Skip to main content
Blog
Blog security

What Is an Approved Scanning Vendor (ASV)? PCI ASV Scans Explained

An Approved Scanning Vendor (ASV) is a company certified by the PCI Security Standards Council to run the external vulnerability scans that PCI DSS requirement 11.3.2 mandates every quarter. This guide explains what an ASV scan covers, how it differs from internal scans and penetration tests, and what it cannot see.

Aug 18, 2026 3 min read
What Is an Approved Scanning Vendor (ASV)? PCI ASV Scans Explained
Table of Contents

An Approved Scanning Vendor (ASV) is a company certified by the PCI Security Standards Council to perform the external vulnerability scans that PCI DSS requires at least quarterly. ASV scans probe your internet-facing systems for known vulnerabilities from the outside, and the passing scan report is part of the compliance evidence merchants submit with their SAQ or Report on Compliance.

What does an ASV scan actually check?

An ASV scan runs from the vendor's infrastructure against your public-facing footprint: web servers, exposed services, TLS configurations, known-vulnerable software versions, and common misconfigurations. The vendor operates under the Council's ASV Program Guide, which standardises scoring — vulnerabilities rated CVSS 4.0 or higher generally fail the scan — and requires the ASV to attest the results.

Under PCI DSS 4.0.1, requirement 11.3.2 mandates these scans at least once every three months and after significant changes. Fail, and you remediate and rescan until you pass.

ASV scan vs internal scan vs penetration test

ASV scanInternal vulnerability scanPenetration test
Who performs itPCI SSC-certified vendorYour team or any qualified toolQualified testers (internal or external)
Vantage pointOutside, internet-facingInside the networkEither, goal-driven
MethodAutomated scanningAutomated scanningManual exploitation
PCI requirement11.3.2, quarterly11.3.1, quarterly11.4, at least annually
OutputAttested pass/fail reportRanked findings for remediationNarrative report of exploited paths

All three are network- and system-level controls. None of them executes your website the way a customer's browser does.

What an ASV scan cannot see

An ASV scan never renders your checkout page. It cannot observe the JavaScript that actually executes in a customer's browser — which is precisely where e-skimming happens. A Magecart script injected through a compromised third party passes every quarterly scan, because from the network edge, nothing about your servers changed.

That blind spot is why PCI DSS 4.0.1 added two browser-layer requirements: 6.4.3, an authorized inventory of every script on payment pages with business justification, and 11.6.1, tamper detection for the headers and script contents the consumer's browser receives. Those requirements need evidence from real sessions, not network probes — which is what cside's PCI Shield produces, in the format QSAs actually accept.

How the pieces fit

Think of the quarterly ASV scan as perimeter hygiene, the penetration test as an adversarial exercise, and 6.4.3/11.6.1 as runtime protection for the payment page itself. A complete PCI DSS 4.0.1 posture needs all three layers, and the cost of each scales differently: ASV scanning is commoditized and cheap; browser-layer evidence is where merchants most often discover a gap during their first 4.0.1 assessment.

Simon Wijckmans
Founder & CEO

Founder and CEO of cside. Previously a product manager on Cloudflare Page Shield (now Cloudflare Client-Side Security). Co-chair of the W3C Anti-Fraud Community Group and a Forbes 30 Under 30 honoree. Building accessible security against client-side attacks, web security is not an enterprise-only problem.

FAQ

Frequently Asked Questions

At least every three months, and after any significant change to the internet-facing environment — per PCI DSS 4.0.1 requirement 11.3.2. A failing scan means remediating and rescanning until you obtain a passing report; the passing quarterly report is part of the evidence package for your SAQ or Report on Compliance.

No. An ASV scan is automated: it probes internet-facing systems for known vulnerabilities from the outside and is required quarterly. A penetration test is a manual, goal-driven exercise where testers actively try to exploit weaknesses, required at least annually under requirement 11.4. Both are required for most merchants; passing one does not substitute for the other.

No — this is the most common gap. ASV scans look at exposed services and server configurations from the network's edge. They do not execute your pages in a browser, so a skimming script injected into your checkout is invisible to them. That risk is covered by PCI DSS requirements 6.4.3 (script inventory and authorization) and 11.6.1 (tamper detection), which need browser-layer evidence.

Monitor and Secure Your Third-Party Scripts

Gain full visibility and control over every script delivered to your users to enhance site security and performance.

Start free, or try Business with a 14-day trial.

cside dashboard interface showing script monitoring and security analytics
Related Articles
Book a demo

Want to walk through this with an engineer?

Thirty minutes, on your own site. Not a slide deck.

We'll show you:

Which third-party scripts are running on your site right now
Where you stand on PCI DSS 6.4.3 and 11.6.1
How much of your traffic is bots and AI agents

Rather just send a question?

Finding open slots…

Real humans only. We'd know.

Having trouble booking? Open scheduler in a new tab

What are you trying to solve?

Tell us in a line and we'll come back with something useful, not a generic pitch.

We usually help with:

Seeing which third-party scripts run on your site
PCI DSS 6.4.3 and 11.6.1 evidence
Bots, AI agents and account takeover

Prefer to just book a time? Pick a slot instead