PCI ASV Scan Frequency: How Often Are ASV Scans Required?

Published on

Updated on

Key Takeaways
  • PCI ASV scan frequency under PCI DSS 4.0.1 Requirement 11.3.2 is at least once every three months, run by a PCI SSC Approved Scanning Vendor.
  • The 90-day window runs from the date of your last passing scan, not from a fixed calendar quarter.
  • Four passing scans in a rolling 12-month period are required for ongoing compliance, with a limited exception in year one only.
  • Requirement 11.3.2.1 adds a second trigger: any significant change to your environment requires an additional scan, on top of your regular quarterly cadence.
  • A passing ASV scan confirms Requirement 11.3.2 only; it does not, by itself, mean you're fully PCI DSS compliant.
  • Scheduling your initial scan around day 65–70 (not day 85+) leaves enough buffer to remediate and rescan before the deadline.

PCI ASV scan frequency sounds like the simplest requirement in PCI DSS 4.0.1: scan every 90 days, done. In practice, it’s one of the most commonly mishandled: merchants track the wrong start date, miss the trigger for a mid-cycle scan after an infrastructure change, or discover during an acquirer review that their “quarterly” scans have quietly drifted past the 90-day mark. None of that shows up until your acquirer asks for scan evidence and your QSA checks the dates, and by then, even a one-week gap can stall your assessment or flag you with your payment brand.

The rule itself is precise; the confusion comes from how it’s applied. This guide walks through exactly what Requirement 11.3.2 says, the specific points where merchants get the timing wrong, and how to build a scan schedule that holds up under review every time.

Key Definitions

Requirement 11.3.2: the PCI DSS 4.0.1 clause requiring external vulnerability scans at least once every three months, performed by a PCI SSC Approved Scanning Vendor.

Requirement 11.3.2.1: the companion clause requiring an additional scan after any significant change to your environment, independent of your quarterly cadence.

90-day window: the compliance clock that runs from the date of your last passing scan, not from a fixed calendar quarter.

Rolling 12-month period: the trailing 12 months of your QSA reviews to confirm four passing scans occurred are required from year two of assessment onwards.

ASV (Approved Scanning Vendor): a company on the current PCI SSC list authorised to perform the scans this requirement mandates. See what a PCI ASV scan checks.

Rescan: a follow-up scan confirming that findings from a failed scan have been remediated; the rescan date, not the initial scan date, is what counts against your deadline.

Book your PCI ASV scan with Secusy ASV; from $80/year, pass certificate within 24 hours.

PCI ASV Scan Frequency Under PCI DSS 4.0.1

PCI DSS 4.0.1 Requirement 11.3.2 mandates external vulnerability scans at least once every three months, performed by a PCI SSC Approved Scanning Vendor, with four passing scans required per rolling 12-month period.

PCI DSS 4.0.1 Requirement 11.3.2 mandates external vulnerability scans at least once every three months, performed by a PCI SSC Approved Scanning Vendor. The 90-day window runs from the date of your last passing scan; not from a fixed calendar quarter. Additional scans are required after any significant change to your environment. Four passing scans per rolling 12-month period are required for ongoing compliance.

What Requirement 11.3.2 Actually Says

The requirement mandates three things at once: scans at least every 90 days, every scan performed by a PCI SSC-listed ASV, and all vulnerabilities resolved with rescans confirming remediation.

The exact text from the ASV Program Guide is unambiguous: external vulnerability scans must be performed at least once every three months by a PCI SSC Approved Scanning Vendor. The assessment procedure (11.3.2.a) requires your QSA to examine scan reports from the last 12 months to confirm that at least four scans occurred within that period.

Three things that requirement mandates simultaneously:

  • Scans run at least every 90 days
  • Every scan must be performed by a PCI SSC-listed ASV
  • All vulnerabilities must be resolved, with rescans confirming remediation

 

A scan report from a non-listed vendor, regardless of how thorough it is, does not satisfy this requirement. The ASV’s listing status on the date the scan was performed is what counts, and your QSA will verify it.

The 90-Day Window: How It Actually Works

The 90-day clock starts from the date of your last passing scan, not from January 1st or a fixed calendar quarter, and it's the rescan date, not the initial scan date, that determines whether you're within the window.

Most merchants think in calendar quarters; Q1, Q2, Q3, Q4. That’s not how Requirement 11.3.2 works, and the distinction trips up a surprising number of otherwise well-run compliance programs.

The clock starts from the date of your last passing scan, not January 1st. If your last passing scan was issued on 15 March, your next scan must produce a passing result by 13 June; 90 days later. Run your scan on 10 June, fail on a medium-severity finding, remediate, and rescan on 20 June: you’ve just missed your window. The rescan date is what matters, not the initial scan date.

This is why unlimited rescans matter operationally, not just financially. If you’re paying per scan, a failed first attempt creates a direct incentive to delay remediation until the next cycle, which is exactly the wrong behaviour from a compliance standpoint. See how PCI ASV scan cost is affected by rescan pricing models.

Scan Event
Date
90-Day Deadline
Last passing scan
15 March
—
Next scan must pass by
—
13 June
Initial scan run
10 June
—
Rescan passing
20 June
❌ Window missed
Rescan passing
12 June
✅ Within window

The lesson: schedule your initial scan with enough buffer to remediate and rescan before the 90-day mark. For most environments, building in a two-to-three-week remediation window is practical. That means initiating your scan around day 65–70 of your cycle, not day 85. See our pre-scan preparation checklist for how to build that buffer in.

When Extra Scans Are Required: Requirement 11.3.2.1

Beyond the quarterly cadence, any significant change to your environment: new IPs, firewall changes, new applications, infrastructure migration, or segmentation changes triggers an additional required scan.

Quarterly cadence is the baseline. PCI DSS 4.0.1 Requirement 11.3.2.1 introduces an additional trigger: significant changes to your environment require an additional external scan.

What counts as a significant change? The standard doesn’t enumerate every scenario, but the intent is clear; any modification that could alter your external attack surface warrants a scan. In practice that includes:

  • New internet-facing IP addresses added to your CDE
  • Significant changes to firewall rules or network architecture
  • New web applications or major application updates in scope
  • Migration to new hosting infrastructure or cloud providers
  • Changes to network segmentation affecting CDE boundaries

 

The scan triggered by Requirement 11.3.2.1 is in addition to your quarterly schedule; it doesn’t reset or replace it. Miss this trigger, and you’ve technically failed the requirement, even if your quarterly scans are clean. This is a gap that many merchants and some compliance advisors overlook. If you launched a new payment page, moved to a different hosting provider, or changed your CDN configuration between your standard quarterly scans, an additional scan is required. Reviewing your PCI ASV scan requirements after any infrastructure change is the safest habit here.

The First-Year Exception (and Why It Doesn't Apply in Year Two)

In your first 12 months of assessment, you don't need four passing scans on record; one passing scan plus documented scanning policies and corrected vulnerabilities is enough. From year two, four passing scans are a hard requirement.

For entities going through their initial PCI DSS compliance assessment, the standard includes a limited exception: it is not required that four passing scans be completed within the first 12 months, provided the assessor can verify three things:

  1. The most recent scan result is a passing scan
  2. Documented policies and procedures requiring quarterly scanning are in place
  3. Vulnerabilities identified in scan results have been corrected

 

This exception exists to give newly assessed entities a practical on-ramp. It does not apply in subsequent years. From year two onwards, four passing scans in the preceding 12-month period is a hard requirement with no discretion for the QSA.

Does a Passing ASV Scan Mean You're PCI Compliant?

No. A passing ASV scan report confirms compliance with Requirement 11.3.2 only; it says nothing about the rest of PCI DSS and doesn't replace your SAQ or ROC.

No, and this is a misconception worth addressing directly. Per PCI SSC guidance, an ASV scan report confirms compliance with Requirement 11.3.2 only. It says nothing about any other PCI DSS requirement. Your scan certificate is one piece of a much larger compliance picture. It does not replace your SAQ, ROC, or any other assessment documentation. Acquirers and payment brands may request scan reports alongside your SAQ submission, but the scan report standing alone is not a compliance declaration.

What a passing scan from a PCI SSC-listed ASV does give you: documented evidence for Requirement 11.3.2 that is accepted by all acquiring banks. One certificate, multiple acquirers; you don’t need to rescan for each relation.

PCI ASV Scan Frequency: Quick Compliance Checklist

Before each scan cycle, confirm your last passing date, calculate your 90-day deadline, schedule the initial scan by day 65–70, and verify scope, remediation readiness, and rescan timing.

Use this before each scan cycle to confirm you’re on track:

What Happens When You Miss the Window

A lapsed scan cadence is a compliance failure; consequences range from a flagged SAQ gap to formal acquirer notification, with the most common real-world impact being a stalled account review.

A lapse in scan cadence is a compliance failure. Depending on your merchant level and payment brand requirements, the consequences range from a compliance gap on your SAQ to formal notification to your acquirer. In worst-case scenarios; particularly where an account data compromise follows a period of lapsed scanning; the exposure is substantial.

The practical risk for most small-to-mid-size merchants is simpler: your acquirer requests scan evidence during an annual review and the dates don’t stack up. That triggers remediation activity, potentially a formal compliance plan, and delay in any account processing agreements you’re trying to expand.

Running scans consistently at a fixed cadence; rather than scrambling quarterly; is the lowest-effort risk mitigation available. At $80/year for a single IP, the cost of maintaining that cadence is trivial against the cost of a compliance gap.

For a deeper look at the full scope of what ASV scanning covers, see PCI ASV Scanning Services: Everything You Need to Know.

Conclusion

The quarterly ASV scan requirement is one of the more mechanical aspects of PCI DSS 4.0.1; the rule is clear, the cadence is fixed, and the consequences of slipping are predictable. What varies is how much friction you introduce into the process. Track your last passing date, build a remediation buffer into your schedule, and treat significant infrastructure changes as their own scan trigger, and PCI ASV scan frequency stops being a compliance risk and becomes routine.

Book your PCI ASV scan with Secusy ASV; no sales calls, transparent pricing, results the same day.

Frequently Asked Questions

At least once every three months, per Requirement 11.3.2. The 90-day window runs from the date of your last passing scan. Four passing scans in a rolling 12-month period are required for ongoing compliance from year two of your assessment onwards.
From the last passing scan date. If your passing scan was issued on 20 April, your next scan must pass by 19 July; regardless of what calendar quarter that falls in. Treating it as a fixed calendar schedule is one of the most common causes of inadvertent compliance gaps.
Yes. Requirement 11.3.2.1 requires an additional external scan following any significant change to your environment. This is separate from your quarterly cadence and does not replace the next scheduled scan.
No. The external vulnerability scan required by Requirement 11.3.2 must be performed by a PCI SSC Approved Scanning Vendor. Internal tools and non-listed vendors cannot produce a compliant scan certificate, regardless of the quality of the scan.
No. A passing scan confirms compliance with Requirement 11.3.2 only; the external vulnerability scanning requirement. It provides no indication of compliance with any other PCI DSS requirement. Your SAQ or ROC documentation covers the full standard.
No. Only passing scans satisfy the quarterly requirement. If your initial scan fails, you must remediate and rescan. The passing rescan date is what the QSA uses to assess whether the 90-day window was met. This is why building remediation time into your schedule before the deadline is critical.

Authored by

Binoy Koonammavu blog image

Binoy Koonammavu, is the Founder and CEO of Secusy ASV, where he helps SMBs and fintech companies meet PCI DSS scanning requirements without the complexity of enterprise-grade tools. His writing focuses on making ASV compliance straightforward for growing businesses.

Share:

Related Post

 

Discover more from Secusy ASV

Subscribe now to keep reading and get access to the full archive.

Continue reading