PCI ASV Scan Cost UK: What to Budget For [2026]

Published on

Updated on

Key Takeaways
  • PCI ASV scan costs in the UK typically run £100–£500+ per quarter (roughly £450–£4,500+ per year), depending on how many public-facing IP addresses are in scope.
  • Small businesses with a minimal internet footprint, one or two IPs and a hosted payment page, often sit under £150/quarter.
  • Mid-market and larger environments (multiple domains, e-commerce platforms, contact centre systems) typically sit at £200–£500+ per quarter.
  • Only scans from a PCI SSC-approved ASV count toward PCI DSS Requirement 11.3.2. A cheap scan from an unapproved vendor satisfies no compliance obligation, at any price.
  • Rescan fees are the most common source of budget surprises; confirm upfront whether they're included or billed separately.
  • Annual billing usually brings the effective per-scan cost down compared with paying quarterly; UK VAT is normally added on top of quoted prices.

If your business processes, stores, or transmits cardholder data in the UK, understanding PCI ASV scan costs is one of the most practical questions you can ask before your next compliance cycle. PCI DSS Requirement 11.3.2 makes quarterly external vulnerability scanning mandatory for every in-scope merchant and service provider; it isn’t optional, and it isn’t a one-off cost.

What’s harder to pin down from most vendor websites is what that scan actually costs once IP count, rescan policy, and VAT are factored in. This guide gives you a grounded 2026 view of PCI ASV scan costs UK businesses are realistically paying, what drives the price up or down, and how ASV scanning fits into your wider PCI compliance cost UK picture, so you can budget with confidence instead of guessing from a US price list.

Key Definitions

PCI DSS (Payment Card Industry Data Security Standard): The global security framework that sets technical and operational requirements for any organisation that stores, processes, or transmits payment card data.

ASV (Approved Scanning Vendor): A company certified by the PCI Security Standards Council (PCI SSC) to run the external vulnerability scans required under PCI DSS. Only PCI SSC-approved vendors' scans satisfy Requirement 11.3.

External vulnerability scan: A non-intrusive, automated scan run from outside your network perimeter, looking for exploitable weaknesses in internet-facing systems, web servers, firewalls, and hosted applications.

In-scope IP address: A public-facing IP that touches, or sits close to, your cardholder data environment. IP count is the single biggest driver of ASV scan pricing.

Rescan: A follow-up scan run after a failed quarterly scan, once the flagged issue has been remediated, needed to get a passing report for that quarter.

PCI ASV Scan Cost UK: What Businesses Are Actually Paying

Most UK businesses pay somewhere between £100 and £500+ per quarter for PCI ASV scanning (around £450–£4,500+ annualised), with the number of public-facing IPs in scope as the main driver of where you land in that range.

At the entry level, a small business with a minimal internet footprint; one or two IPs tied to a hosted payment page or a single web server, can typically access fully compliant scanning for well under £150 a quarter. These entry-level packages exist specifically for businesses that need genuine compliance without an enterprise-sized budget.

Mid-market businesses running multiple domains, hosted applications, remote access infrastructure, or an e-commerce platform with several public-facing components will usually see £200–£500 per quarter. At this level, the price generally reflects a wider scan scope, plus, often, more detailed reporting and remediation guidance when vulnerabilities are flagged.

UK government procurement listings give a useful sense-check on these numbers: quarterly external ASV scanning packages from established UK security vendors have appeared on public-sector digital marketplace frameworks at roughly £800 per unit per year, with unit-based add-ons for larger environments scaling upward from there. Treat these as reference points rather than universal prices; always confirm against your own IP count and scope.

What’s actually included in the price?

Not all ASV packages are equivalent, so it’s worth knowing what you’re paying for. A baseline package produces a pass/fail compliance report for your in-scope IPs. Higher-tier packages often add unlimited rescans within the billing period, vulnerability prioritisation, human-reviewed reports, and dedicated support to help you interpret findings and remediate. For businesses without in-house security staff, most UK SMBs that remediate support are frequently worth more than the scan itself. Our guide to how ASV pricing models work breaks down these package structures in more detail.

Know exactly what you'll pay before you commit

Get a clear, IP-based quote for PCI ASV scanning, no opaque pricing, no surprise rescan fees.

ASV Scan Pricing UK: What Drives the Cost Up or Down

ASV scan pricing UK vendors charge is driven primarily by IP count, with scan frequency, reporting depth, remediation support, and rescan policy all affecting the final number.

Number of IP addresses in scope

Almost every ASV provider prices around IP blocks; for example, one to five IPs, six to fifteen, and so on. A small footprint keeps you in the lowest tier; a growing environment moves you up. Periodically auditing your IP scope to remove anything no longer genuinely in scope is one of the more effective ways to manage cost over time. Our rescan cost policy guide and pricing model breakdown both cover how scope changes flow through to your bill.

Hosted vs on-premise environments

If you use a fully hosted payment solution, where a payment service provider handles card data entirely on its own infrastructure, your own scan scope for that component may be minimal or zero, since the scanning obligation shifts to the hosted provider. Any internet-facing systems that still connect to your cardholder data flows, however, remain in scope and need scanning by your own ASV.

Cloud environments

Businesses running on AWS, Azure, or Google Cloud need to factor in each platform's own scanning policies; some require advance notice, and certain IP ranges may need pre-authorisation before a scan can run. A good ASV provider walks you through these requirements rather than leaving you to find out the hard way mid-scan.

Rescans, the most common budget surprise

This is where UK businesses most often get caught out. Some ASVs include unlimited rescans in the annual fee; others charge per rescan. A single misconfigured open port can turn one quarter's scan into two or three billable rescans if your provider charges separately. Confirm the rescan policy before you sign; it's the single easiest way to avoid an unexpectedly large invoice. See our rescan cost policy explainer for a full breakdown.

Annual vs quarterly billing

Paying annually rather than quarterly often reduces the effective per-scan cost. For a stable environment with a mature compliance programme, committing annually is a straightforward way to bring the line item down without reducing coverage.

PCI Compliance Cost UK: Where ASV Scanning Fits

ASV scanning is one part of your total PCI compliance cost in the UK, and usually the more predictable, budget-friendly part; the bulk of the spend for Level 1 merchants sits in QSA fees, penetration testing, and remediation rather than in the ASV line item itself.

Total compliance cost varies significantly by merchant level, the tier your acquiring bank assigns based on annual transaction volume. Level 1 merchants, the highest-volume tier, need a formal Report on Compliance from a Qualified Security Assessor and can face five- or six-figure annual compliance costs once QSA fees, penetration testing, and remediation are included. Most UK businesses, however, sit at Levels 2 to 4, where compliance runs primarily through a Self-Assessment Questionnaire plus quarterly ASV scanning.

For a Level 4 merchant, the tier covering most UK SMBs, the total compliance cost is manageable when structured well: the appropriate SAQ can usually be completed in-house, internal vulnerability scanning tools are widely affordable, and quarterly ASV scanning adds one predictable, transparent line to the budget. Set against the potential cost of a card-data breach, card scheme fines, forensic investigation, legal exposure, and possible loss of the ability to accept card payments, that line item is small.

The cost of getting it wrong

Choosing an unapproved scanning vendor to save money is a false economy: PCI DSS is explicit that only scans from a vendor on the PCI SSC’s approved scanning vendor list satisfy Requirement 11.3. A cheap scan from the wrong vendor buys you nothing toward compliance. Incomplete remediation carries its own cost too; a failed scan left unresolved before your compliance window closes can trigger extra scrutiny from your acquirer or push you toward a higher assessment level. Our guide on reducing ASV and PCI DSS scan costs covers how to cut spend without cutting the corners that create these problems.

Not sure which pricing model fits your environment?

See how quarterly, annual, and bundled internal-scan packages compare for businesses your size.

PCI ASV Scan Cost for UK SMBs: What "Affordable and Approved" Looks Like

Affordable, fully PCI SSC-approved ASV scanning is genuinely accessible to UK SMBs; entry-level pricing has brought real compliance within reach of small businesses with limited IT budgets, provided you check for the right things beyond price alone.

Price shouldn’t be the only factor when comparing providers. Look for:

  • PCI SSC approval status. Check the PCI SSC’s approved scanning vendor list before purchasing anything; no approval, no compliance, regardless of price.
  • Transparent pricing. Providers that publish clear pricing, rather than requiring an opaque quote process, make it far easier to compare like-for-like.
  • Clear remediation guidance. A failed report with no explanation leaves you no better off. Look for plain-language guidance on fixing what’s flagged.
  • A defined rescan policy. Understand whether rescans are included or billed separately; a fail on a first scan is common, and included rescans remove a real source of surprise cost.
  • Onboarding support. First-time scan setup can be unfamiliar; hands-on onboarding reduces the risk of scope errors that invalidate results.

 

For a side-by-side view of vendors built for this end of the market, see our low-cost ASV scan providers comparison and our guide to choosing an ASV vendor if you’re evaluating options from scratch.

UK-Specific Procurement Considerations

A few things that don’t always show up on a vendor’s headline price:

  • VAT. Most UK vendor pricing pages quote figures excluding VAT; confirm this before comparing quotes, since the 20% difference can flip which vendor is actually cheaper.
  • Quarterly invoicing. Because ASV scanning is inherently a quarterly obligation, some buyers, particularly public sector and larger commercial procurement teams, prefer quarterly invoicing over one annual charge for cash-flow reasons. Not all ASVs offer this by default, even though the scanning itself happens quarterly.
  • Procurement frameworks. The UK public sector and larger commercial buyers can source ASV scanning through G-Cloud and similar digital marketplace frameworks, which publish list pricing openly; a useful sense-check against a private quote.
  • Currency risk on multi-year contracts. If you sign with a non-UK vendor priced in USD or EUR, confirm whether the GBP price is fixed for the contract term or subject to adjustment at renewal.

Conclusion

Budget £100–£500+ per quarter (roughly £450–£4,500+ a year) for PCI ASV scanning in the UK, with your exact position in that range set mainly by how many IPs are in scope. Watch for rescan fees, confirm whether VAT is included, and check PCI SSC approval status before price, a cheap scan from an unapproved vendor is money spent with nothing to show for it on your compliance record. Get the scope and the provider right, and PCI ASV scan cost becomes one of the smallest, most predictable line items in your entire PCI compliance budget.

First scan, or switching providers?

PCI SSC-approved scanning with clear remediation guidance and a rescan policy that won't blindside your budget.

Frequently Asked Questions

Most UK businesses pay £100–£500+ per quarter (roughly £450–£4,500+ per year) for PCI ASV scanning, depending on IP count and scope. Businesses with a small internet footprint sit at the lower end.
A PCI ASV scan is an external vulnerability scan run by a PCI SSC-approved vendor to find security weaknesses in internet-facing systems. UK businesses handling cardholder data must complete one every quarter under PCI DSS Requirement 11.3.2, or risk losing the ability to accept card payments.

At minimum, once per quarter, four times a year, plus after any significant change to internet-facing systems or network infrastructure.

Usually not. UK vendor pricing pages typically quote figures excluding VAT, so add 20% when comparing your true cost against a competitor's headline price.

Yes. Entry-level packages from PCI SSC-approved vendors are priced for small IP environments and can sit well under £150 a quarter. The non-negotiable requirement is PCI SSC approval; a cheap scan from an unapproved vendor satisfies no compliance obligation.

It depends on the vendor. Some bundle unlimited rescans into the annual fee; others charge per rescan. Confirm this before signing, since rescans are the most common source of unexpected cost.

ASV scanning is usually the smallest, most predictable part of PCI compliance cost. Bigger cost drivers, QSA fees, penetration testing, remediation, apply mainly to higher-volume Level 1 and Level 2 merchants; most UK SMBs at Level 4 manage compliance with an in-house SAQ plus quarterly ASV scanning.

Some vendors offer quarterly invoicing to match the scan cadence, but it isn't universal, and annual billing often brings the effective per-scan cost down. Ask your provider directly if cash-flow timing matters for your budgeting.
Pro tip:

The fastest path to a first-time pass is running your own Nmap scan 2–3 weeks before your ASV scan date, then remediating everything with a CVSS of 4.0 or above. That window is enough time to patch, reboot, and confirm fixes are in place before the official scan runs.

Authored by

Binoy Koonammavu blog image

Binoy Koonammavu, is the Founder and CEO of Secusy ASV, where he helps SMBs and fintech companies meet PCI DSS scanning requirements without the complexity of enterprise-grade tools. His writing focuses on making ASV compliance straightforward for growing businesses.

Share:

Related Post

 

Discover more from Secusy ASV

Subscribe now to keep reading and get access to the full archive.

Continue reading