PCI Approved Scanning Vendor Services

Quarterly ASV scanning.Clear support to achieve a passing result.

PCI DSS external vulnerability scanning for internet-facing systems, delivered through an approved scanning service and supported by Vectra’s experienced PCI team.

Vectra helps merchants and service providers confirm scope, schedule scans, understand findings, coordinate remediation, complete rescans and obtain the official passing reports required for PCI DSS validation.

Supported ASV scanning for PCI DSS v4.0.1 Scope ConfirmationScheduled ScanningFinding ReviewRemediation SupportPassing Reports
A repeatable quarterly process

From scan scope to passing evidence.

ASV compliance depends on accurate scope, reliable scanning, timely remediation and successful rescanning—not simply launching a vulnerability scan.

01

Confirm scope

Identify all internet-facing systems and e-commerce assets that must be included.

02

Prepare

Authorise scanning, confirm ownership and ensure protective controls do not invalidate the assessment.

03

Scan

Run the approved external vulnerability scan against the confirmed target scope.

04

Remediate

Review failures, resolve vulnerabilities and document valid disputes or exceptions.

05

Rescan

Validate remediation and produce the official passing ASV scan report.

Vectra ASV services

Practical support across the entire scan cycle.

Onboarding

ASV portal and service setup

Establish access, contacts, scan targets, authorised users and recurring scan schedules.

Scoping

External asset confirmation

Review IP addresses, domains, payment pages, hosted systems and other externally accessible assets.

Scanning

Scheduled quarterly scans

Run scans at the required frequency and provide visibility over status and scan outcomes.

Analysis

Finding review and explanation

Help technical teams understand reported vulnerabilities, severity and likely remediation actions.

Remediation

Support to resolve failures

Coordinate with system owners, hosting providers and vendors to address issues efficiently.

Rescanning

Validation after remediation

Repeat scans as required to confirm that failures have been resolved and passing criteria are met.

Reporting

Official ASV scan reports

Provide the required scan evidence for QSA, acquirer, merchant bank or internal compliance review.

PCI Advisory

Connect scanning to compliance

Align ASV scanning with the wider PCI DSS scope, validation method and annual compliance programme.

Explore PCI consulting →
Broader Security

Beyond compliance scanning

Extend visibility through ongoing vulnerability management across internal, cloud and external assets.

Explore vulnerability management →
PCI DSS v4.0.1

What Requirement 11.3.2 expects.

PCI DSS requires evidence of passing external vulnerability scans performed by a PCI SSC Approved Scanning Vendor. Scans must cover the required external attack surface, failed findings must be resolved and rescans must confirm the passing result.

01
At least once every three monthsExternal ASV scanning is normally required quarterly, with the timing managed throughout the reporting period.
02
After significant changeAn additional external scan may be required when significant changes affect in-scope systems or the external attack surface.
03
Performed through an approved ASV serviceGeneral vulnerability scans do not replace the formal ASV scanning and reporting process required by PCI DSS.
04
Passing result and official evidenceVulnerabilities must be resolved and rescans completed until the ASV Program Guide passing requirements are met.
Who may need ASV scanning

Merchants, service providers and e-commerce environments.

The exact requirement depends on the organisation’s PCI DSS validation pathway, payment architecture and externally accessible systems.

Merchants

Internet-facing payment environments

Organisations with public systems that form part of, connect to or can affect the security of the cardholder-data environment.

  • Public IP addresses
  • Externally accessible services
  • Payment-related web infrastructure
  • Remote access and perimeter services
Service Providers

Platforms supporting customer payments

Providers whose services store, process, transmit or can affect the security of customer account data.

  • Hosting and cloud services
  • Payment applications
  • Managed infrastructure
  • Shared-service platforms
SAQ A E-commerce

Websites redirecting or embedding payments

Under PCI DSS v4.x, certain SAQ A e-commerce merchants also need ASV scanning of the systems hosting the merchant webpage.

  • Redirect payment journeys
  • Embedded payment forms
  • Merchant-hosted web pages
  • Public web infrastructure
ASV scanning versus vulnerability management

Compliance evidence and security operations serve different purposes.

ASV Vulnerability Scanning

Formal PCI DSS external scanning.

Designed to validate the external scanning requirements of PCI DSS using an approved scan solution and prescribed reporting process.

  • External internet-facing scope
  • Quarterly compliance cycle
  • ASV Program Guide methodology
  • Official passing reports
  • Evidence for PCI validation
Ongoing Vulnerability Management

Continuous operational risk reduction.

Designed to discover and prioritise weaknesses across internal, cloud, endpoint, network and external assets throughout the year.

  • Broader asset coverage
  • Authenticated and agent-based assessment
  • Risk-based prioritisation
  • Remediation workflow
  • Continuous reporting and improvement
A passing ASV scan does not prove full PCI DSS compliance.

ASV scanning validates one specific external vulnerability-scanning requirement. PCI DSS compliance also depends on the organisation’s wider technical, operational and governance controls and the appropriate annual validation process.

Why Vectra

ASV scanning backed by experienced PCI specialists.

Vectra combines ASV scanning support with one of Australia’s most experienced PCI consulting teams. This helps customers move from a failed scan to a practical remediation plan and defensible compliance evidence.

ExperiencedMore than 20 years in payment security

Long-standing experience supporting PCI DSS programmes across Australian organisations.

SupportedHelp beyond the scan result

Guidance on scope, findings, remediation, rescanning and evidence requirements.

IntegratedConnected to broader PCI services

QSA assessment, SAQ assistance, penetration testing and compliance advisory when required.

PracticalClear advice for technical teams

Translate scanner output into actionable remediation rather than leaving customers with a report alone.

RepeatableQuarterly programme management

Maintain scheduling, target scope, report access and evidence across the year.

ScalableSingle sites to complex enterprises

Support simple merchant environments and larger estates with multiple public services.

Complete the quarterly scan with confidence

Get the scan, support and evidence required for PCI DSS.

Talk to Vectra about ASV onboarding, scan scope, quarterly scanning, failed findings, rescanning or integration with your wider PCI compliance programme.

Arrange your next ASV scan

Tell us about your payment environment, external assets and current PCI validation pathway.

Contact the PCI Team →

Send an ASV Vulnerability Scanning Enquiry

Complete the form below and our ASV Team will be in touch to discuss your scanning requirements.

ASV Scanning Contact Form

Pre-Contact Questions (Optional)

To help us better understand your enquiry we have put together an optional set of questions for you to answer. You may answer as many of the questions as possible based on your current knowledge.

Merchant Information

Your bank should be able to tell you, however if you are unsure or unable to check, choose the corresponding number of transactions.
What payment channels do you use?

Service Provider Information