PCI ASV Scanning Checklist: What to Do Every 90 Days to Stay Compliant Year-Round

Published on

Updated on

Key Takeaways
  • PCI DSS Requirement 11.3.2 mandates external vulnerability scans at least once every 90 days, run by a PCI SSC-approved ASV, and after any significant network change.
  • A PCI ASV scanning checklist turns a once-a-quarter scramble into a repeatable four-phase process: pre-scan preparation, scan execution, remediation, and documentation.
  • Scope accuracy: every external IP, domain, and cloud service tied to the cardholder data environment is the single most common reason scans fail.
  • A scan isn't compliant until vulnerabilities are remediated and a passing rescan is confirmed; the Attestation of Scan Compliance is what proves it.
  • Anchoring all four quarterly scans to fixed calendar dates, with built-in prep and remediation buffers, is what separates businesses that stay compliant year-round from those that lapse between audits.

A PCI ASV scanning checklist is what stands between “we passed a scan once” and “we are actually PCI compliant.” PCI DSS Requirement 11.3.2 requires external vulnerability scans from a PCI SSC-approved Approved Scanning Vendor (ASV) at least once every 90 days, and each scan has to come back clean or with vulnerabilities remediated and rescanned before that quarter counts as compliant.

For most businesses, the problem isn’t knowing that ASV scans are required. It’s knowing exactly what has to happen before, during, and after each scan so the result is valid, clean, and accepted by a QSA or acquiring bank. Without a structured checklist, organisations routinely run into avoidable failures: incomplete scope, blocked scan traffic, unpatched systems, or rescans that slip past the compliance deadline.

This guide breaks down a practical, repeatable PCI ASV scanning checklist: everything to do every 90 days to stay compliant year-round, not just compliant in bursts.

Key Definitions

ASV (Approved Scanning Vendor): A company certified by the PCI Security Standards Council (PCI SSC) to perform external vulnerability scans required under PCI DSS. Only scans from a PCI SSC-approved ASV count toward compliance.

External vulnerability scan: A non-intrusive scan of internet-facing IP addresses, domains, and systems to identify vulnerabilities an attacker could exploit from outside the network perimeter. Under Requirement 11.3.2, these scans run quarterly and after any significant network change.

Cardholder Data Environment (CDE): The systems, networks, and processes that store, process, or transmit payment card data. Any external IP or domain connected to or supporting the CDE is in scope for ASV scanning.

Attestation of Scan Compliance: A formal document an ASV issues after a passing scan, confirming the scan met PCI DSS requirements and that identified vulnerabilities were remediated or addressed.

Understanding Quarterly PCI Scan Requirements

PCI DSS Requirement 11.3.2 requires any entity with external-facing systems connected to the cardholder data environment to run vulnerability scans with a PCI SSC-approved ASV at least once every 90 days and again after any significant network change.

Quarterly scanning is a requirement, not a suggestion. The 90-day cadence exists because new vulnerabilities are disclosed constantly; a system that passed a scan three months ago can be exposed to entirely new risks by the next scan window. The requirement covers all external-facing IPs and domains within or connected to the CDE; a payment gateway, a customer portal, or any internet-facing service that touches cardholder data all fall in scope. Many organisations only discover scope gaps when a QSA or acquiring bank challenges their scan documentation, by which point it’s too late to avoid a compliance finding.

It also applies outside the quarterly cycle: adding a server, changing network architecture, or deploying a new application all trigger a fresh scan requirement before that change is considered compliant. Building change-triggered scans into security planning, not just the quarterly calendar, is what separates organisations that are compliant in practice from those that are compliant only on paper.

Get Your Next Quarterly Scan Scheduled

Stay ahead of the 90-day deadline instead of racing it.

Building Your PCI ASV Scanning Checklist: The Four Phases

A complete PCI ASV scanning checklist covers four phases: pre-scan preparation, scan execution, post-scan remediation, and compliance documentation, each with a defined owner and deadline.

Treating the ASV scan as a single event rather than a four-phase process is one of the most common mistakes businesses make. When something goes wrong  a failed scan, a missed IP, or a blocked port – there’s no documented process to fall back on, and the result is delay and confusion. A checklist turns the quarterly scan into a predictable workflow instead of a stressful one.

Phase 1: Pre-scan preparation (weeks 1–2 before the scan)

Pull the current list of external IPs and fully qualified domain names tied to the CDE. Compare it against the previous scan submission and network documentation to catch additions, removals, or changes. Review firewall and IPS configurations so ASV scan traffic isn't blocked or throttled. Patch outstanding critical and high-severity vulnerabilities before the scan window opens.

Phase 2: Scan execution

Confirm the scan date and time with the ASV in writing, and make sure the right internal team is available in case of issues. Avoid infrastructure changes during an active scan; mid-scan changes can invalidate results. Keep a record of the scan confirmation, including the date, ASV name, and scope submitted.

Phase 3: Post-scan remediation

Review results systematically. Prioritise any finding rated medium, high, or critical, since these are what typically prevent a passing result. Assign ownership and deadlines, then coordinate a rescan once remediation is complete.

Phase 4: Compliance documentation

Once the scan passes, secure the Attestation of Scan Compliance and store it alongside previous reports. A QSA or acquiring bank will want evidence of continuous quarterly scanning, not just the latest result.

Step-by-Step: Your External Vulnerability Scan Checklist

An external vulnerability scan checklist should walk through scope verification, environment readiness, scan execution, results review, and documentation, applied the same way every quarter.

This is the working checklist to hand to whoever owns PCI compliance internally or at an MSP partner.

Scope verification

Environment readiness

Scan execution

Results review and remediation

Documentation and attestation

Building an ASV Scan Schedule That Works Year-Round

An effective ASV scan schedule anchors each of the four quarterly scans to a fixed calendar date, with pre-scan and post-scan tasks built in as recurring items, so the 90-day window never slips through operational gaps.

Set all four scan dates at the start of the year and build the surrounding tasks backwards from each one. This removes the most common cause of missed scans: assuming someone else has it covered or that there’s more time than there actually is. Ninety days sounds generous until two weeks of preparation, a scan window, and a remediation-and-rescan cycle are factored in.

A workable annual ASV scan schedule looks something like this: Q1 scan in mid-January (covering changes made over the holiday period), Q2 in mid-April, Q3 in mid-July, and Q4 in mid-October, each preceded by a two-week prep window and followed by a two-week remediation window, leaving a clear buffer before the next cycle starts. Assigning a named scan coordinator for each cycle removes ambiguity about ownership.

The ASV partner matters here too. A reliable ASV gives advance notice of scan windows, delivers results promptly so remediation isn’t delayed, and makes rescans straightforward. When evaluating an ASV, ask specifically about average turnaround from scan initiation to report delivery; slow reporting eats directly into the remediation window.

Not Sure If You're In Scope?

Check exactly which systems and domains PCI DSS requires you to scan.

Common Reasons Quarterly Scans Fail

Most quarterly scan failures trace back to a handful of recurring causes: scope gaps, expired certificates, unpatched software, blocked scan traffic, or a missed rescan, all of which a structured checklist catches before they become compliance gaps.

  • Scope gaps: new infrastructure added without updating scan scope
  • Expired certificates: SSL/TLS issues are among the most common recurring findings
  • Unpatched CMS or plugins: especially on WordPress, Magento, and similar platforms
  • Firewall/WAF blocking: scans misreported as failing because scanner traffic was blocked, not because of a real vulnerability
  • Missed rescans: treating the first scan as final instead of confirming remediation with a passing rescan

Maintaining PCI Compliance Year-Round Beyond the Scan

Staying PCI compliant year-round means treating the quarterly scan as one part of an ongoing security programme, not the whole of it, with continuous patch management and change control running between scan cycles.

A passing ASV scan confirms external-facing systems were free of exploitable vulnerabilities then. It doesn’t guarantee the environment stays that way for the next 90 days. New vulnerabilities are disclosed constantly, and relying solely on the quarterly scan without maintaining security hygiene in between leaves unnecessary risk on the table.

Between scans, consistent patch management and a change-control process that requires security review before any new system or domain goes live are what most directly support clean results. Without that gate, scope creep builds quietly between cycles, and businesses arrive at scan time with assets they didn’t know were in scope. Internal vulnerability scanning is required separately under PCI DSS; it also supports year-round compliance when its findings inform what to watch for in the next external scan.

Documentation discipline is what ties it together. Compliance isn’t just a passing scan; it’s being able to show a continuous, documented history of scanning, remediation, and security management. Businesses with that record are far better positioned during a QSA assessment than those reconstructing their compliance history at audit time.

For authoritative detail beyond this checklist, the PCI Security Standards Council’s official documentation at pcisecuritystandards.org is the primary source for Requirement 11.3.2, alongside Verizon’s annual Payment Security Report and SANS Institute research on vulnerability management.

Conclusion

A quarterly PCI ASV scanning checklist isn’t administrative overhead; it’s the operational backbone of a defensible, continuous compliance programme. Every 90 days, the external attack surface needs reviewing, vulnerabilities need addressing, and documentation needs updating. Businesses that work this cycle with a structured checklist, a fixed ASV scan schedule, and clear ownership at each phase consistently avoid the compliance gaps that catch others out. Staying compliant year-round isn’t about bigger security budgets; it’s about making the quarterly cycle a predictable process rather than a periodic crisis.

Failed a Recent Scan?

Get remediation guidance and a fast rescan before your compliance window closes.

Frequently Asked Questions

A PCI ASV scan is an external vulnerability scan run by a PCI SSC-approved vendor to find weaknesses in internet-facing systems. It's required under PCI DSS Requirement 11.3.2 for any entity whose external systems connect to the cardholder data environment, at least every 90 days.

At least once every 90 days for any business that stores, processes, or transmits cardholder data over the internet, and again after any significant network change.

Scope verification of all external IPs and domains, environment readiness (firewall and patch status), scan execution records, remediation tracking, and secure storage of the Attestation of Scan Compliance.
Any vulnerability that caused the failure must be remediated, and the full original scope must be rescanned until it returns a clean result. Compliance isn't achieved until a passing report and Attestation of Scan Compliance are issued.
No. Scope should be reviewed and updated every quarter to account for new IPs, subdomains, cloud services, or third-party integrations added since the last scan.
The merchant or service provider being scanned. Acquirers, QSAs, and payment processors can request passing scan reports and remediation evidence at any time, not only during a formal audit.

Far far away, behind the word mountains, far from the countries Vokalia and Consonantia, there live the blind texts. Separated they live in Bookmarksgrove right at the coast

Document all external-facing IPs and domains in scope, whitelist the ASV's source IP ranges in firewalls and IPS systems, apply outstanding critical patches, and confirm the scan window with the provider in advance.

Authored by

Binoy Koonammavu blog image

Binoy Koonammavu, is the Founder and CEO of Secusy ASV, where he helps SMBs and fintech companies meet PCI DSS scanning requirements without the complexity of enterprise-grade tools. His writing focuses on making ASV compliance straightforward for growing businesses.

Share:

Related Post

 

Discover more from Secusy ASV

Subscribe now to keep reading and get access to the full archive.

Continue reading