Binoy Koonammavu
Your acquirer is asking for ASV scan results. Your QSA just flagged Requirement 11.3.2. Or someone on your team mentioned a “PCI external scan”, and nobody can quite explain what it actually requires, who has to do it, or what happens if it fails.
This is one of the most common points of confusion in PCI compliance, not because the rule is complicated, but because most explanations either oversimplify it or bury the details a compliance team actually needs in dense standards language.
This guide breaks down exactly what PCI ASV scanning requires under PCI DSS 4.0.1: who it applies to, what gets scanned, how often, and what a genuine pass looks like, so you can walk into your next audit or acquirer conversation with a clear answer instead of a guess.
Answer a few questions and find out which SAQ type applies to your business, and whether ASV scanning is required.
ASV (Approved Scanning Vendor): A company certified by the PCI Security Standards Council (PCI SSC) to perform external vulnerability scans for PCI DSS compliance. Only ASV-employed staff can configure scan parameters, assign severity levels, or issue results.
CDE (Cardholder Data Environment): The systems, networks, and processes that store, process, or transmit cardholder data, plus any connected systems that could provide a path into that environment.
SAQ (Self-Assessment Questionnaire): The compliance questionnaire type your acquiring bank or payment brand assigns based on how you handle card data. It determines which PCI DSS requirements, including ASV scanning, apply to your business.
CVSS (Common Vulnerability Scoring System): The 0-10 severity scale used to rank vulnerabilities found during a scan. A score of 4.0 or higher (medium, high, or critical) must be remediated for a scan to pass.
Attestation of Scan Compliance: The official report an ASV issues once a scan passes, using PCI SSC's required templates. This is the document you submit to your acquirer or QSA.
Under PCI DSS 4.0.1 Requirement 11.3.2, any in-scope merchant or service provider must run an external vulnerability scan at least once every three months, performed by a PCI SSC-listed ASV.
The scan must cover every Internet-facing component connected to your cardholder data environment. A passing certificate is only issued once all high- and medium-severity vulnerabilities (CVSS 4.0+) are remediated and a clean rescan confirms the fix. There’s no manual workaround here; Requirement 11.3.2 is explicit that only an ASV can perform this scan; internal or self-run scans don’t satisfy it.
Whether you need ASV scanning depends on your SAQ type, not on your business size or industry.
This is where a lot of businesses get caught out. The requirement isn’t universal; it depends on which Self-Assessment Questionnaire (SAQ) your acquirer or payment brand has assigned to you. ASV scanning is required under the following SAQ types:
SAQ Type | Who It Applies To | ASV Scan Required? |
|---|---|---|
SAQ A | E-commerce merchants using redirects or iframes to a compliant TPSP | Yes (PCI DSS v4 addition) |
SAQ A-EP | E-commerce merchants with partially outsourced payment pages | Yes |
SAQ B-IP | Merchants using IP-connected POI devices | Yes |
SAQ C | Merchants with payment application systems connected to the internet | Yes |
SAQ D (Merchants) | All merchants not covered by A, B, B-IP, or C | Yes |
SAQ D (Service Providers) | Service providers storing, processing, or transmitting cardholder data | Yes |
SAQ B | Merchants using only imprint machines or standalone dial-out terminals | No |
Important nuance on SAQ A: PCI DSS 4.0.1 expanded ASV scan requirements to SAQ A merchants; specifically those whose webpage either redirects to a PCI DSS-compliant third-party service provider (TPSP) or embeds a compliant TPSP payment page via iframe.
This was a deliberate response to the volume of e-commerce breaches targeting these redirect and iframe integrations. If you run a Shopify, WooCommerce, or similar store using a hosted checkout, you likely fall here. If you’re unsure which SAQ applies to you, your acquiring bank or payment brand defines that, not your ASV.
Scope covers every Internet-facing component that is part of, or connects to, your cardholder data environment.
That includes:
Systems that look low-risk on the surface, such as email servers and general internet access points, can still create a route into your network, and the ASV Program Guide is explicit that these need to be evaluated against your CDE boundary rather than assumed to be out of scope. If you’re relying on network segmentation to narrow your scope, your ASV needs to confirm that segmentation is properly implemented before excluding anything.
If part of your CDE is hosted with an ISP or multi-tenant provider, there are two ways this gets handled: either the provider undergoes its own ASV scan and shares the passing evidence with you, or their infrastructure gets included directly in your scan scope. Either way, the compliance responsibility stays with you, confirm which route your provider takes before your next scan cycle.
From $80/year per IP, unlimited rescans included, no sales call required.
A pass requires more than "no critical vulnerabilities"; it requires full remediation, a clean rescan, and an official attestation.
A passing scan under the ASV Program Guide isn’t just “no critical vulnerabilities found.” The full requirement includes:
One thing worth understanding: a passing ASV scan certificate only confirms compliance with Requirement 11.3.2. It does not certify compliance with the rest of PCI DSS. Your scan report is one piece of evidence your acquirer or QSA reviews, not a full compliance endorsement.
A failed scan doesn't end your compliance cycle; it starts a remediation loop, not a penalty.
Failing scans don’t end your compliance cycle; they start a remediation loop. The process under the ASV Program Guide:
A point practitioners often overlook: Denial of Service (DoS) vulnerabilities, where CVSS Confidentiality Impact and Integrity Impact is both “None” and explicitly excluded from failing a scan under ASV Program Guide rules. ASVs are required not to count DoS-only vulnerabilities as compliance failures. If an ASV is failing your scan for a pure DoS finding with no cardholder data exposure risk, that’s a dispute worth raising.
Similarly, the Triple DEA (3DES/TDES) cipher vulnerability is ranked as Medium by CVSS. Under Requirement 11.2.2, medium and high vulnerabilities must be corrected; but your ASV can re-rank a vulnerability’s severity if your specific environment justifies it, and you can dispute findings where compensating controls reduce the real-world risk.
Most first-time scan failures come down to scope gaps, blocked scan traffic, or skipping the rescan, not actual unfixable vulnerabilities.
Most businesses that struggle to pass their first scan run into the same issues:
PCI ASV scanning under PCI DSS 4.0.1 Requirement 11.3.2 is a quarterly external vulnerability scan of all Internet-facing systems connected to your CDE, performed by a PCI SSC-listed vendor. A passing result requires remediation of all medium-severity and above findings, confirmed by a clean rescan.
The requirement applies to most e-commerce merchants, SaaS companies handling card payments, and service providers; including SAQ A merchants since PCI DSS v4. It does not confirm full PCI compliance, but it is a mandatory component of it.
For the full mechanics of the scanning process; what scopes, what fails, and how to prepare; see our complete guide to PCI ASV scanning services.
Secusy ASV is PCI SSC-listed, with analyst support and pass certificates delivered within 24 hours of a clean scan.
Any merchant or service provider whose SAQ type includes ASV scanning under PCI DSS 4.0.1. This covers SAQ A (e-commerce only), SAQ A-EP, SAQ B-IP, SAQ C, SAQ D for merchants, and SAQ D for service providers. Your acquiring bank determines which SAQ applies to you.
No. PCI DSS 4.0.1 Requirement 11.3.2 is explicit — external vulnerability scans must be performed by a PCI SSC-listed ASV. You can initiate a scan through an ASV's portal, but only ASV-employed staff can configure scan parameters, assign severity levels, or modify scan output. Self-scanning does not satisfy the requirement.
At minimum, once every three months. The 90-day window runs from the date of your last passing scan. Additional scans are required under Requirement 11.3.2.1 after significant environment changes — new infrastructure, architecture changes, or major configuration updates.
No. A passing certificate confirms compliance with Requirement 11.3.2 only. It is one piece of evidence within a full compliance programme. Your acquirer or QSA will review it alongside your SAQ, network documentation, access controls, and other requirements. PCI SSC has confirmed this explicitly — any additional documentation an ASV provides (certificates, letters) is supplemental and not endorsed by PCI SSC as a replacement for the official scan templates.
Vulnerabilities with a CVSS score of 4.0 or above — classified as medium, high, or critical — must be remediated for a scan to pass under Requirement 11.2.2. Pure Denial of Service vulnerabilities, where CVSS Confidentiality and Integrity Impact are both "None," are explicitly excluded from failing criteria by the ASV Program Guide.
That depends entirely on your ASV. With Secusy ASV, pass certificates are delivered within 24 hours of a clean scan — no waiting on a manual review queue.

Binoy Koonammavu, is the Founder and CEO of Secusy ASV, where he helps SMBs and fintech companies meet PCI DSS scanning requirements without the complexity of enterprise-grade tools. His writing focuses on making ASV compliance straightforward for growing businesses.
Subscribe now to keep reading and get access to the full archive.