PCI DSS 11.3.2.1: External vulnerability scans are performed after any significant change
PCI DSS v4.0.1 control 11.3.2.1: the requirement in full, the 3 testing procedures an assessor uses to verify it, and the related controls in section 11.3.
Requirement 11: Test Security of Systems and Networks Regularly › Section 11.3
External vulnerability scans are performed after any significant change as follows:
- Vulnerabilities that are scored 4.0 or higher by the CVSS are resolved.
- Rescans are conducted as needed.
- Scans are performed by qualified personnel and organizational independence of the tester exists (not required to be a QSA or ASV).
Summary
Scan externally after a significant change, and resolve anything CVSS 4.0 or higher.
What the assessor will examine
These are the testing procedures the standard defines for this control. They tell you what evidence to have ready.
| Procedure | |
|---|---|
| 11.3.2.1.a | Examine change control documentation and external scan reports to verify that system components were scanned after any significant changes. |
| 11.3.2.1.b | Interview personnel and examine external scan and rescan reports to verify that external scans were performed after significant changes and that vulnerabilities scored 4.0 or higher by the CVSS were resolved. |
| 11.3.2.1.c | Interview personnel to verify that external scans are performed by a qualified internal resource(s) or qualified external third party and that organizational independence of the tester exists. |
Two differences from its quarterly sibling 11.3.2, and both cut in useful directions. The threshold is fixed at CVSS 4.0 or higher, not "high-risk or critical according to your own ranking", so your risk ranking does not apply here and a medium-scored finding still has to be resolved. That makes this bar stricter than the internal post-change scan in 11.3.1.3, which does defer to your ranking. And an ASV is not required. The quarterly external scan must come from an Approved Scanning Vendor; this one needs only a qualified, organisationally independent tester, which means it can be run in-house and does not need to be bought.
What to prepare
- Change records identifying externally facing significant changes.
- Scan reports for each, with CVSS scores visible.
- Rescan evidence for anything scored 4.0 or higher.
- Who ran them and their independence, which 11.3.2.1.c interviews.
How to implement it
1. Run these yourself. No ASV is required, so the constraint is capability and independence rather than procurement, and waiting for the next quarterly ASV scan does not satisfy a post-change obligation.
2. Score by CVSS, not by your internal ranking. It is the one place in Requirement 11 where the standard fixes the threshold, and an entity applying its own ranking here will under-remediate.
3. Trigger from the same change field as 11.3.1.3. One definition of significant change, two scans, one place to look when the assessor asks.
4. Watch the 4.0 line. It is lower than most internal remediation policies, so this control routinely requires fixing things you would otherwise have scheduled.
Where this commonly fails
- Internal risk ranking applied instead of CVSS, leaving findings between 4.0 and the entity's own high threshold unresolved.
- Waiting for the quarterly ASV scan, which is a different control on a different trigger.
- Assuming an ASV is required and doing nothing because none was booked.
- Only perimeter changes counted, missing a change to an application that is externally reachable.
Related controls
Others in section 11.3:
| Control | What it requires |
|---|---|
| 11.3.1 | Internal vulnerability scans… |
| 11.3.1.1 | All other applicable vulnerabilities… |
| 11.3.1.2 | Internal vulnerability scans are performed via authenticated scanning… |
| 11.3.1.3 | Internal vulnerability scans are performed after any significant change… |
| 11.3.2 | External vulnerability scans… |
← 11.3.2 · All controls · 11.4.1 →
Source
The requirement text and testing procedures above are reproduced from PCI DSS v4.0.1 (June 2024), ©2006-2024 PCI Security Standards Council, LLC. All rights reserved. The commentary is our own.
The official standard is authoritative and also contains the Customized Approach Objective, applicability notes and guidance for this control. Download it from the PCI Security Standards Council document library. PCI DSS is a registered standard of the PCI Security Standards Council, LLC, which does not endorse this site. Nothing here is a substitute for advice from a Qualified Security Assessor.