Binoy Koonammavu
PCI DSS v4.0 ASV scanning is no longer the checkbox exercise it was under the previous standard. If your compliance calendar still treats a quarterly scan as a single pass/fail event with no paper trail behind it, that approach is already behind where PCI DSS v4.0.1 has moved. As of March 31, 2025, every future-dated requirement in the standard is enforceable, and external vulnerability scanning, now numbered Requirement 11.3.2, carries more explicit expectations around scope accuracy and remediation evidence than it did under v3.2.1.
The core mechanics are still familiar: a PCI SSC-approved vendor scans your internet-facing systems every three months, and you remediate anything that fails. What’s different is who has to do it, SAQ A merchants in particular, and what an assessor now expects to see behind a passing report. This guide walks through Requirement 11.3.2 as it stands today, the real differences from v3.2.1, and the practical steps to keep a scanning program audit-ready.
Approved Scanning Vendor (ASV): A company certified by the PCI Security Standards Council (PCI SSC) to perform external vulnerability scans and issue official Attestations of Scan Compliance. Only PCI SSC-listed ASVs satisfy Requirement 11.3.2.
Cardholder Data Environment (CDE): The people, processes, and technology that store, process, or transmit cardholder data, plus any systems connected to or capable of impacting that environment's security.
Requirement 11.3.2: The PCI DSS v4.0/v4.0.1 control requires external vulnerability scans by an ASV at least once every three months, with a passing result confirmed by remediation and rescan.
Requirement 11.3.2.1: A newer sub-requirement extending quarterly ASV scanning obligations specifically to SAQ A merchants, many of whom weren't previously in scope.
Vulnerability Rescan: A follow-up scan performed after remediating findings from an initial scan. A passing rescan is required to close out a quarterly compliance period.
Requirement 11.3.2 requires a quarterly external vulnerability scan of every internet-facing system connected to the CDE, performed by a PCI SSC-listed ASV, with all medium-severity-and-above findings remediated and confirmed by a passing rescan.
This is the same underlying obligation that existed under v3.2.1’s Requirement 11.2.2; the scanning cadence and pass criteria haven’t been rewritten. What v4.0 adds is an accountability layer around what happens after the scan runs. Assessors increasingly expect evidence that vulnerabilities were actually remediated: patch records, configuration change logs, or documented compensating controls, not just a clean rescan sitting in a compliance folder. Scans must also happen immediately after any significant environment change, not just once per quarter on a fixed schedule.
PCI DSS v4.0 brought SAQ A into scope for many merchants. Confirm exactly what applies to your environment.
The quarterly scan frequency and CVSS-based pass criteria are unchanged, but v4.0 renumbered the requirement, tightened scope-accuracy accountability, and extended scanning obligations to SAQ A merchants for the first time.
External ASV scanning moved from Requirement 11.2.2 (v3.2.1) to Requirement 11.3.2 (v4.0/4.0.1), reflecting a broader restructuring of Requirement 11 around ongoing external attack-surface management rather than a standalone quarterly task.
Every internet-facing IP address and domain connected to the CDE must appear in each scan. Scope drift, a new cloud instance, a forgotten subdomain, is treated as a compliance gap under v4.0, not just a technical oversight.
Under v3.2.1, many SAQ A e-commerce merchants using a full payment redirect were exempt from ASV scanning entirely. PCI DSS v4.0 introduced sub-requirement 11.3.2.1, bringing quarterly external scans into SAQ A for the first time, specifically to address rising breach activity targeting SAQ A environments.
Often, yes. Requirement 11.3.2.1 under PCI DSS v4.0 introduced quarterly ASV scanning for SAQ A merchants, a population that was largely exempt under v3.2.1.
The PCI SSC has published SAQ A-specific guidance precisely because so many of these merchants are completing this requirement for the first time. Whether it applies to a specific business still depends on the exact payment integration; a genuine full-redirect setup where no cardholder data ever touches the merchant’s own servers sits closest to any remaining exemption, but that determination should come from a QSA or acquiring bank rather than an assumption carried over from a prior assessment cycle.
A passing scan requires no unresolved vulnerabilities rated CVSS 4.0 or higher, confirmed by a clean rescan completed within the same quarterly window, and the window matters as much as the result.
Running a scan late in the quarter, failing on the first attempt, and remediating into the start of the next quarter does not satisfy the requirement for the quarter that just closed. That gap is a finding, not a rounding error, and it’s one of the more common ways otherwise diligent teams fall out of compliance. Scheduling the scan early in the quarter, not the final week, leaves room for triage, remediation, and a passing rescan before the window closes.
Get a PCI SSC-approved external vulnerability scan with clear, actionable reporting.
A single failed scan is expected and recoverable through remediation and rescan, but an unresolved failure that carries across quarterly boundaries constitutes a compliance gap that cannot be corrected retroactively.
A formal dispute process exists through the ASV for confirmed false positives or genuinely mitigating compensating controls; it is not a mechanism for deferring real remediation work, and assessors scrutinize repeated dispute use accordingly. For businesses with dynamic infrastructure, frequent deployments, active cloud footprints, and ongoing development touching the CDE, quarterly scanning is a compliance floor, not a security ceiling; more frequent scanning closes the visibility gap that a fixed 90-day cycle leaves open.
Any vendor on the PCI SSC's current Approved Scanning Vendor list can produce a valid report, but report clarity, remediation guidance, and rescan turnaround are what actually determine whether a scanning program holds up under assessor and acquirer scrutiny.
PCI SSC approval is the baseline, not the differentiator, every listed ASV has met the same technical bar. What varies is whether scan reports translate into action a compliance team can actually use: clear severity context, remediation guidance tied to business impact, and rescans that don’t turn into a new billable event every time. For SMBs without a dedicated security function, fast onboarding and responsive support during a failed scan matter as much as the scan itself, particularly given how little slack the quarterly window leaves for delay.
PCI DSS v4.0 didn’t rewrite the ASV scanning playbook, the quarterly cadence, the CVSS 4.0+ pass bar, and the ASV-only rule all carry over from v3.2.1. What changed is the margin for error: scope has to be demonstrably accurate, remediation has to be documented, and SAQ A merchants who were exempt before now have a dedicated requirement of their own. Auditing current scan scope, confirming SAQ type with a QSA or acquirer, and building a scanning calendar with real remediation runway are the three moves that close the gap between the old standard’s expectations and where v4.0.1 actually sits today.
See current, transparent pricing for PCI ASV scanning before your next quarterly window opens.
It's the mandatory external vulnerability scan performed by a PCI SSC-approved vendor against every internet-facing system connected to the cardholder data environment, required quarterly under Requirement 11.3.2.
At minimum once every three months, four scans per year, plus an additional scan after any significant change to the environment.
Many now do. Sub-requirement 11.3.2.1 extends quarterly ASV scanning to SAQ A merchants, a group largely exempt under the prior standard.
Remediate the findings and pass a rescan within the same quarterly window. Carrying an unresolved failure into the next quarter creates a compliance gap.

Binoy Koonammavu, is the Founder and CEO of Secusy ASV, where he helps SMBs and fintech companies meet PCI DSS scanning requirements without the complexity of enterprise-grade tools. His writing focuses on making ASV compliance straightforward for growing businesses.
Subscribe now to keep reading and get access to the full archive.