What Is an ASV Scan? PCI ASV Scanning Explained & Costs

Published on

Updated on

Key Takeaways
  • An ASV scan is an external vulnerability scan of internet-facing systems required under PCI DSS for any organisation that stores, processes, or transmits cardholder data.
  • Only vendors approved by the PCI Security Standards Council (PCI SSC) are authorised to conduct ASV scans; using an unapproved vendor means your results will not satisfy compliance requirements.
  • ASV scans must be performed at least quarterly and after any significant change to your network infrastructure or public-facing systems.
  • The scan produces a formal ASV scan report that documents discovered vulnerabilities, severity levels, and remediation guidance; this report is submitted as evidence of compliance.
  • ASV scanning is not the same as internal vulnerability scanning or penetration testing; it has a specific, defined scope focused entirely on externally reachable systems connected to your cardholder data environment.

An ASV scan is a mandatory external vulnerability assessment of your internet-facing systems, conducted by a vendor approved by the PCI Security Standards Council, to verify that your externally reachable infrastructure does not expose payment card data to known security threats. If your business accepts, processes, stores, or transmits cardholder data and has any systems connected to the internet, quarterly ASV scanning is a non-negotiable component of your PCI DSS compliance programme.

For many business owners and IT managers, the term “ASV scan” surfaces for the first time when a payment processor flags it as a compliance requirement, often accompanied by a tight deadline and little explanation. The result is a scramble to understand what the scan actually involves, who is qualified to perform it, and what happens if the results come back with findings.

The good news is that once you understand the structure of ASV scanning, its purpose, its scope, and its relationship to the broader PCI DSS framework, it becomes one of the more manageable compliance obligations you will face. This guide covers everything you need to know about ASV scans: what they are, what the PCI ASV scan process looks like in practice, how to read and act on your ASV scan report, and how to choose the right scanning partner for your organisation.

Whether you are a small business owner encountering this requirement for the first time or an IT manager preparing to formalise your quarterly scanning programme, the sections below will give you the clarity and confidence to move forward decisively.

Key Definitions

Approved Scanning Vendor (ASV): A company or organisation that has been qualified and approved by the PCI Security Standards Council to perform external vulnerability scanning services in accordance with the ASV Program Guide, and whose scan solutions have passed validation testing to confirm accuracy and reliability.

Cardholder Data Environment (CDE): The people, processes, and technology that store, process, or transmit cardholder data or sensitive authentication data, as well as any systems directly connected or that could impact the security of those systems; this is the primary scope boundary for PCI DSS compliance activities, including ASV scanning.

External Vulnerability Scan: An automated security assessment conducted from outside an organisation's network perimeter, targeting publicly accessible IP addresses and domains to identify known vulnerabilities that could be exploited by an attacker without internal access. This is different from a penetration test, which involves a human tester actively attempting to exploit weaknesses rather than just scanning for them, see how this differs from a penetration test for the full comparison.

PCI DSS (Payment Card Industry Data Security Standard): The globally recognised security standard developed and maintained by the PCI SSC that defines technical and operational requirements for organisations that handle cardholder data, including mandatory ASV scanning under Requirement 11.3.2.

What is an ASV scan?

An ASV scan is an external vulnerability scan of your internet-facing systems, performed by a PCI Security Standards Council-approved vendor, to identify security weaknesses that could expose your cardholder data environment to attack. It is a specific, mandated compliance activity under PCI DSS Requirement 11.3.2, distinct from all other forms of security testing.

To understand the ASV scan meaning fully, it helps to break the term into its components. “ASV” stands for Approved Scanning Vendor; a category of company that has undergone rigorous qualification testing by the PCI SSC to confirm that its scanning tools and methodologies meet the council’s technical standards. Not every vulnerability scanner qualifies.

The vendor’s tools must pass validation testing, and the vendor itself must maintain its approved status by complying with the ASV Program Guide. This matters because when your payment processor, acquirer, or QSA requests evidence of your quarterly scan, they are specifically requesting a report produced by a qualified member of the PCI SSC’s ASV list.

A scan from an unapproved tool, regardless of how sophisticated it may be, will not satisfy the requirement. The scan itself operates from an external vantage point. This is a defining characteristic of ASV scanning and one of the most common sources of confusion for organisations new to the process. The scanner does not sit inside your network; it probes your systems from the outside, exactly as an attacker on the internet would. It sends requests to your public IP addresses and internet-facing hostnames, tests for known vulnerabilities in the services and software those systems expose, and records what it finds.

This external perspective is intentional; the goal is to surface the weaknesses that a real-world threat actor could actually reach and exploit, without the benefit of being inside your firewall.

ASV scan vs internal vulnerability scan: An ASV scan targets what an attacker on the public internet can see; your external attack surface. A separate internal vulnerability scan (Requirement 11.3.1) covers systems inside your network perimeter. Both are required under PCI DSS v4.0.1, but they are distinct processes.

Need a PCI ASV Scan?

Whether you're preparing for your first PCI DSS assessment or switching providers, Secusy ASV makes quarterly scanning simple with fast turnaround times, clear reporting, and expert support when you need it.

Who needs an ASV scan?

Merchants and service providers that handle payment card data typically need quarterly ASV scans under PCI DSS requirements. This includes all Level 1, Level 2, and Level 3 merchants, most Level 4 merchants if required by their acquiring bank, organisations completing SAQ B-IP, SAQ C, SAQ C-VT, or SAQ D, and all PCI DSS service providers in scope. Businesses using fully hosted payment pages that qualify for SAQ A are generally exempt.

Whether you need an ASV scan depends on both your PCI merchant level and how your organisation handles payment card data.

Merchants Required to Run Quarterly ASV Scans

Quarterly ASV scans are mandatory for:

Merchant LevelQuarterly ASV scan required?Notes
Level 1YesOver 6M Visa/Mastercard transactions per year
Level 2Yes1M–6M transactions/year
Level 3Yes20K–1M e-commerce transactions
Level 4Recommended / often required by acquirerSmaller merchants — check with your bank
Service ProvidersYesAll levels of service providers in scope
ASV Scan Requirements by SAQ Type

ASV scans are also required for organisations completing the following Self-Assessment Questionnaires (SAQs):

Must run ASV scans

SAQ B-IP, SAQ C, SAQ C-VT, SAQ D (merchants), SAQ D (service providers), and all Level 1, 2, and 3 merchants undergoing a full Report on Compliance (ROC).

Generally exempt

SAQ A merchants using a fully hosted, PCI-certified payment page (such as Stripe Checkout or Shopify Payments) where cardholder data never touches your systems or network.

SaaS and fintech providers

Service providers handling payment processing on behalf of merchants, including payment gateways, hosted commerce platforms, and fintech infrastructure providers are required to complete quarterly ASV scans as part of their own PCI DSS compliance programme. A passing ASV scan is often a prerequisite for issuing an Attestation of Compliance (AOC) to enterprise clients.

When to run an ASV scan

An ASV scan must be completed every 90 days and whenever significant changes are made to systems that affect the cardholder data environment. This helps maintain continuous PCI DSS compliance and identify new vulnerabilities before they can be exploited.

Quarterly requirement

PCI DSS requires a passing ASV scan result at least once every 90 days. In practice, this means four scans per calendar year, though the 90-day clock runs from the date of your last passing scan, not from fixed quarterly dates. Missing the 90-day window, even by a few days, constitutes a compliance gap.

Post-change rescans

Beyond the quarterly cadence, PCI DSS v4.0.1 requires you to run a new ASV scan after any significant change to your environment that could affect the cardholder data environment. Triggers include:

  • Adding a new server, IP address, or domain within your CDE
  • Changing firewall rules or network segmentation
  • Upgrading or replacing internet-facing infrastructure
  • Migrating to a new hosting provider or cloud environment
  • Deploying a new payment integration or checkout flow

 

The intent is to ensure that infrastructure changes do not introduce new vulnerabilities between scheduled quarterly scans. Your ASV can advise on what constitutes a “significant change” in your specific environment.

What an ASV scan checks

An ASV scan identifies vulnerabilities in external-facing systems, including open ports, unpatched CVEs, weak SSL/TLS settings, insecure configurations, and DNS or email server issues. Under PCI DSS, findings with a CVSS score of 4.0 or higher must be fixed to achieve a passing result.

An ASV scan probes all external-facing IP addresses, hostnames, and domains that you declare within your cardholder data environment scope. The scan engine evaluates each target across several dimensions:

What it checks
Why it matters for PCI
Open ports and running services
Unnecessary open ports expand your attack surface. PCI DSS requires only approved services to be accessible externally.
Known CVEs (Common Vulnerabilities and Exposures)
The scan checks your software versions against the National Vulnerability Database. Unpatched CVEs scored 4.0+ on CVSS will cause a scan failure.
SSL/TLS configuration
Weak cipher suites, expired certificates, and deprecated protocol versions (TLS 1.0, SSL 3.0) are flagged. PCI DSS v4.0.1 mandates TLS 1.2 as the minimum.
HTTP security headers
Missing headers such as HSTS, X-Content-Type-Options, and Content Security Policy are evaluated as indicators of web application security posture.
Misconfigured services
Default credentials, anonymous FTP access, exposed admin panels, and unrestricted directory listings are checked.
DNS and mail server configuration
Open resolvers, zone transfer vulnerabilities, and insecure mail relay configurations are in scope.

The severity of findings is scored using the Common Vulnerability Scoring System (CVSS). Under PCI DSS requirements, any finding with a CVSS base score of 4.0 or higher must be remediated before a scan can pass. Findings below 4.0 are noted in the report but do not cause an automatic failure.

How a quarterly PCI scan works (step by step)

The process involves scoping your external assets, submitting them to an Approved Scanning Vendor, detecting vulnerabilities, fixing and rescanning failed findings, and obtaining a passing ASV report for PCI DSS compliance.

01

Scoping your environment

You identify all external-facing IP addresses and domains that are in scope for PCI DSS. This includes web servers, APIs, cloud instances, load balancers, and anything else that sits on the boundary between your system and the public internet.

02

Submitting to your ASV

You hand your IP list to your approved scanning vendor. They schedule and run the scan, typically automated, against those targets. You don't need to be heavily involved at this stage.

03

Scan and vulnerability detection

The ASV tool runs through your external surface, checking for known CVEs, open risky ports, exposed services, outdated TLS/SSL configurations, and more. Results are logged with severity ratings.

04

Reviewing results, remediate findings and rescan

Any finding rated medium, high, or critical must be addressed before you can pass. Your team fixes the issues (patching, reconfiguring, closing ports) and requests a rescan.

05

Receiving your passing report

Once all high-severity findings are resolved, your ASV issues a passing scan report. That report is submitted to your acquirer, QSA, or compliance portal. Done until next quarter. Please do more scans as a security hygiene measure.

The most common reasons businesses fail their approved scanning vendor scan

The most common reasons for failing an ASV scan include missing in-scope IP addresses, weak or outdated TLS settings, exposed services with unpatched vulnerabilities, inadequate evidence when disputing false positives, and delaying scans until the end of the compliance period.

Failing an ASV scan is extremely common on the first attempt. Here’s what typically goes wrong and the practical fix for each:

Incomplete IP scope

Teams forget staging environments, third-party integrations running on their IP space, or cloud instances spun up without proper tracking. The fix: audit your entire external attack surface before submitting. Use a tool like Shodan or your cloud provider’s asset inventory to sanity-check what’s publicly visible.

Outdated TLS configurations

TLS 1.0 and 1.1 are still flagged by many ASV tools, even on servers where the actual card data never flows. PCI DSS 4.0 is particularly strict here. Disable legacy protocols across all in-scope hosts; not just your primary payment endpoint.

Unpatched services on non-standard ports

Many teams patch their main web servers religiously but forget about SSH on port 2222, admin panels on high ports, or internal monitoring tools accidentally exposed to the internet. Scan your own infrastructure first with an open-source tool like Nmap before the ASV does

Disputing false positives badly

Sometimes ASV tools flag things incorrectly. You have the right to dispute findings, but most teams either ignore the dispute process or submit weak evidence. A solid dispute needs proof the finding doesn’t apply (screenshots, config dumps, vendor documentation) and a clear written explanation. Secusy ASV’s support team can walk you through this directly.

Leaving it too late in the quarter

The scan, remediation, rescan, and report submission cycle can take two to three weeks if issues are found. Starting your quarterly PCI scan in week 12 of the quarter is how you miss deadlines. Build in a buffer ideally starting by week 8.

What the ASV scan report actually tells you

An ASV scan report includes the pass/fail result, scan date, the IP addresses and hostnames scanned, details of identified vulnerabilities and their severity, remediation or dispute status, and the ASV's signed attestation for PCI DSS compliance.

A passing ASV scan report includes the following components, worth understanding if you’re submitting it to an acquirer or QSA:

  • Executive summary — pass/fail status, scan date, number of findings
  • Target list — all IP addresses and hostnames scanned
  • Vulnerability details — each finding with CVE reference, severity, and description
  • Remediation status — confirmed as fixed or disputed
  • ASV attestation — signed confirmation from the vendor that the scan meets PCI DSS requirements. Acquirers and QSAs expect clean, readable reports. If your ASV’s report format is confusing or missing required fields, it creates unnecessary back-and-forth. This is one area where the quality of your vendor matters more than people realise.

Failed an ASV Scan or Unsure What's in Scope?

Most organisations don't pass their first scan because of scoping gaps, outdated configurations, or unresolved findings. Secusy ASV helps you identify issues quickly, guide remediation, and get back to compliance without unnecessary delays.

How much does PCI ASV scanning cost?

PCI ASV scan pricing ranges from $400 to over $5,000 per quarter, depending on your environment's size and the vendor you choose. Be sure to check whether rescans are included, as some providers charge extra for failed scan retests.

Pricing varies significantly across vendors. A few data points to set expectations:

  • Large, enterprise-focused ASVs charge $400–$5,000+ per quarter depending on IP count and contract terms
  • Many older vendors charge separately for rescans, a high hidden cost if your first attempt fails
  • Secusy ASV is positioned at the lower end of the market without cutting corners on scan depth or report quality.

 

For most SaaS businesses and mid-market merchants, there is no reason to pay enterprise rates for a standard quarterly scan. The PCI SSC sets the technical requirements; every approved vendor scans to the same standard. The differentiators are turnaround speed, support quality, and pricing transparency.

PCI DSS 4.0 and what's changed for external scans

PCI DSS 4.0 introduced stricter external scanning requirements, including stronger TLS expectations, enhanced scoping for cloud and third-party environments, clearer documentation for disputed findings, and greater emphasis on authenticated vulnerability assessments where applicable.

PCI DSS 4.0 became the mandatory standard in April 2024, replacing version 3.2.1. For external ASV scanning, the key changes include:

  • Stricter requirements around TLS configuration: version 1.2 is now the minimum, with 1.3 strongly recommended
  • Greater emphasis on authenticated scanning where possible (Requirement 11.3. 2)
  • More rigorous scoping expectations, cloud environments and third-party hosted components must be explicitly addressed
  • Clearer documentation requirements for disputed findings

 

If you’ve been running scans under PCI DSS 3.2.1, it’s worth re-examining your scope and configuration assumptions. Several findings that previously passed are now flagged under 4.0.

Choosing the right approved scanning vendor

Choose an ASV based on turnaround time, rescan policies, support quality, and report clarity. While all ASVs follow the same PCI DSS requirements, the best vendors provide transparent pricing, responsive support, and reports that acquirers and QSAs can easily review.

All ASVs are technically approved by the PCI SSC, but that doesn’t mean they’re equal. Here’s what to evaluate:

01

Turnaround time

Some vendors take 5–7 business days to deliver scan results. Others, including Secusy ASV, turn around results significantly faster. In a compliance crunch, that difference is material.

02

Rescan policy

Ask directly: are rescans included, or do they cost extra? This is a common profit centre for vendors. If you fail your first scan (which is common), you shouldn't be penalised for it.

03

Support access

When you have a false positive or a confusing finding at 4pm on a Friday before a compliance deadline, you want a real person to speak to. Not a ticket queue with a 48-hour SLA.

04

Report quality

Request a sample report before committing. It should be clean, structured, and formatted in a way that your acquirer or QSA will accept without pushing back.

US, UK, and global compliance; does location change anything?

No. PCI DSS is a global standard, so quarterly ASV scanning requirements are the same regardless of where your business operates. However, some regional acquirers may have different submission processes, timelines, or validation workflows.

PCI DSS is a global standard, set by the Payment Card Industry Security Standards Council. Whether you’re processing payments in New York, London, or Singapore, the quarterly external scan requirement is the same. That said, some regional acquirers in the UK and EU have specific submission portals or timelines.

Visa Europe and Mastercard have slightly different compliance validation workflows from their US counterparts, though the underlying scan standard is identical. Secusy ASV works with merchants and service providers across the US, UK, and globally.

Statistics & Citations
  • "PCI DSS Requirement 11.3.2 mandates external vulnerability scanning by an ASV at least once every three months and after any significant change to the network." — PCI Security Standards Council
  • "The PCI SSC maintains a publicly available list of all currently approved ASV companies, and approved status must be verified before engaging any scanning vendor." — PCI Security Standards Council
  • "Vulnerabilities rated 4.0 or above on the Common Vulnerability Scoring System (CVSS) must be remediated before a passing ASV scan report can be issued." — PCI Security Standards Council
  • "SAQ A merchants who have fully outsourced all payment handling may be exempt from ASV scanning requirements, but this exemption must be confirmed with a QSA or acquirer." — PCI Security Standards Council

ASV scanning sits at a specific, well-defined intersection of compliance obligation and genuine security value. It is a mandatory quarterly requirement for most organisations handling payment card data, underpinned by a rigorous PCI SSC approval framework that ensures only qualified vendors can produce compliant results.

But beyond its regulatory function, a well-managed ASV scanning programme gives your organisation a reliable, recurring window into the real-world security posture of your public-facing infrastructure, one that is updated every quarter and calibrated against the latest threat intelligence.

The key to getting real value from your ASV scan, rather than simply tolerating it as a compliance burden, lies in choosing the right partner, understanding what the results mean, and connecting the findings to your broader security and operations practices.

When scoping is accurate, remediation is supported, and rescanning is fast and affordable, ASV compliance becomes a manageable, predictable process rather than a recurring source of stress. The organisations that approach it this way are both more compliant and more secure, and that combination is precisely what the programme was designed to produce.

Summary

An ASV scan is a mandatory external vulnerability scan conducted by a PCI Security Standards Council-approved vendor, required under PCI DSS Requirement 11.3.2 for any organisation whose internet-facing systems connect to a cardholder data environment. Performed at least quarterly, the scan targets publicly accessible IP addresses and domains to identify known vulnerabilities rated CVSS 4.0 or above, producing a formal ASV scan report that serves as evidence of PCI DSS compliance. Selecting a qualified, approved scanning partner and integrating ASV results into ongoing security operations transforms a compliance requirement into a genuine security asset.

Ready to Complete Your PCI ASV Scan?

Avoid hidden fees, long turnaround times, and confusing reports. With Secusy ASV, you get PCI-compliant quarterly scanning, unlimited guidance throughout the process, and the support needed to achieve a passing result with confidence.

Frequently Asked Questions

An ASV scan (Approved Scanning Vendor scan) is an external vulnerability assessment performed by a PCI SSC-approved ASV. It identifies security vulnerabilities in internet-facing systems and helps organizations meet PCI DSS compliance requirements.
Businesses that store, process, or transmit payment card data and have internet-facing systems typically need quarterly ASV scans to comply with PCI DSS. This includes merchants, eCommerce businesses, payment service providers, and many service providers.
An ASV scan examines publicly accessible IP addresses, domains, websites, and servers for known vulnerabilities, security misconfigurations, open ports, and outdated software. After the scan, the ASV provides a report detailing vulnerabilities and the compliance status.
An ASV scan checks internet-facing assets for known security vulnerabilities, open ports, outdated software, SSL/TLS configuration issues, exposed services, and other weaknesses that could put cardholder data at risk.
PCI DSS requires organizations that need ASV scanning to complete a passing external vulnerability scan at least once every 90 days. Additional scans should be performed after significant changes to internet-facing systems.
If an ASV scan fails, the organization must remediate the identified vulnerabilities and perform a rescan. A passing scan report is required to demonstrate PCI DSS compliance.
An ASV scan report includes the scanned assets, identified vulnerabilities, severity ratings, remediation recommendations, and an overall PASS or FAIL status. Passing reports can be submitted to acquiring banks or QSAs as PCI DSS compliance evidence.
ASV scan pricing varies depending on the provider, the number of external IP addresses, and reporting requirements. Small businesses typically pay between $100 and $500 per year, while larger environments may require customized pricing.
An ASV scan is an automated external vulnerability assessment required for PCI DSS compliance, while a penetration test is a manual security assessment performed by security professionals to identify and exploit vulnerabilities.
ASV scanning helps organizations identify and remediate internet-facing vulnerabilities before attackers can exploit them. It is a mandatory PCI DSS requirement for many merchants and service providers and provides evidence of ongoing compliance.

Authored by

Binoy Koonammavu blog image

Binoy Koonammavu, is the Founder and CEO of Secusy ASV, where he helps SMBs and fintech companies meet PCI DSS scanning requirements without the complexity of enterprise-grade tools. His writing focuses on making ASV compliance straightforward for growing businesses.

Share:

Related Post

 

Discover more from Secusy ASV

Subscribe now to keep reading and get access to the full archive.

Continue reading