Approved Scanning Vendor (ASV)

PCIComplianceHubLast updated

A company approved by the PCI SSC to perform the external vulnerability scans PCI DSS requires, using a scanning solution the Council has tested. ASVs are listed on the Council's website, and only a scan by a listed ASV satisfies the quarterly scan requirement.

Applies to. Every entity with an internet-facing system in scope: 11.3.2 requires an ASV scan at least every three months with a passing result.
Example. A merchant's ASV scans its public checkout host each quarter. A finding scored 4.0 or higher on CVSS fails the scan under the ASV Program Guide; the merchant fixes it and the ASV rescans until the report passes.
Limits. The ASV requirement is for the quarterly scan. The scan after a significant change (11.3.2.1) needs qualified personnel with organisational independence, not an ASV, and the standard says so. An ASV scan tests what is reachable from the internet at the time; it is not a penetration test (11.4) and it does not cover internal scans (11.3.1). A passing scan is evidence for one quarter, so a year of compliance needs four.
In PCI DSS v4.0.1. 11.3.2, 11.3.2.1