Binoy Koonammavu
A PCI ASV scan, that is, an external vulnerability scan conducted by a PCI Security Standards Council-approved scanning vendor, is a mandatory compliance requirement for most businesses that handle payment card data.
The cost of a single scan can range from around $100 at the lower end to $500 or more depending on the size and complexity of your external network environment, which vendor you select, and whether the scan is part of a bundled compliance package or priced individually.
For small and mid-sized businesses, “PCI compliance” can feel like a vague and potentially expensive obligation with no clear price tag attached. That uncertainty is often worse than the actual cost, because when you don’t know what you’re getting into financially, it’s easy to either underprepare or overspend.
The reality is that ASV scanning, when scoped and priced correctly, is one of the more straightforward elements of the PCI compliance journey. The challenge is knowing what drives the cost, what you actually need, and where vendors differ.
This guide is designed to give you clear, current answers to all of those questions. Whether you’re a business owner budgeting for PCI compliance for the first time, an IT manager reviewing your existing scanning arrangement, or an MSP partner looking for pricing context to support your clients, what follows will give you a precise and honest view of the 2026 ASV scan cost landscape, and how to make sure you’re getting real value from every dollar you spend on compliance.
Approved Scanning Vendor (ASV): An organisation approved by the PCI Security Standards Council to conduct external vulnerability scans of internet-facing systems as required under PCI DSS. Only scans from a currently approved ASV are accepted for compliance.
PCI DSS (Payment Card Industry Data Security Standard): The global security standard that applies to any organisation storing, processing, or transmitting cardholder data. Compliance requirements and associated costs scale with transaction volume and environment complexity.
External Vulnerability Scan: An automated scan of internet-facing IP addresses designed to identify known security vulnerabilities. Under PCI DSS, this must be conducted at least quarterly by an approved ASV.
Cardholder Data Environment (CDE): The systems, people, and processes that store, process, or transmit cardholder data. Only IPs within or connected to the CDE need to be in the scan scope; controlling CDE boundaries is a primary lever for reducing ASV scan cost.
Attestation of Scan Compliance (ASC): The formal document issued by an ASV upon a passing scan. This is the compliance artefact your acquiring bank or assessor will request as evidence of quarterly scanning.
Self-Assessment Questionnaire (SAQ): A PCI SSC validation tool allowing eligible merchants to self-certify compliance. The specific SAQ type required depends on how cardholder data is handled. For most SMBs, completing the relevant SAQ alongside quarterly ASV scans forms the core of the annual compliance cycle.
Flat-rate pricing. No retest fees. No surprise invoices.
A PCI ASV scan is an automated external vulnerability scan of your internet-facing systems, conducted by a PCI SSC-approved vendor. Cost is driven primarily by IP count, vendor pricing model, and what's bundled into the base price, not by the scan itself, which is fundamentally the same process across all approved vendors.
PCI ASV scans are mandatory, not optional, for any business that stores, processes, or transmits cardholder data and falls under SAQ A-EP, SAQ B-IP, SAQ C, SAQ D, or Level 1–2 merchant requirements. The PCI Security Standards Council requires external vulnerability scanning by an Approved Scanning Vendor at a minimum once per quarter.
Four variables explain most of the pricing variance you’ll see across the market:
IP count. PCI ASV pricing is almost universally IP-based. Each external IP in your CDE that faces the internet is a billable unit. A SaaS startup with two load balancers pays a fraction of what a mid-market company with 25 endpoints pays. This is the single largest cost lever and the one most businesses can meaningfully control through network segmentation and scope reviews.
Quarterly requirement. PCI DSS mandates external vulnerability scanning at a minimum once per quarter. Vendors price either per-scan or annually. Annual pricing is nearly always cheaper on a per-scan basis, but it also means your cost multiplies by four if you’re comparing quarterly rates to annual totals.
Retest fees. First-time scans frequently return failures. Vendors handle this very differently: some bundle unlimited retests into the base price; others charge $50–$200 per retest. For newly scoped or complex environments, two or three rescan rounds before clean attestation are common. This single variable can double your first-year cost.
Analyst support. Self-serve scan portals cost less. Managed scans, where an analyst reviews findings, identifies false positives, and handles dispute submissions to the PCI SSC, cost more. For teams running their first scan or without internal security staff, managed is often cheaper in total when you factor in internal time.
In 2026, PCI ASV scan costs for SMBs typically range from $80 to $300 per scan at the lower end, with more complex environments pushing costs to $500 or higher per scan. Annual spend on ASV scanning alone, accounting for the four mandatory quarterly scans, runs from roughly $400 to well over $3,000 depending on scope and vendor.
The table below reflects publicly listed or market-documented rates as of 2026. Where vendors do not publish pricing, ranges are based on market research and vendor quote data. Always confirm current pricing directly before purchasing.
| Vendor | Pricing Model | Est. Annual Cost (5 IPs) | Retests Included | Notes |
|---|---|---|---|---|
| Secusy ASV Scanner | $80/IP/year | ~$400 | Yes | Fixed-rate attestation and dispute support included |
| Sectigo HackerGuardian | Per-scan, IP-tiered | ~$600–$900 | Limited | Legacy ASV; part of Sectigo’s broader SSL/PKI suite |
| PCICompliance.com | Per-scan + platform fee | ~$700–$1,200 | Varies by plan | SMB-focused; free scan lead magnet available |
| SecurityMetrics | Annual subscription | ~$900–$1,500 | Included | Full-service compliance platform; higher cost reflects QSA integration |
| Trustwave | Custom quote | ~$1,200–$2,500+ | Varies | Enterprise-oriented; significant upsell toward managed security services |
| Qualys | Platform subscription | ~$2,000–$5,000+ | Included | ASV scanning bundled inside broader VM platform; rarely cost-effective for scan-only use |
How to read this table: ranges cover a 5-IP environment running four quarterly scans annually. Per-IP costs compress at 1–2 IPs and expand sharply past 20. If a vendor does not publish pricing, treat that as relevant information about how they’ll approach renewals and retest fees.
Small businesses with 1–5 external IPs should expect $200–$800/year. Mid-market companies with 6–20 IPs should budget $800–$2,000. Enterprise environments with complex scope require custom quoting but have real negotiating leverage on annual contracts.
| Business Size | IP Count | Cost Per Quarter | Annual Cost |
|---|---|---|---|
| Small business / SaaS startup | 1–5 IPs | $50–$200 | $200–$800 |
| Mid-market | 6–20 IPs | $200–$500 | $800–$2,000 |
| Enterprise | 30+ IPs | $500–$1,500+ | Custom |
Small businesses and SaaS startups (1–5 IPs)
Quarterly PCI scan cost at this tier typically runs $50–$200 per scan, or $200–$800 annually. Most companies here route payments through a gateway (Stripe, Braintree, Adyen) and have a limited external footprint. The scan is straightforward and pricing should reflect that.
If you’re paying more than $200/quarter for a sub-5-IP environment without dedicated analyst support, you’re outside the market rate for this tier.
Mid-market companies (6–20 IPs)
This is where pricing becomes most variable. External PCI scan cost for mid-market ranges from $300 to $800/quarter, depending on whether remediation support and retests are bundled.
Staging environments, dev endpoints, and third-party integrations often expand IP scope beyond what companies expect; every unnecessary IP kept in scope adds cost every quarter. Regular scope audits matter at this tier.
Enterprise environments (30+ IPs)
Most vendors move to custom quoting at this level. Approved scanning vendor cost typically starts at $500/quarter and can exceed $1,500, with annual contracts often delivering 20–35% reductions versus pay-as-you-go rates.
At this tier, bundling all four quarterly scans, unlimited retests, and dedicated analyst access into a single annual agreement provides cost certainty and is almost always the smarter financial structure.
All PCI DSS merchant levels require quarterly ASV scans, but the broader compliance obligations, and therefore total compliance spend, differ significantly by transaction volume. Understanding your merchant level is the first step in estimating your full annual cost accurately.
| Merchant Level | Annual Transaction Volume | ASV Scan Requirement | Additional Compliance Obligations |
|---|---|---|---|
| Level 1 | 6 million+ transactions/year | Quarterly (mandatory) | Annual QSA on-site audit, Report on Compliance (ROC), penetration testing |
| Level 2 | 1 million–6 million transactions/year | Quarterly (mandatory) | Annual SAQ, attestation, penetration testing often required by acquiring bank |
| Level 3 | 20,000–1 million e-commerce transactions/year | Quarterly (mandatory) | Annual SAQ, attestation |
| Level 4 | Under 20,000 e-commerce or under 1 million total transactions/year | Quarterly (mandatory) | Annual SAQ, enforcement varies by acquiring bank |
SAQ A note: PCI DSS v4.0 Requirement 11.3.2.1 extended external ASV scanning to SAQ A e-commerce merchants for the first time. If your business outsources payment processing entirely to a compliant third party and you’ve been on SAQ A since before 2024, verify your current scanning obligations with your acquiring bank now, don’t wait for them to ask.
The headline scan price is rarely the full invoice. Retest fees, dispute resolution time, urgency premiums, and platform access fees are the four most common sources of cost variance between the quoted price and what you actually pay.
Retest fees. Many vendors charge $50–$200 per retest. First-time scanners commonly need two to three rounds before achieving a clean Attestation of Scan Compliance. This alone can double the first-year cost if retests aren’t bundled. Ask explicitly before purchasing how rescans are priced and how many are typically needed across environments similar to yours.
Dispute resolution. If a finding is a false positive, submitting a dispute to the PCI SSC requires analyst time. Some vendors handle this as part of the service; others bill hourly. The dispute process takes time and, at some vendors, costs additional fees. Clarify whether this is included before signing.
Urgency premiums. Need results within 24 hours for a compliance deadline? Most vendors apply a surcharge of 25–50%. If scan timing is predictable and it should be with quarterly requirements, it should be scheduling mid-quarter to avoid this entirely.
Platform fees. Some vendors charge a portal access fee on top of per-scan pricing. This is more common at larger compliance platforms where ASV scanning is one module among many. Always ask for the total invoice cost, not just the headline scan rate.
Annual vs pay-as-you-go. Pay-as-you-go carries meaningful per-scan premiums. Since quarterly scans are a legal requirement, not optional, annual pricing is almost always the correct financial decision if you’re committed to staying compliant.
Secusy ASV pricing is fixed at $80/IP/year, four quarterly scans, and your Attestation of Scan Compliance included. No per-retest fees, no platform surcharges.
A compliant ASV scan includes the external vulnerability scan, a severity-classified results report, a Pass/Fail determination per PCI DSS ASV Program requirements, and an Attestation of Scan Compliance upon passing. Anything beyond this internal scanning, web application testing, penetration testing, is a separate engagement.
A proper PCI ASV scan should include:
What it should not include and what you should not pay a scan vendor to deliver as part of a scan package: internal network scanning, web application penetration testing, or QSA advisory services. These are distinct engagements with distinct pricing. Any vendor bundling them into a “compliance package” without clear line-item pricing is upselling, not adding value.
ASV scanning typically represents only a portion of total PCI compliance spend. For most SMBs, the full annual programme scans, penetration testing, SAQ completion, and remediation run from $500 to $3,000+, depending on environment complexity and how card data is handled.
This broader context matters because many businesses budget for the scan in isolation without accounting for what surrounds it:
Annual penetration testing. While ASV scanning is automated and external, penetration testing is a manual, targeted exercise by a qualified professional to actively attempt to exploit vulnerabilities. Both are required under PCI DSS v4.0; they serve different purposes, and neither substitutes for the other. SMBs typically pay $1,000–$5,000+ annually for a properly scoped penetration test.
SAQ completion. Most Level 4 merchants complete their SAQ annually alongside their scanning program. For straightforward environments, this is a self-service exercise. For more complex ones, a compliance partner adds advisory cost.
Remediation work. Scan findings don’t fix themselves. Patching, configuration changes, and architectural improvements all carry engineering costs; this is the most variable and often largest component of total compliance spend for businesses with vulnerability debt.
The most effective cost lever is upstream: how you accept card data in the first place. Moving to a fully hosted payment solution that removes card data from your environment entirely can significantly simplify scope, reduce IP count, and lower ongoing compliance costs year after year.
The right ASV for most SMBs appears on the current PCI SSCC-approved vendor list, offers transparent flat-rate or bundled pricing, includes rescan capability without punishing fees, and provides accessible support to help you act on results, not just deliver them.
The market spans large enterprise security firms to specialist SMB-focused compliance vendors. Enterprise vendors offer sophisticated tooling, but their pricing reflects their primary market; SMBs typically pay for capabilities and account management overhead they don’t need. Specialist providers focused on SMB and mid-market generally offer more appropriate pricing, faster onboarding, and support teams accustomed to helping businesses without a full-time security function.
When evaluating vendors, look beyond the per-scan rate and assess the total cost of the engagement. Key questions to ask:
A vendor that answers these questions clearly without evasion or upselling is demonstrating the transparency that makes for a reliable compliance partner.
All pricing ranges and compliance cost estimates cited are based on general market knowledge and published industry benchmarks as of 2026. Readers are encouraged to verify current pricing directly with PCI SSC-approved ASV providers and to consult the PCI Security Standards Council's published guidance at pcisecuritystandards.org for authoritative compliance requirements.
PCI ASV scan costs in 2026 are not a fixed number, they are a function of your environment’s scope, your chosen vendor’s pricing model, and the broader compliance programme you are running around the scan. For most SMBs, the scan itself is an affordable and manageable obligation when approached with the right partner and a clear understanding of what is in scope.
The more consequential cost decisions are the ones that sit around the scan: how you handle card data, how well-segmented your network is, and whether you have chosen a compliance partner who gives you support that goes beyond delivering a report.
The businesses that manage PCI compliance costs most effectively are those that treat it as an ongoing programme rather than an annual scramble. Quarterly scans, timely remediation, and a vendor relationship built on transparency and genuine support all contribute to a compliance posture that is both cost-efficient and genuinely secure, which, ultimately, is what the standard exists to achieve.
The biggest cost drivers are IP count, retest fees, and the level of analyst support included. The most common mistake is evaluating vendors on headline scan rate alone without confirming what the total invoice looks like after retests, dispute resolution, and platform fees.
Businesses that manage compliance costs most effectively treat ASV scanning as an ongoing program, quarterly scans, timely remediation, and a vendor relationship built on transparent pricing, rather than an annual scramble. That structure is both cheaper over time and far less stressful to operate.
$80/IP/year. Retests included. Attestation of Scan Compliance issued same day on passing results.
A PCI ASV scan costs between $80 and $500+ per scan in 2026, depending on how many IP addresses are in scope and which vendor you use. For small businesses with 1–5 IPs, the annual cost across four mandatory quarterly scans typically runs $200–$800. Mid-market environments should budget $800–$2,000. Enterprise environments are usually custom-quoted.
A PCI ASV scan is an automated external vulnerability scan of your internet-facing systems, conducted by a PCI Security Standards Council-approved vendor. It is required quarterly for any business that stores, processes, or transmits cardholder data. Only scans from a currently approved ASV count toward compliance output from unapproved tools is not accepted regardless of quality.
The ASV scan scope covers all external-facing IP addresses connected to your Cardholder Data Environment systems that store, process, or transmit cardholder data. Internal systems and firewalled infrastructure are excluded. Scope is the primary cost driver: every IP in scope is scanned four times per year. Reviewing scope before each cycle is the simplest way to control cost.
An ASV scan report lists all identified vulnerabilities by severity, Critical, High, Medium, Low and gives a Pass/Fail determination per PCI DSS requirements. A passing scan produces an Attestation of Scan Compliance (ASC), which is the document your acquiring bank will request as compliance evidence. A failing scan details what must be fixed before a clean attestation can be issued.
PCI compliance is an ongoing program, not a one-time fee. For most SMBs, annual spend includes four quarterly ASV scans ($200–$2,000), an annual penetration test ($1,000–$5,000+), SAQ completion, and remediation work. A straightforward Level 4 merchant can manage compliance for around $500/year. Complex environments with multiple IPs regularly exceed $5,000 annually.
In 2026, market rates range from $80–$200 per IP per year for SMB environments. Fixed-rate specialist vendors typically price at $80/IP/year with retests and attestation included. Larger platforms like Qualys or Trustwave bundle ASV scanning into broader subscriptions that cost significantly more per IP. Per-IP rates usually drop with volume across most vendors.
PCI DSS requires four passing external vulnerability scans per year, one per quarter. Missing a quarter creates a compliance gap, and acquiring banks can request your most recent attestation at any time. Annual pricing packages covering all four scans upfront are the most cost-effective approach and eliminate the risk of an unplanned missed quarter.
It depends on the vendor. Some include unlimited retests; others charge $50–$200 per retest. First-time scanners commonly need two or three rounds before achieving a clean attestation. This can double your first-year cost if retests aren't bundled. Always ask how rescans are priced before purchasing, any vendor that avoids this question directly is worth scrutinising.
For a small business with 1–5 external IPs, the annual ASV scan cost typically runs $200–$800 across four quarterly scans. Fixed-rate vendors price this as low as $80–$100/IP/year, retests included. Per-scan pricing with separate retest fees can push the same environment past $1,500 annually. Paying above $200/quarter for a sub-5-IP setup without analyst support is above market rate.
The scan process itself is standardised; the variance is in what's bundled around it. Retests, dispute resolution, attestation formatting, and analyst support are included by some vendors and billed separately by others. A lower headline rate can easily become more expensive than a higher flat-rate when rescan fees are added. Always compare total invoice cost, not headline rate.
Binoy Koonammavu, is the Founder and CEO of Secusy ASV, where he helps SMBs and fintech companies meet PCI DSS scanning requirements without the complexity of enterprise-grade tools. His writing focuses on making ASV compliance straightforward for growing businesses.
Subscribe now to keep reading and get access to the full archive.