PCI DSS Requirement 11.3.2

Quarterly PCI ASV scans, managed end to end

An ASV scan is an external vulnerability scan of the internet-facing systems in scope for PCI DSS, run once a quarter by a PCI SSC Approved Scanning Vendor. Requirement 11.3.2 makes four passing scans a year a condition of compliance. We arrange the scans through our ASV partner and manage everything around them.

The requirements

What PCI DSS actually requires

The PCI DSS vulnerability scanning requirements split into two halves. Requirement 11.3.2 covers the outside: every system facing the internet from your cardholder data environment must receive an external vulnerability scan at least once every three months, performed by an Approved Scanning Vendor, and the result must be a pass. Requirement 11.3.1 covers the inside: internal vulnerability scans on the same quarterly cadence, with version 4 raising expectations around authenticated scanning of in-scope systems.

The word that catches people out is passing. Running a PCI scan is not the requirement; passing it is. A scan that surfaces qualifying vulnerabilities fails, and the quarter stays open until fixes are made and a rescan comes back clean. The passing reports then become evidence in your Attestation of Compliance or SAQ, which is why a missed or failed quarter tends to surface at the worst possible moment: assessment time.

PCI DSS quarterly scanning requirements calendar
Requirement What it asks for Cadence
Req 11.3.2 External vulnerability scans of internet-facing systems in scope for PCI DSS, performed by a PCI SSC Approved Scanning Vendor, with a passing result At least once every three months
Req 11.3.1 Internal vulnerability scans across in-scope systems, with v4 tightening what assessors expect around authenticated scanning At least once every three months
Rescans A failed external scan must be corrected and rescanned until a passing result is achieved; the quarter is not satisfied by an attempt, only by a pass As needed, after each failure
Evidence Passing scan reports and attestations retained as evidence to support your Attestation of Compliance or Self-Assessment Questionnaire Every quarter, kept on file

PCI DSS v4.x. Reviewed July 2026.

When the result says fail

Why ASV scans fail, and what a failure means

An ASV vulnerability scan is marked against a fixed rulebook: any finding at or above the qualifying severity threshold fails the scan, and a short list of conditions fails it automatically regardless of score. First scans fail far more often than merchants expect, usually on unglamorous things rather than exotic ones.

The usual failing items

  • Expired, self-signed or misconfigured certificates on payment-adjacent services
  • Out-of-date web, mail or remote-access software with known vulnerabilities
  • Legacy encryption protocols left enabled on internet-facing endpoints
  • Administrative interfaces and databases reachable from the internet
  • Forgotten test systems and stale subdomains sitting inside the scan scope

What a failure sets in motion

A failure starts a clock, not a penalty. The findings behind it must be fixed and the scan rerun until a passing result lands inside the quarter. Where a finding is a genuine false positive, say a patched package the scan fingerprinted by version number alone, you can dispute it with evidence and the ASV can attest the exception rather than fail you for it.

The friction is that every one of those steps, interpretation, remediation, dispute, rescan, sits with the merchant by default. The ASV marks the paper; it does not fix your estate or chase your hosting provider. That gap between the report and a passing quarter is exactly where a managed service earns its keep.

The managed wrap

PCI ASV scanning, run as a service

To be precise about roles: CyPro is not an Approved Scanning Vendor, and this page does not pretend otherwise. The scans themselves are performed by our PCI-SSC Approved Scanning Vendor partner, because PCI DSS requires exactly that. Everything around the scan, which is where quarters are won and lost, is what we deliver.

01

Scope the perimeter

We map every internet-facing IP address, domain and service that stores, processes or transmits cardholder data, or that could affect its security. Under-scoping is the most common way a merchant fails an assessment despite four passing scans.

02

Run the quarterly scan

Each quarter's ASV scan runs through our PCI-SSC Approved Scanning Vendor partner against the agreed scope, on a calendar we manage so a deadline never arrives unscanned.

03

Interpret the report

We read the full report for you, separate genuine failing findings from false positives, and prepare the false-positive evidence the ASV needs before it can attest an exception.

04

Drive the fixes

Failing findings arrive with you as a prioritised fix list in plain language: what failed, why it failed the scan, and the specific change that clears it. We stay on it until each item is closed.

05

Manage the rescan

Once fixes land we schedule the rescan through the ASV partner and repeat the cycle until the quarter shows a passing result, with time still on the clock.

06

Hand over the evidence

You receive an attestation-ready evidence pack each quarter: the passing scan attestation and summary, filed and ready for your acquirer, QSA or SAQ submission.

The quarterly cycle uses the same scan, triage and fix-list discipline as the rest of our managed scanning service. And where PCI DSS asks for more than scanning, Requirement 11.4 penetration testing is delivered by CyPro's CREST-accredited penetration testing team, so scan evidence and test evidence land with one firm behind both.

The question everyone asks

What an ASV scan costs

Our PCI ASV add-on is REPLACE_WITH_PRICE_ASV_ADDON per year. That buys four quarterly ASV scan cycles across your external IP block, run through our Approved Scanning Vendor partner, plus a rescan cycle for any quarter that fails first time, with report interpretation, fix guidance and the quarterly attestation evidence pack included.

Try to compare that figure and you will notice the market rarely offers one: PCI compliance scanning is usually priced inside quote-only retainers or platform bundles you cannot see until you have handed over your details. Ours sits on the pricing page with everything else, alongside the monthly managed scanning it attaches to.

Two different jobs

ASV scanning is not your only external scan

An ASV scan is a compliance artefact: quarterly, marked against the PCI rulebook, scoped to the systems that touch cardholder data, and valuable chiefly because of whose letterhead the pass sits on. Ordinary external vulnerability scanning is a hygiene practice: it covers your whole internet-facing estate, not just the PCI slice, runs monthly or more often, and is judged on what it helps you fix rather than on a pass mark.

The two work best stacked. Clients who run the monthly managed service with us between quarters, on their own scanning tool with our risk analysis on top, walk into each ASV vulnerability scan already knowing what it will find, because the same weaknesses were flagged and fixed weeks earlier. The quarterly PCI scan stops being a cliff edge and becomes a formality with a certificate attached.

PCI ASV scanning questions answered

Asked before every quarter

PCI ASV scan questions, answered

How much does an ASV scan cost?

Our PCI ASV add-on is REPLACE_WITH_PRICE_ASV_ADDON per year. That covers four quarterly ASV scan cycles across your external IP block, run through our PCI-SSC Approved Scanning Vendor partner, plus a rescan cycle for any quarter that needs one, with interpretation, fix guidance and the quarterly evidence pack included.

Almost nobody else in the UK market publishes a figure: ASV scanning is typically bundled into quote-only compliance retainers or hidden behind platform trials. The full ladder is on our pricing page.

See the pricing page

What is an ASV scan report?

It is the document set the Approved Scanning Vendor issues after each scan: an attestation cover sheet recording the overall pass or fail, an executive summary listing each scanned component with its result, and a technical detail section your engineers use to fix what failed.

Your acquirer or QSA normally wants the attestation and executive summary from a passing scan. We assemble exactly that into your quarterly evidence pack, so nothing needs decoding at submission time.

Do all merchants need ASV scans?

Not all. Whether Requirement 11.3.2 applies to you depends on how you take payments and which SAQ type or assessment route you fall under: merchants with internet-facing systems in scope for PCI DSS generally need quarterly ASV scans, while some fully outsourced setups do not.

Your acquirer and your SAQ type are the deciding factors. We confirm which route applies during scoping, before you pay for scans you may not need.

What happens if we fail an ASV scan?

A failed scan is a deadline, not a dead end. The findings that caused the failure must be fixed and the scan rerun until it passes; the quarter only counts once a passing result is on file. Genuine false positives can be disputed with evidence, which the ASV reviews and can attest as exceptions.

This fix-and-rescan loop is precisely the part we manage: interpreting the report, driving the remediation and scheduling rescans so the quarter closes with a pass.

Rocket above the Managed Vulnerability Scanning call to action

A quarterly deadline on the horizon?

Get your next ASV scan cycle handled

One free 45 minute conversation maps your internet-facing PCI scope, sets the dates for the next quarterly scan and puts a firm figure on the annual add-on. Nobody sells at you.