PCI ASV
PCI DSS requires quarterly external vulnerability scanning by an Approved Scanning Vendor. Getting a passing result depends on knowing what's in scope and fixing what the scan finds.
0
0 +
0 +
What is PCI ASV scanning?
An Approved Scanning Vendor (ASV) is an organization qualified by the PCI Security Standards Council to perform external vulnerability scans against PCI DSS requirements. The Council tests and approves each ASV's scanning solution before listing it, and re-approves annually.
ASV scans assess your internet-facing systems at the network and application level and produce a report identifying vulnerabilities and the remediation each one needs. A passing scan is what your acquirer or assessor accepts as evidence that your external environment meets the PCI DSS vulnerability management requirements.
How often are ASV scans required?
PCI DSS Requirement 11.3.2 requires an external vulnerability scan performed by a PCI SSC Approved Scanning Vendor at least once every three months, with a passing result. Scanning is also required after significant changes to the environment.
The obligation is quarterly rather than annual, which makes ASV scanning one of the few PCI DSS requirements that has to stay live between assessments. Understanding which requirements apply to your environment and which systems fall within scope is where the preparation happens, and it is where we work with you.
What ASV scanning does and does not cover
External systems only: ASV scanning covers internet-facing systems in your cardholder data environment. Internal vulnerability scanning falls under a separate PCI DSS requirement and does not need an ASV.
Scanning, not testing: An ASV scan is an automated external vulnerability scan. It is not a penetration test, and PCI DSS requires both. The two have different requirements, different frequencies and different outputs.
Evidence, not remediation: The scan identifies what needs fixing and produces the report. Closing the findings sits with your team, with support from ours where you want it.
Where ASV scanning fits with the rest of your PCI work
Scope definition
Establishing which internet-facing systems fall within your cardholder data environment and confirming the IP ranges and domains the scan needs to cover. An inaccurate inventory is the most common reason a scan result means less than it appears to.
Interpreting results
Working through what the scan found, what it means for your environment, and which findings carry real risk alongside the compliance obligation.
Remediation
Closing findings and getting you to a passing rescan, with the work prioritized rather than worked through in report order.
The scan itself
Performed by a PCI SSC Approved Scanning Vendor.
Speak to an expert
Most of what determines a passing scan happens before and after the scan runs. Talk to an advisor about your external scope and what your last set of findings looked like.
Dublin: +353 01 293 4027
London: +44 20 3397 3414
Sofia: +359 2 491 0110
Cape Town: +27 08 606 25673
Johannesburg: +27 08 606 25673
