Attestation of Scan Compliance
PCIComplianceHubLast updated
The document an Approved Scanning Vendor issues to summarise the outcome of an external vulnerability scan, stating whether the scan passed and confirming that the scan customer and the ASV agree the scope was complete. It accompanies the executive summary and the detailed vulnerability report, and together these form the quarterly external scanning evidence submitted with an SAQ or Report on Compliance. A passing scan is required, not merely a completed one.