An ASV scan is a mandatory external vulnerability scan required under PCI DSS Requirement 11.3.2, performed by a PCI-approved vendor to check internet-facing systems for security gaps that could expose cardholder data. This guide walks through what an ASV scan is, which organizations are required to complete one, how the scan process works, and the steps that help you prepare to pass.
What Is an ASV Scan?
Before getting into requirements and preparation, it helps to understand exactly what this scan checks and who is qualified to run it.
An ASV scan is an external vulnerability assessment performed by a company approved by the PCI Security Standards Council, known as an Approved Scanning Vendor. The scan tests internet-facing systems and network components for known vulnerabilities, misconfigurations, and weaknesses that an attacker could exploit from outside the organization. PCI DSS Requirement 11.3.2 mandates this scan at least once every three months for any entity with systems that store, process, or transmit cardholder data.
The scan is described as external because it runs from outside the organization's network, taking the same vantage point as an internet-based attacker. This differs from an internal vulnerability scan, which is run from inside the network to test how systems hold up once a threat has already gained a foothold, such as a compromised endpoint or an internal account with excessive access. Internal scans do not need to be performed by an ASV and their results stay with the organization, while ASV scan results are submitted to the acquirer.
| ASV Scan | Internal Vulnerability Scan | |
|---|---|---|
| Who performs it | A PCI SSC-approved scanning vendor | Internal staff or a qualified internal resource |
| What it tests | Internet-facing systems, public IPs, and domains | Internal network segments and systems |
| Frequency | At least once every three months | At least once every three months, per internal policy |
| Results submitted to the acquirer | Yes, via an Attestation of Scan Compliance | No, retained for internal records |
Once a scan passes, the ASV issues an Attestation of Scan Compliance, a report confirming the environment met PCI requirements for that quarter. Acquirers and auditors rely on this document as evidence that scanning obligations have been fulfilled, and organizations are generally expected to retain a rolling history of these reports for review during an assessment.
Who Needs an ASV Scan?
The requirement casts a wide net, and it now reaches further than many organizations expect.
Any merchant or service provider with internet-facing systems that store, process, or transmit cardholder data, or that connect to the cardholder data environment (CDE), must complete quarterly ASV scans. This covers web servers, payment gateways, VPN endpoints, and any remote access tools exposed to the internet.
PCI DSS v4.0.1 introduced a notable change for SAQ A merchants, effective March 31, 2025. Organizations whose checkout process embeds or redirects to a third-party payment form, previously excluded from ASV scanning, now generally fall under Requirement 11.3.2 and must complete quarterly scans. The shift addresses a rise in attacks that exploit the connection between a merchant's own site and the payment processor it redirects to.
A limited exemption still exists for fully outsourced merchants where cardholder data never touches their own systems, though eligibility depends on the exact payment integration and should be confirmed with the acquirer rather than assumed.
For multi-site operators in retail, restaurant, and convenience fuel environments, the challenge rarely stops at a single network. Each location can introduce its own internet-facing assets, and understanding how SC//AcuVigil™ secures c-store networks illustrates how centralized oversight helps operators manage scanning obligations consistently across hundreds or thousands of sites rather than location by location.
How an ASV Scan Works
Knowing the mechanics of the scan makes it easier to know what to expect and where things tend to go wrong.
ASV scans are automated assessments run from outside the network. They check public IP addresses and domains, open ports, SSL/TLS configurations, and known vulnerabilities cataloged under the Common Vulnerabilities and Exposures (CVE) system, comparing findings against severity ratings to determine a pass or fail result.
The process generally follows five stages:
- Scope Definition: the organization and its ASV agree on which public IPs, domains, and internet-facing systems are included in the scan boundary.
- Scan Execution: the ASV runs the automated external scan against the defined scope, typically completing within a day or two.
- Result Analysis: findings are reviewed to confirm which are genuine vulnerabilities and which may be false positives requiring further evidence.
- Remediation: the organization applies patches, configuration changes, or other fixes to resolve confirmed vulnerabilities.
- Rescan and Attestation: a follow-up scan confirms the fixes worked, and a passing result produces the Attestation of Scan Compliance.
For multi-site operators, defining scope across dozens or thousands of locations can be one of the more challenging parts of this process, since every site may have its own public-facing footprint. Reducing that footprint through network segmentation can shrink the systems that fall inside PCI DSS scope in the first place, which simplifies both the scan itself and the ongoing compliance burden that follows it.
Common Reasons ASV Scans Fail
A failed scan is not the end of the process, but it does start a clock. If an ASV scan fails, the underlying issues must be fixed and a passing rescan completed within the same quarter to stay compliant.
Most failures trace back to a handful of recurring issues:
- Unpatched Vulnerabilities: outdated software versions or missing security patches are the most common cause of a failed scan.
- Version-Banner False Positives: some systems report an older software version in their banner even after patching, triggering a finding that requires documentation to dispute.
- SSL/TLS Misconfigurations: weak ciphers, expired certificates, or outdated protocol versions are flagged quickly by external scanners.
- Unexpected Assets in Scope: forgotten subdomains, legacy servers, or shadow IT systems can surface during scanning and pull unplanned assets into scope.
- Unnecessary Open Ports or Services: services left running without a business need widen the attack surface and are an easy target for scanners.
How to Pass an ASV Scan
Passing on the first attempt comes down to preparation rather than luck. The following steps form a practical checklist organizations can use ahead of scan day.
Six steps consistently improve pass rates:
- Maintaining an accurate asset inventory so nothing is scanned by surprise
- Applying security patches on a regular cadence
- Reviewing SSL/TLS settings before they become a finding
- Closing unnecessary ports and services that serve no active purpose
- Engaging the ASV early enough to leave time for remediation
- and preparing supporting documentation in advance for any assets likely to trigger a false positive.
For multi-site operators, managing scope and remediation across many locations requires centralized network visibility rather than a site-by-site approach. As an informational reference, SC//AcuVigil™ managed network solutions carries its own PCI DSS Attestation of Compliance and include a Self-Assessment Questionnaire (SAQ) Portal that helps brands oversee quarterly compliance activity across franchisees and sites from a single view.
Conclusion
An ASV scan is a quarterly external vulnerability assessment required under PCI DSS Requirement 11.3.2 for any organization with internet-facing systems connected to cardholder data. Since PCI DSS v4.0.1, that requirement now reaches SAQ A merchants using third-party payment forms, closing a gap that had left many e-commerce environments unscanned.
Passing consistently depends less on any single fix and more on ongoing habits, including an accurate asset inventory, scheduled patching, and engaging the ASV with enough lead time to remediate before the quarter closes. Treated as a one-time task, ASV compliance becomes a recurring scramble. Treated as an ongoing rhythm, it becomes a routine part of running a secure, compliant environment.
Need help managing PCI compliance across your sites? Talk to a Scale Computing™ specialist about simplifying quarterly compliance for distributed operations.