Back to Scanners

ASV Vulnerability Scanning

PCI DSS Requirement 11.3.2 asks for quarterly external vulnerability scans performed by a PCI SSC Approved Scanning Vendor. This page explains what that means and what we are building — scan scheduling is not available yet.

PCI DSS 11.3.2
Coming soon
Quarterly Reports
ASV scanning is launching soon
You cannot schedule an ASV scan here yet. Here is exactly where things stand.
  • We are not an Approved Scanning Vendor. Under Requirement 11.3.2 the quarterly external scan is only valid when it comes from a vendor listed by the PCI Security Standards Council, so this will always be a partnership with an ASV rather than a scan we run ourselves.
  • Available today: the SSL/TLS scanner, which tests transport encryption against Requirement 4.2.1 and returns a pass or fail per control with the evidence behind it.

Vendors we plan to integrate with

These are the scanning vendors we intend to support first. Nothing is connected yet. Always confirm a vendor's current ASV status on the PCI Security Standards Council website before engaging them — listings change.

Rapid7
Comprehensive vulnerability management platform

Key Features

  • InsightVM scanning
  • Real-time dashboards
  • API integration

Integration planned — not yet available.

Qualys
Cloud-based vulnerability assessment

Key Features

  • VMDR platform
  • Continuous monitoring
  • Compliance reporting

Integration planned — not yet available.

Tenable
Enterprise vulnerability management

Key Features

  • Nessus scanning
  • Risk-based prioritization
  • Asset discovery

Integration planned — not yet available.

What we intend to build

The workflow we are aiming for once an ASV partnership is in place. None of it is live today.

Quarterly Vulnerability Scanning
Automated quarterly scans as required by PCI DSS standards

Planned

  • Quarterly scan scheduling
  • Comprehensive port scanning
  • Service enumeration
  • Vulnerability identification
ASV Provider Integration
Connect with approved scanning vendors for compliance

Planned

  • ASV directory access
  • Provider comparison tools
  • Automated scan coordination
  • Compliance verification
Automated Compliance Reporting
Generate and manage PCI compliance scan reports

Planned

  • ASV scan report generation
  • Compliance status tracking
  • Historical scan data
  • Executive summary reports
Risk Prioritization
Intelligent vulnerability prioritization and remediation guidance

Planned

  • CVSS scoring integration
  • Risk-based vulnerability ranking
  • Remediation recommendations
  • Patch management guidance
PCI DSS 11.3.2 Requirements
How ASV scanning ensures PCI compliance for external vulnerabilities

Quarterly Scanning

Perform quarterly external vulnerability scans by approved scanning vendor (ASV).

External Network Scanning

Scan all externally accessible IP addresses and services for vulnerabilities.

Compliance Documentation

Generate required ASV scan reports for PCI compliance validation.

Want this when it ships?

Tell us and we will let you know. In the meantime you can engage an ASV directly, and use our SSL/TLS scanner for Requirement 4.2.1 today.