Free Consultation
#PCI DSS

PCI Network Vulnerability Scan Requirements: What Quarterly ASV Scans Cover

September 1, 2026

Starting April 1, 2025, a large group of e-commerce merchants filing the simplest self-assessment questionnaire inherited a quarterly external scanning obligation many had never faced before. PCI DSS v4.x added external vulnerability scan requirements performed by an ASV to SAQ A to address common attack patterns targeting SAQ A merchant environments. That single change moved thousands of small online sellers, subscription businesses, and software-as-a-service companies with embedded checkout pages into a formal scanning and remediation cycle.

This article explains what a PCI network vulnerability scan involves, who has to run one, what role an Approved Scanning Vendor (ASV) plays, and how remediation timelines work under the current version of the Payment Card Industry Data Security Standard (PCI DSS). Quarterly scanning is not a one-time technical task. It is an ongoing PCI vulnerability management obligation with a specific pass standard, a specific vendor requirement, and a specific rescan step that many organizations skip.

What Is a PCI Network Vulnerability Scan?

A PCI network vulnerability scan is an automated, non-intrusive examination of internet-facing systems connected to the cardholder data environment. PCI DSS Requirement 11.3.2 mandates the scan, which identifies weaknesses an external attacker could exploit. The scan looks at public IP addresses, web servers, firewalls, and any other component reachable from the open internet. It searches for misconfigurations, outdated software, and known vulnerabilities that a remote attacker could use as an entry point.

This differs from the internal scanning covered under a separate sub-requirement and from annual penetration testing. PCI DSS v4.0.1 separates these into distinct requirements: 11.3.2 for ASV scanning and 11.4 for penetration testing. Each answers a different question. A vulnerability scan asks whether known weaknesses exist, while a penetration test asks whether those weaknesses, or others, can actually be exploited to reach cardholder data.

Who Needs Quarterly ASV Scans Under PCI DSS?

Nearly every merchant and service provider that stores, processes, or transmits cardholder data falls under some form of PCI vulnerability scanning requirement. The exact details vary by merchant level and by which Self-Assessment Questionnaire (SAQ) applies. Merchant levels are generally organized by annual transaction volume:

Card brands set the exact thresholds, and each brand's program can differ slightly. Confirming the applicable level with an acquiring bank remains the reliable path.

The bigger recent shift involves SAQ A, historically the lightest self-assessment path for merchants that fully outsource payment processing. ASV scan requirements in SAQ A apply only to an e-commerce merchant system that hosts a webpage which either redirects payment transactions to a PCI DSS compliant third-party service provider or includes an embedded payment page from a PCI DSS compliant third-party service provider. Merchants that once assumed "SAQ A means no scanning" now need to check that assumption directly against the current SAQ A form and their acquirer's guidance, since the January 2025 revision retained the scanning requirement.

What Does an Approved Scanning Vendor Do?

An Approved Scanning Vendor is a company certified by the PCI Security Standards Council (PCI SSC) to run the quarterly external scans that Requirement 11.3.2 requires. An ASV maintains a set of security services and tools, often called an "ASV scan solution," to conduct external vulnerability scanning that validates adherence to the external scanning requirements of PCI DSS Requirement 11.3.2. A general-purpose scanning tool, even a capable one, does not satisfy this requirement unless the vendor operating it appears on the official PCI SSC list.

Becoming an ASV involves more than registering with the council. The ASV Program Guide specifies requirements for acceptance into the program, including these areas:

Approval is not permanent. ASV status is a credential that must be earned and renewed each year.

An ASV differs from a Qualified Security Assessor (QSA), another PCI SSC certification that some organizations encounter during full assessments. An ASV runs and certifies the external scan. A QSA evaluates the organization's overall compliance posture and, where a Report on Compliance applies, signs off on that report.

What Counts as a Passing PCI Vulnerability Scan?

A passing scan requires the complete absence of qualifying vulnerabilities across every in-scope system, not simply the absence of critical findings. Under the ASV Program Guide, any vulnerability with a CVSS Base Score of 4.0 or higher results in a non-compliant scan, and all such vulnerabilities must be remediated by the scan customer. A score of 4.0 sits at the low end of the "medium" severity band, which means findings that many teams consider low priority can still block a passing result.

Beyond the numeric threshold, certain issues fail a scan automatically regardless of their CVSS score, including detected backdoors, malware, and unsupported software. One narrow carve-out exists for denial-of-service related findings, which the ASV Program Guide treats differently from exploitable confidentiality or integrity risks.

Frequency matters as much as the score. Requirement 11.3.2 states that organizations must perform external vulnerability scans at least every three months and after any change to internet-facing systems. That significant-change scan, covered under 11.3.2.1, does not have to come from the same ASV, though many organizations use their existing vendor for consistency.

Remediation Timelines and Rescanning

Fixing a flagged vulnerability is only half the process. A passing Attestation of Scan Compliance requires a documented rescan confirming the fix actually worked. PCI DSS v4.0.1 requires a passing scan result, confirmed by rescan, at least once every three months. Remediating a finding without requesting a follow-up scan leaves the original report showing an unresolved vulnerability. That gap does not satisfy the requirement no matter how thoroughly the underlying issue was patched.

PCI DSS does not publish a fixed number of days for closing every vulnerability class, so the practical timeline depends on internal patch management processes and how quickly a rescan can be scheduled. What is consistent across the standard is the expectation that a passing report exists at least once every 90 days, with remediation and rescanning happening inside that window whenever a finding appears. Organizations that treat remediation as a quarterly scramble rather than a continuous process tend to miss that window when multiple findings stack up at once.

Building a Real PCI Vulnerability Management Program

Quarterly scanning works best as one component of an ongoing PCI vulnerability management program rather than an isolated compliance task performed four times a year. A mature program tracks scan results over time, assigns internal ownership for remediation, and schedules patching cycles that anticipate scan dates instead of reacting to them. It also keeps the scan scope current, since the ASV Program Guide places responsibility for defining scope on the organization being scanned, not on the vendor running the scan.

Treating a passing scan as proof of full compliance is a common misstep. A quarterly external scan validates one requirement among many in the broader standard, covering only internet-facing systems and only the vulnerabilities detectable through external testing. Patch management, access control, encryption, and the dozens of other PCI DSS requirements still need separate attention and evidence.

Moving From Scanning to Sustained Compliance

Quarterly ASV scanning is a fixed, well-defined piece of the PCI DSS puzzle, but treating it as a standalone checkbox misses the point of the requirement. The scan exists to catch externally visible weaknesses before an attacker does, and the remediation and rescanning steps exist to prove those weaknesses actually got closed. Organizations that build scanning into a continuous PCI vulnerability management rhythm, rather than a quarterly fire drill, tend to move through assessments with fewer surprises and less scramble at deadline time.

Planet 9 is a Bay Area cybersecurity consulting firm specializing in PCI DSS compliance for SMBs in retail, e-commerce, and payments. Our vCISOs and compliance managers help organizations choose the right approach, configure GRC tools if needed, and get audit-ready without wasted time.

Book a Free Consultation

Schedule a free consultation today to explore how Planet 9 can help you achieve your security and compliance goals.
Book Free Consultation

FAQs

How does a vCISO service differ from hiring a full-time CISO?
A part-time CISO offers the same strategic oversight and expertise as a full-time CISO but on a flexible, cost-effective basis. It’s ideal for small to mid-sized businesses that need executive-level guidance without the overhead.
Is a virtual CISO service suitable for regulated industries like healthcare or finance?
Yes, virtual CISOs (or fractional CISOs) are especially valuable for industries with strict compliance requirements such as HIPAA, PCI DSS, or GLBA. They help ensure your organization meets regulatory standards and is prepared for audits.
What can I expect during a vCISO engagement?
Our vCISO service typically includes cybersecurity assessments, program development, compliance planning, incident response strategy, vendor risk management, and ongoing executive reporting tailored to your business.
How do I know if my business needs a CISO-as-a-Service?
If you lack in-house security leadership, struggle with compliance, or face growing cyber risks, a vCISO can fill that gap, providing strategic direction, improving resilience, and helping you make smarter security investments.

FAQs

What is a PCI network vulnerability scan?
A PCI network vulnerability scan is an automated external scan of internet-facing systems connected to the cardholder data environment, designed to detect weaknesses a remote attacker could exploit. PCI DSS Requirement 11.3.2 requires this scan, and it must be performed by a certified Approved Scanning Vendor rather than an internal team or general-purpose scanning tool.
How often is a PCI vulnerability scan required?
PCI DSS requires the scan at least once every three months, commonly described as quarterly, along with an additional scan after any significant change to internet-facing infrastructure. A passing result must be documented for each required scan cycle.
What is an Approved Scanning Vendor?
An Approved Scanning Vendor is a company certified by the PCI Security Standards Council to run the external scans required under PCI DSS Requirement 11.3.2. The certification requires annual renewal, and only vendors on the official PCI SSC list can issue an attestation that satisfies the requirement.
Does SAQ A require a vulnerability scan?
Under current PCI DSS versions, SAQ A merchants whose checkout page redirects to or embeds a third-party payment form generally fall under the quarterly scanning requirement. This represents a change from earlier standard versions, where most SAQ A merchants were exempt from external scanning.
What happens if a PCI vulnerability scan fails?
A failing scan means at least one in-scope system has a vulnerability that must be remediated, whether due to a CVSS score of 4.0 or higher or an automatic-failure condition such as unsupported software. The organization must fix the issue and complete a rescan showing a passing result before the scan cycle counts as compliant.

Related blog posts