Starting April 1, 2025, a large group of e-commerce merchants filing the simplest self-assessment questionnaire inherited a quarterly external scanning obligation many had never faced before. PCI DSS v4.x added external vulnerability scan requirements performed by an ASV to SAQ A to address common attack patterns targeting SAQ A merchant environments. That single change moved thousands of small online sellers, subscription businesses, and software-as-a-service companies with embedded checkout pages into a formal scanning and remediation cycle.
This article explains what a PCI network vulnerability scan involves, who has to run one, what role an Approved Scanning Vendor (ASV) plays, and how remediation timelines work under the current version of the Payment Card Industry Data Security Standard (PCI DSS). Quarterly scanning is not a one-time technical task. It is an ongoing PCI vulnerability management obligation with a specific pass standard, a specific vendor requirement, and a specific rescan step that many organizations skip.
What Is a PCI Network Vulnerability Scan?
A PCI network vulnerability scan is an automated, non-intrusive examination of internet-facing systems connected to the cardholder data environment. PCI DSS Requirement 11.3.2 mandates the scan, which identifies weaknesses an external attacker could exploit. The scan looks at public IP addresses, web servers, firewalls, and any other component reachable from the open internet. It searches for misconfigurations, outdated software, and known vulnerabilities that a remote attacker could use as an entry point.
This differs from the internal scanning covered under a separate sub-requirement and from annual penetration testing. PCI DSS v4.0.1 separates these into distinct requirements: 11.3.2 for ASV scanning and 11.4 for penetration testing. Each answers a different question. A vulnerability scan asks whether known weaknesses exist, while a penetration test asks whether those weaknesses, or others, can actually be exploited to reach cardholder data.
Who Needs Quarterly ASV Scans Under PCI DSS?
Nearly every merchant and service provider that stores, processes, or transmits cardholder data falls under some form of PCI vulnerability scanning requirement. The exact details vary by merchant level and by which Self-Assessment Questionnaire (SAQ) applies. Merchant levels are generally organized by annual transaction volume:
- Level 1: merchants processing over 6 million transactions a year, across all channels
- Level 2: merchants processing between 1 million and 6 million transactions annually, across all channels
- Level 3: merchants processing between 20,000 and 1 million online transactions annually
- Level 4: smaller merchants below those thresholds
Card brands set the exact thresholds, and each brand's program can differ slightly. Confirming the applicable level with an acquiring bank remains the reliable path.
The bigger recent shift involves SAQ A, historically the lightest self-assessment path for merchants that fully outsource payment processing. ASV scan requirements in SAQ A apply only to an e-commerce merchant system that hosts a webpage which either redirects payment transactions to a PCI DSS compliant third-party service provider or includes an embedded payment page from a PCI DSS compliant third-party service provider. Merchants that once assumed "SAQ A means no scanning" now need to check that assumption directly against the current SAQ A form and their acquirer's guidance, since the January 2025 revision retained the scanning requirement.
What Does an Approved Scanning Vendor Do?
An Approved Scanning Vendor is a company certified by the PCI Security Standards Council (PCI SSC) to run the quarterly external scans that Requirement 11.3.2 requires. An ASV maintains a set of security services and tools, often called an "ASV scan solution," to conduct external vulnerability scanning that validates adherence to the external scanning requirements of PCI DSS Requirement 11.3.2. A general-purpose scanning tool, even a capable one, does not satisfy this requirement unless the vendor operating it appears on the official PCI SSC list.
Becoming an ASV involves more than registering with the council. The ASV Program Guide specifies requirements for acceptance into the program, including these areas:
- What an ASV must be able to scan and the vulnerabilities it must detect
- The technical capabilities required of the scanning solution
- How ASVs must conduct scans and interact with merchants
- How disputes must be handled
- The business and ethical standards ASVs must meet
- The content and format requirements of scan reports and attestations
Approval is not permanent. ASV status is a credential that must be earned and renewed each year.
An ASV differs from a Qualified Security Assessor (QSA), another PCI SSC certification that some organizations encounter during full assessments. An ASV runs and certifies the external scan. A QSA evaluates the organization's overall compliance posture and, where a Report on Compliance applies, signs off on that report.
What Counts as a Passing PCI Vulnerability Scan?
A passing scan requires the complete absence of qualifying vulnerabilities across every in-scope system, not simply the absence of critical findings. Under the ASV Program Guide, any vulnerability with a CVSS Base Score of 4.0 or higher results in a non-compliant scan, and all such vulnerabilities must be remediated by the scan customer. A score of 4.0 sits at the low end of the "medium" severity band, which means findings that many teams consider low priority can still block a passing result.
Beyond the numeric threshold, certain issues fail a scan automatically regardless of their CVSS score, including detected backdoors, malware, and unsupported software. One narrow carve-out exists for denial-of-service related findings, which the ASV Program Guide treats differently from exploitable confidentiality or integrity risks.
Frequency matters as much as the score. Requirement 11.3.2 states that organizations must perform external vulnerability scans at least every three months and after any change to internet-facing systems. That significant-change scan, covered under 11.3.2.1, does not have to come from the same ASV, though many organizations use their existing vendor for consistency.
Remediation Timelines and Rescanning
Fixing a flagged vulnerability is only half the process. A passing Attestation of Scan Compliance requires a documented rescan confirming the fix actually worked. PCI DSS v4.0.1 requires a passing scan result, confirmed by rescan, at least once every three months. Remediating a finding without requesting a follow-up scan leaves the original report showing an unresolved vulnerability. That gap does not satisfy the requirement no matter how thoroughly the underlying issue was patched.
PCI DSS does not publish a fixed number of days for closing every vulnerability class, so the practical timeline depends on internal patch management processes and how quickly a rescan can be scheduled. What is consistent across the standard is the expectation that a passing report exists at least once every 90 days, with remediation and rescanning happening inside that window whenever a finding appears. Organizations that treat remediation as a quarterly scramble rather than a continuous process tend to miss that window when multiple findings stack up at once.
Building a Real PCI Vulnerability Management Program
Quarterly scanning works best as one component of an ongoing PCI vulnerability management program rather than an isolated compliance task performed four times a year. A mature program tracks scan results over time, assigns internal ownership for remediation, and schedules patching cycles that anticipate scan dates instead of reacting to them. It also keeps the scan scope current, since the ASV Program Guide places responsibility for defining scope on the organization being scanned, not on the vendor running the scan.
Treating a passing scan as proof of full compliance is a common misstep. A quarterly external scan validates one requirement among many in the broader standard, covering only internet-facing systems and only the vulnerabilities detectable through external testing. Patch management, access control, encryption, and the dozens of other PCI DSS requirements still need separate attention and evidence.
Moving From Scanning to Sustained Compliance
Quarterly ASV scanning is a fixed, well-defined piece of the PCI DSS puzzle, but treating it as a standalone checkbox misses the point of the requirement. The scan exists to catch externally visible weaknesses before an attacker does, and the remediation and rescanning steps exist to prove those weaknesses actually got closed. Organizations that build scanning into a continuous PCI vulnerability management rhythm, rather than a quarterly fire drill, tend to move through assessments with fewer surprises and less scramble at deadline time.
Planet 9 is a Bay Area cybersecurity consulting firm specializing in PCI DSS compliance for SMBs in retail, e-commerce, and payments. Our vCISOs and compliance managers help organizations choose the right approach, configure GRC tools if needed, and get audit-ready without wasted time.





