Authenticated Internal Vulnerability Scan
PCIComplianceHubLast updated
An internal vulnerability scan performed with credentials that let the scanner log in to each system component and inspect it from the inside, rather than probing it only across the network. Authenticated scanning finds missing patches, insecure local configurations and vulnerable packages that an unauthenticated scan cannot see. PCI DSS Requirement 11.3.1.2 requires internal scans to be authenticated, with the scanning credentials managed under the same protections as any other privileged account. This was future-dated at publication and became mandatory on 31 March 2025.