything with a CVSS of 4.0 or above. That window is enough time to patch, reboot, and confirm fixes are in place before the official scan runs.

Binoy Koonammavu, is the Founder and CEO of Secusy ASV, where he helps SMBs and fintech companies meet PCI DSS scanning requirements without the complexity of enterprise-grade tools. His writing focuses on making ASV compliance straightforward for growing businesses.
Subscribe now to keep reading and get access to the full archive.