What PCI DSS v4.0 Means for Your ASV Scanning Program

Published on

Updated on

Key Takeaways
  • PCI DSS v4.0 ASV scanning is governed by Requirement 11.3.2, which replaced the older Requirement 11.2.2 from PCI DSS v3.2.1; same obligation, new number, sharper expectations.
  • All 51 future-dated v4.0 requirements became mandatory on March 31, 2025. There is no remaining grace period.
  • The quarterly cadence and CVSS 4.0+ pass bar haven't changed; what's changed is the documentation and scope-accuracy expected around each scan.
  • SAQ A merchants, many of whom were exempt from ASV scanning under v3.2.1, now fall under a dedicated sub-requirement (11.3.2.1) requiring quarterly external scans for the first time.
  • Only a PCI SSC-listed Approved Scanning Vendor can produce a report that satisfies Requirement 11.3.2, self-scanning never qualifies, regardless of tooling.

PCI DSS v4.0 ASV scanning is no longer the checkbox exercise it was under the previous standard. If your compliance calendar still treats a quarterly scan as a single pass/fail event with no paper trail behind it, that approach is already behind where PCI DSS v4.0.1 has moved. As of March 31, 2025, every future-dated requirement in the standard is enforceable, and external vulnerability scanning, now numbered Requirement 11.3.2, carries more explicit expectations around scope accuracy and remediation evidence than it did under v3.2.1.

The core mechanics are still familiar: a PCI SSC-approved vendor scans your internet-facing systems every three months, and you remediate anything that fails. What’s different is who has to do it, SAQ A merchants in particular, and what an assessor now expects to see behind a passing report. This guide walks through Requirement 11.3.2 as it stands today, the real differences from v3.2.1, and the practical steps to keep a scanning program audit-ready.

Key Definitions

Approved Scanning Vendor (ASV): A company certified by the PCI Security Standards Council (PCI SSC) to perform external vulnerability scans and issue official Attestations of Scan Compliance. Only PCI SSC-listed ASVs satisfy Requirement 11.3.2.

Cardholder Data Environment (CDE): The people, processes, and technology that store, process, or transmit cardholder data, plus any systems connected to or capable of impacting that environment's security.

Requirement 11.3.2: The PCI DSS v4.0/v4.0.1 control requires external vulnerability scans by an ASV at least once every three months, with a passing result confirmed by remediation and rescan.

Requirement 11.3.2.1: A newer sub-requirement extending quarterly ASV scanning obligations specifically to SAQ A merchants, many of whom weren't previously in scope.

Vulnerability Rescan: A follow-up scan performed after remediating findings from an initial scan. A passing rescan is required to close out a quarterly compliance period.

PCI DSS v4.0 ASV Scanning Requirement 11.3.2 Explained

Requirement 11.3.2 requires a quarterly external vulnerability scan of every internet-facing system connected to the CDE, performed by a PCI SSC-listed ASV, with all medium-severity-and-above findings remediated and confirmed by a passing rescan.

This is the same underlying obligation that existed under v3.2.1’s Requirement 11.2.2; the scanning cadence and pass criteria haven’t been rewritten. What v4.0 adds is an accountability layer around what happens after the scan runs. Assessors increasingly expect evidence that vulnerabilities were actually remediated: patch records, configuration change logs, or documented compensating controls, not just a clean rescan sitting in a compliance folder. Scans must also happen immediately after any significant environment change, not just once per quarter on a fixed schedule.

Not Sure If Your SAQ Type Requires ASV Scanning?

PCI DSS v4.0 brought SAQ A into scope for many merchants. Confirm exactly what applies to your environment.

What Changed Between PCI DSS v3.2.1 and v4.0 for ASV Scans?

The quarterly scan frequency and CVSS-based pass criteria are unchanged, but v4.0 renumbered the requirement, tightened scope-accuracy accountability, and extended scanning obligations to SAQ A merchants for the first time.

Three differences matter most in practice:
01

Renumbering with substance behind it

External ASV scanning moved from Requirement 11.2.2 (v3.2.1) to Requirement 11.3.2 (v4.0/4.0.1), reflecting a broader restructuring of Requirement 11 around ongoing external attack-surface management rather than a standalone quarterly task.

02

Explicit scope-accuracy responsibility

Every internet-facing IP address and domain connected to the CDE must appear in each scan. Scope drift, a new cloud instance, a forgotten subdomain, is treated as a compliance gap under v4.0, not just a technical oversight.

03

SAQ A now in scope

Under v3.2.1, many SAQ A e-commerce merchants using a full payment redirect were exempt from ASV scanning entirely. PCI DSS v4.0 introduced sub-requirement 11.3.2.1, bringing quarterly external scans into SAQ A for the first time, specifically to address rising breach activity targeting SAQ A environments.

Do SAQ A Merchants Need ASV Scans Under PCI DSS v4.0?

Often, yes. Requirement 11.3.2.1 under PCI DSS v4.0 introduced quarterly ASV scanning for SAQ A merchants, a population that was largely exempt under v3.2.1.

The PCI SSC has published SAQ A-specific guidance precisely because so many of these merchants are completing this requirement for the first time. Whether it applies to a specific business still depends on the exact payment integration; a genuine full-redirect setup where no cardholder data ever touches the merchant’s own servers sits closest to any remaining exemption, but that determination should come from a QSA or acquiring bank rather than an assumption carried over from a prior assessment cycle.

What Counts as a Passing Quarterly ASV Scan Under v4.0?

A passing scan requires no unresolved vulnerabilities rated CVSS 4.0 or higher, confirmed by a clean rescan completed within the same quarterly window, and the window matters as much as the result.

Running a scan late in the quarter, failing on the first attempt, and remediating into the start of the next quarter does not satisfy the requirement for the quarter that just closed. That gap is a finding, not a rounding error, and it’s one of the more common ways otherwise diligent teams fall out of compliance. Scheduling the scan early in the quarter, not the final week, leaves room for triage, remediation, and a passing rescan before the window closes.

Ready to Run a Compliant Quarterly Scan?

Get a PCI SSC-approved external vulnerability scan with clear, actionable reporting.

What Happens If You Miss a Quarter or Fail an External Vulnerability Scan?

A single failed scan is expected and recoverable through remediation and rescan, but an unresolved failure that carries across quarterly boundaries constitutes a compliance gap that cannot be corrected retroactively.

A formal dispute process exists through the ASV for confirmed false positives or genuinely mitigating compensating controls; it is not a mechanism for deferring real remediation work, and assessors scrutinize repeated dispute use accordingly. For businesses with dynamic infrastructure, frequent deployments, active cloud footprints, and ongoing development touching the CDE, quarterly scanning is a compliance floor, not a security ceiling; more frequent scanning closes the visibility gap that a fixed 90-day cycle leaves open.

How Do You Choose the Right ASV for PCI DSS v4.0 Compliance?

Any vendor on the PCI SSC's current Approved Scanning Vendor list can produce a valid report, but report clarity, remediation guidance, and rescan turnaround are what actually determine whether a scanning program holds up under assessor and acquirer scrutiny.

PCI SSC approval is the baseline, not the differentiator, every listed ASV has met the same technical bar. What varies is whether scan reports translate into action a compliance team can actually use: clear severity context, remediation guidance tied to business impact, and rescans that don’t turn into a new billable event every time. For SMBs without a dedicated security function, fast onboarding and responsive support during a failed scan matter as much as the scan itself, particularly given how little slack the quarterly window leaves for delay.

Conclusion

PCI DSS v4.0 didn’t rewrite the ASV scanning playbook, the quarterly cadence, the CVSS 4.0+ pass bar, and the ASV-only rule all carry over from v3.2.1. What changed is the margin for error: scope has to be demonstrably accurate, remediation has to be documented, and SAQ A merchants who were exempt before now have a dedicated requirement of their own. Auditing current scan scope, confirming SAQ type with a QSA or acquirer, and building a scanning calendar with real remediation runway are the three moves that close the gap between the old standard’s expectations and where v4.0.1 actually sits today.

Planning Your Compliance Budget?

See current, transparent pricing for PCI ASV scanning before your next quarterly window opens.

Frequently Asked Questions

It's the mandatory external vulnerability scan performed by a PCI SSC-approved vendor against every internet-facing system connected to the cardholder data environment, required quarterly under Requirement 11.3.2.

At minimum once every three months, four scans per year, plus an additional scan after any significant change to the environment.

Yes. It moved from Requirement 11.2.2 in PCI DSS v3.2.1 to Requirement 11.3.2 in v4.0 and v4.0.1.

Many now do. Sub-requirement 11.3.2.1 extends quarterly ASV scanning to SAQ A merchants, a group largely exempt under the prior standard.

No. Requirement 11.3.2 requires scans to be performed by a PCI SSC-listed ASV; internal or self-run scans don't satisfy the requirement.
Any unresolved finding rated CVSS 4.0 or higher results in a failing scan, unless successfully disputed through the ASV's formal process.

Remediate the findings and pass a rescan within the same quarterly window. Carrying an unresolved failure into the next quarter creates a compliance gap.

It meets the minimum requirement, but organizations with frequent infrastructure changes or large cloud footprints often benefit from scanning more often than the quarterly floor.

Authored by

Binoy Koonammavu blog image

Binoy Koonammavu, is the Founder and CEO of Secusy ASV, where he helps SMBs and fintech companies meet PCI DSS scanning requirements without the complexity of enterprise-grade tools. His writing focuses on making ASV compliance straightforward for growing businesses.

Share:

Related Post

 

Discover more from Secusy ASV

Subscribe now to keep reading and get access to the full archive.

Continue reading