Binoy Koonammavu
Secusy ASV vs Sectigo HackerGuardian is a comparison that comes up constantly for merchants shopping for a PCI-approved scanning vendor, because both show up in searches for affordable, credentialed PCI DSS scanning. Both are listed on the PCI Security Standards Council’s official ASV register, which means both are technically qualified to run the external vulnerability scans required under PCI DSS Requirement 11.3.2. That shared credential is the easy part of the decision. The harder part is figuring out which one actually fits your business, your IP count, your budget cycle, and how much hand-holding you need to get from signup to a submittable report.
Sectigo is best known as a certificate authority (formerly Comodo); HackerGuardian is the PCI ASV product it sells alongside its SSL/TLS business, with the scan engine delivered through a partnership with Qualys. Secusy ASV is a standalone vendor built specifically for PCI DSS external scanning, with nothing else bundled in: no certificate business, no broader security suite, just the scan, the report, and the Attestation of Scan Compliance.
This comparison walks through pricing at different IP counts, what each vendor actually includes, and where the numbers genuinely favour one over the other, including the ranges where Sectigo comes out ahead, because a comparison that only ever favours one side isn’t useful to the person paying the invoice.
PCI ASV (Approved Scanning Vendor): A company certified by the PCI Security Standards Council to perform the external vulnerability scans required under PCI DSS Requirement 11.3.2.
PCI DSS (Payment Card Industry Data Security Standard): The security framework mandated by the major card brands for any organisation that stores, processes, or transmits cardholder data.
Sectigo HackerGuardian: A PCI ASV scanning product sold by Sectigo, structured as two fixed-capacity tiers (Standard and Enterprise) and sold directly through Sectigo's online store.
Secusy ASV: A PCI SSC-approved scanning vendor built specifically for external PCI DSS scanning, priced per IP with no tier caps or bundled platform.
Attestation of Scan Compliance (AoSC): The document issued after a passing scan, submitted to your acquirer or QSA as proof of PCI DSS Requirement 11.3.2 compliance.
Secusy charges a flat $80 per IP per year with no tiers. Sectigo HackerGuardian pricing is tiered: Standard covers up to 5 IPs, from $241.67 to $286/year, and Enterprise covers up to 20 IPs, from $394.33 to $459/year, so the cheaper vendor depends entirely on how many IPs you're scanning.
Factor | Secusy ASV | Sectigo HackerGuardian |
|---|---|---|
Pricing model | $80/IP/year, linear, no tiers | Two fixed tiers: Standard (≤5 IPs), Enterprise (≤20 IPs) |
Cost for 1 IP | $80/year | $286/year (Standard is the minimum available tier) |
Cost for 5 IPs | $400/year | $241.67–$286/year (Standard, full tier utilised) |
Cost for 20 IPs | $1,600/year | $394.33–$459/year (Enterprise, full tier utilized) |
Buying process | Self-serve, instant published price | Self-serve online store, no sales call required |
Neither model is objectively “cheaper”; they’re built differently. Secusy’s per-IP rate means your bill tracks your actual scope. Sectigo’s tiered rate means your bill is fixed once you’re inside a tier, regardless of whether you’re using 1 IP or all 5. For a full breakdown of how ASV vendors structure pricing, see our PCI ASV pricing models guide.
Run a 2-minute check before you compare vendor pricing.
Secusy is cheaper for merchants scanning 1–4 external IPs, the range that covers most small e-commerce and SaaS businesses, because Sectigo's Standard tier charges the same fixed price for 1 IP as it does for 5.
If you’re looking for a genuinely cheap PCI ASV scanner and your external footprint is small, the per-IP math favours Secusy directly:
At this end of the market, Sectigo’s tier structure works against the buyer: you’re paying for headroom you don’t need. Our full PCI ASV scan cost breakdown covers how IP count drives pricing across the wider vendor market, not just these two.
Sectigo HackerGuardian is cheaper once your scope approaches a full tier: 5 IPs or up to 20, because its pricing is fixed per tier rather than per IP.
The trade-off is capacity waste in the other direction: if you need 6 IPs, Sectigo forces you into the 20-IP Enterprise tier, so you’re paying a fixed rate for 14 IPs you’re not using. That’s still cheaper in absolute dollars than Secusy’s linear rate at 6 IPs, but your cost stops tracking your actual footprint once you cross a tier boundary.
A meaningful PCI ASV scanner comparison has to go beyond checking PCI SSC approval, since every listed vendor already clears that bar; the real differences are in pricing structure, onboarding time, rescan policy, and how a vendor's business model matches the size of business it's selling to.
Sectigo’s core business is SSL/TLS certificates; HackerGuardian is an added product line, sold to a customer base that spans far beyond PCI scanning alone. Secusy’s only product is PCI ASV scanning, which is reflected in how the platform is built: published pricing with no quote step, no minimum IP tier, and onboarding designed so a non-technical buyer can enter their IPs and get scanning the same day. Neither structural difference makes one vendor’s scan results more or less valid; PCI SSC approval means both follow the same ASV Program Guide methodology, but it does affect how much friction you’ll hit getting from signup to a submittable report. For a broader look at how to weigh vendors on this basis, see our guide on how to choose an ASV vendor.
The published HackerGuardian PCI compliance cost covers the Standard or Enterprise subscription, but scaling beyond a tier's IP cap requires an Additional IP Address Pack, and Sectigo does not publish pricing for those packs; you'll need to check at checkout or contact sales for scope beyond 20 IPs.
This is worth flagging because it’s the one part of Sectigo’s pricing that isn’t transparent upfront: the Standard and Enterprise tier prices are clearly published, but the cost of extending beyond either tier’s IP cap isn’t listed on the product pages. Secusy’s linear $80/IP rate has no equivalent gap; the price for any IP count is calculable before you sign up, which matters if you expect your external footprint to grow.
Enter your IP count and get a fixed annual price instantly, no sales call, no quote request.
Sectigo includes unlimited scans per quarter on both tiers. Secusy includes 4 quarterly scans plus up to 6 free rescans per quarter.
In practice, “unlimited” on Sectigo’s side means you can re-run a scan as often as you like within your IP allowance; useful if you’re iterating through remediation in a complex environment. Secusy’s 6-rescan cap covers the large majority of pass/fail/fix cycles for a typical SMB setup, but a business with unusually persistent findings could exhaust it faster than an unlimited plan would allow. See our PCI ASV rescan cost and policy guide for how rescan terms vary across vendors more broadly.
Both vendors sell directly online with no sales call required, but Sectigo offers a 45-day free trial and Secusy publishes an instant fixed price with no trial.
Secusy’s stated report turnaround is 24 hours, with most scans completing in under 4 hours, and setup is self-serve from signup to first scan. Sectigo’s HackerGuardian is also sold directly through its online store without a mandatory sales conversation, with scanning delivered via its Qualys partnership, though it doesn’t publish a specific report turnaround time. Sectigo’s 45-day trial covers up to 2 IPs, but the trial report is watermarked and explicitly not intended for compliance submission, useful for evaluating the interface before you buy, not a substitute for a paid scan when you need to file with your acquiring bank.
Yes. In any PCI approved scanning vendor comparison, Secusy and Sectigo HackerGuardian sit on equal footing for compliance purposes; both are listed on the PCI SSC's ASV register, and both follow the same ASV Program Guide methodology.
A passing report from either vendor is accepted identically by acquirers, card brands, and QSAs; the report format and pass/fail logic come from the PCI SSC program itself, not from the vendor’s brand, size, or price point. Where the vendors genuinely differ, pricing structure, rescan allowance, trial availability, onboarding speed; has no bearing on whether a scan satisfies Requirement 11.3.2. You can confirm current listings for either vendor, or explore the wider field, on our PCI Approved Scanning Vendor list.
Secusy ASV vs Sectigo HackerGuardian isn’t a question with one universal answer, it’s a question of where your IP count falls. If you’re scanning 1–4 external IPs, which covers most small e-commerce and SaaS businesses, Secusy’s linear $80/IP pricing is the more cost-accurate choice, and you’ll never pay for scanning capacity you don’t use. If your scope sits closer to 5 IPs, or anywhere up to 20, Sectigo HackerGuardian’s flat-tier pricing and unlimited quarterly scans work out cheaper in absolute terms. Compliance risk isn’t part of the equation either way: both vendors are PCI SSC-approved, and a passing report from either is accepted the same way by your acquiring bank or QSA. The right vendor is the one whose pricing model matches how many IPs you actually need to scan today, and how much that number is likely to grow.
Sign up, enter your IPs, and get your PCI-ready report within 24 hours.

Binoy Koonammavu, is the Founder and CEO of Secusy ASV, where he helps SMBs and fintech companies meet PCI DSS scanning requirements without the complexity of enterprise-grade tools. His writing focuses on making ASV compliance straightforward for growing businesses.
Subscribe now to keep reading and get access to the full archive.