Binoy Koonammavu
A PCI ASV scanning checklist is what stands between “we passed a scan once” and “we are actually PCI compliant.” PCI DSS Requirement 11.3.2 requires external vulnerability scans from a PCI SSC-approved Approved Scanning Vendor (ASV) at least once every 90 days, and each scan has to come back clean or with vulnerabilities remediated and rescanned before that quarter counts as compliant.
For most businesses, the problem isn’t knowing that ASV scans are required. It’s knowing exactly what has to happen before, during, and after each scan so the result is valid, clean, and accepted by a QSA or acquiring bank. Without a structured checklist, organisations routinely run into avoidable failures: incomplete scope, blocked scan traffic, unpatched systems, or rescans that slip past the compliance deadline.
This guide breaks down a practical, repeatable PCI ASV scanning checklist: everything to do every 90 days to stay compliant year-round, not just compliant in bursts.
ASV (Approved Scanning Vendor): A company certified by the PCI Security Standards Council (PCI SSC) to perform external vulnerability scans required under PCI DSS. Only scans from a PCI SSC-approved ASV count toward compliance.
External vulnerability scan: A non-intrusive scan of internet-facing IP addresses, domains, and systems to identify vulnerabilities an attacker could exploit from outside the network perimeter. Under Requirement 11.3.2, these scans run quarterly and after any significant network change.
Cardholder Data Environment (CDE): The systems, networks, and processes that store, process, or transmit payment card data. Any external IP or domain connected to or supporting the CDE is in scope for ASV scanning.
Attestation of Scan Compliance: A formal document an ASV issues after a passing scan, confirming the scan met PCI DSS requirements and that identified vulnerabilities were remediated or addressed.
PCI DSS Requirement 11.3.2 requires any entity with external-facing systems connected to the cardholder data environment to run vulnerability scans with a PCI SSC-approved ASV at least once every 90 days and again after any significant network change.
Quarterly scanning is a requirement, not a suggestion. The 90-day cadence exists because new vulnerabilities are disclosed constantly; a system that passed a scan three months ago can be exposed to entirely new risks by the next scan window. The requirement covers all external-facing IPs and domains within or connected to the CDE; a payment gateway, a customer portal, or any internet-facing service that touches cardholder data all fall in scope. Many organisations only discover scope gaps when a QSA or acquiring bank challenges their scan documentation, by which point it’s too late to avoid a compliance finding.
It also applies outside the quarterly cycle: adding a server, changing network architecture, or deploying a new application all trigger a fresh scan requirement before that change is considered compliant. Building change-triggered scans into security planning, not just the quarterly calendar, is what separates organisations that are compliant in practice from those that are compliant only on paper.
Stay ahead of the 90-day deadline instead of racing it.
A complete PCI ASV scanning checklist covers four phases: pre-scan preparation, scan execution, post-scan remediation, and compliance documentation, each with a defined owner and deadline.
Treating the ASV scan as a single event rather than a four-phase process is one of the most common mistakes businesses make. When something goes wrong a failed scan, a missed IP, or a blocked port – there’s no documented process to fall back on, and the result is delay and confusion. A checklist turns the quarterly scan into a predictable workflow instead of a stressful one.
Pull the current list of external IPs and fully qualified domain names tied to the CDE. Compare it against the previous scan submission and network documentation to catch additions, removals, or changes. Review firewall and IPS configurations so ASV scan traffic isn't blocked or throttled. Patch outstanding critical and high-severity vulnerabilities before the scan window opens.
Confirm the scan date and time with the ASV in writing, and make sure the right internal team is available in case of issues. Avoid infrastructure changes during an active scan; mid-scan changes can invalidate results. Keep a record of the scan confirmation, including the date, ASV name, and scope submitted.
Review results systematically. Prioritise any finding rated medium, high, or critical, since these are what typically prevent a passing result. Assign ownership and deadlines, then coordinate a rescan once remediation is complete.
Once the scan passes, secure the Attestation of Scan Compliance and store it alongside previous reports. A QSA or acquiring bank will want evidence of continuous quarterly scanning, not just the latest result.
An external vulnerability scan checklist should walk through scope verification, environment readiness, scan execution, results review, and documentation, applied the same way every quarter.
An effective ASV scan schedule anchors each of the four quarterly scans to a fixed calendar date, with pre-scan and post-scan tasks built in as recurring items, so the 90-day window never slips through operational gaps.
Set all four scan dates at the start of the year and build the surrounding tasks backwards from each one. This removes the most common cause of missed scans: assuming someone else has it covered or that there’s more time than there actually is. Ninety days sounds generous until two weeks of preparation, a scan window, and a remediation-and-rescan cycle are factored in.
A workable annual ASV scan schedule looks something like this: Q1 scan in mid-January (covering changes made over the holiday period), Q2 in mid-April, Q3 in mid-July, and Q4 in mid-October, each preceded by a two-week prep window and followed by a two-week remediation window, leaving a clear buffer before the next cycle starts. Assigning a named scan coordinator for each cycle removes ambiguity about ownership.
The ASV partner matters here too. A reliable ASV gives advance notice of scan windows, delivers results promptly so remediation isn’t delayed, and makes rescans straightforward. When evaluating an ASV, ask specifically about average turnaround from scan initiation to report delivery; slow reporting eats directly into the remediation window.
Check exactly which systems and domains PCI DSS requires you to scan.
Most quarterly scan failures trace back to a handful of recurring causes: scope gaps, expired certificates, unpatched software, blocked scan traffic, or a missed rescan, all of which a structured checklist catches before they become compliance gaps.
Staying PCI compliant year-round means treating the quarterly scan as one part of an ongoing security programme, not the whole of it, with continuous patch management and change control running between scan cycles.
A passing ASV scan confirms external-facing systems were free of exploitable vulnerabilities then. It doesn’t guarantee the environment stays that way for the next 90 days. New vulnerabilities are disclosed constantly, and relying solely on the quarterly scan without maintaining security hygiene in between leaves unnecessary risk on the table.
Between scans, consistent patch management and a change-control process that requires security review before any new system or domain goes live are what most directly support clean results. Without that gate, scope creep builds quietly between cycles, and businesses arrive at scan time with assets they didn’t know were in scope. Internal vulnerability scanning is required separately under PCI DSS; it also supports year-round compliance when its findings inform what to watch for in the next external scan.
Documentation discipline is what ties it together. Compliance isn’t just a passing scan; it’s being able to show a continuous, documented history of scanning, remediation, and security management. Businesses with that record are far better positioned during a QSA assessment than those reconstructing their compliance history at audit time.
For authoritative detail beyond this checklist, the PCI Security Standards Council’s official documentation at pcisecuritystandards.org is the primary source for Requirement 11.3.2, alongside Verizon’s annual Payment Security Report and SANS Institute research on vulnerability management.
A quarterly PCI ASV scanning checklist isn’t administrative overhead; it’s the operational backbone of a defensible, continuous compliance programme. Every 90 days, the external attack surface needs reviewing, vulnerabilities need addressing, and documentation needs updating. Businesses that work this cycle with a structured checklist, a fixed ASV scan schedule, and clear ownership at each phase consistently avoid the compliance gaps that catch others out. Staying compliant year-round isn’t about bigger security budgets; it’s about making the quarterly cycle a predictable process rather than a periodic crisis.
Get remediation guidance and a fast rescan before your compliance window closes.
At least once every 90 days for any business that stores, processes, or transmits cardholder data over the internet, and again after any significant network change.
Far far away, behind the word mountains, far from the countries Vokalia and Consonantia, there live the blind texts. Separated they live in Bookmarksgrove right at the coast

Binoy Koonammavu, is the Founder and CEO of Secusy ASV, where he helps SMBs and fintech companies meet PCI DSS scanning requirements without the complexity of enterprise-grade tools. His writing focuses on making ASV compliance straightforward for growing businesses.
Subscribe now to keep reading and get access to the full archive.