Confirm scope
Identify all internet-facing systems and e-commerce assets that must be included.
PCI DSS external vulnerability scanning for internet-facing systems, delivered through an approved scanning service and supported by Vectra’s experienced PCI team.
Vectra helps merchants and service providers confirm scope, schedule scans, understand findings, coordinate remediation, complete rescans and obtain the official passing reports required for PCI DSS validation.
ASV compliance depends on accurate scope, reliable scanning, timely remediation and successful rescanning—not simply launching a vulnerability scan.
Identify all internet-facing systems and e-commerce assets that must be included.
Authorise scanning, confirm ownership and ensure protective controls do not invalidate the assessment.
Run the approved external vulnerability scan against the confirmed target scope.
Review failures, resolve vulnerabilities and document valid disputes or exceptions.
Validate remediation and produce the official passing ASV scan report.
Establish access, contacts, scan targets, authorised users and recurring scan schedules.
Review IP addresses, domains, payment pages, hosted systems and other externally accessible assets.
Run scans at the required frequency and provide visibility over status and scan outcomes.
Help technical teams understand reported vulnerabilities, severity and likely remediation actions.
Coordinate with system owners, hosting providers and vendors to address issues efficiently.
Repeat scans as required to confirm that failures have been resolved and passing criteria are met.
Provide the required scan evidence for QSA, acquirer, merchant bank or internal compliance review.
Align ASV scanning with the wider PCI DSS scope, validation method and annual compliance programme.
Explore PCI consulting →Extend visibility through ongoing vulnerability management across internal, cloud and external assets.
Explore vulnerability management →PCI DSS requires evidence of passing external vulnerability scans performed by a PCI SSC Approved Scanning Vendor. Scans must cover the required external attack surface, failed findings must be resolved and rescans must confirm the passing result.
The exact requirement depends on the organisation’s PCI DSS validation pathway, payment architecture and externally accessible systems.
Organisations with public systems that form part of, connect to or can affect the security of the cardholder-data environment.
Providers whose services store, process, transmit or can affect the security of customer account data.
Under PCI DSS v4.x, certain SAQ A e-commerce merchants also need ASV scanning of the systems hosting the merchant webpage.
Designed to validate the external scanning requirements of PCI DSS using an approved scan solution and prescribed reporting process.
Designed to discover and prioritise weaknesses across internal, cloud, endpoint, network and external assets throughout the year.
ASV scanning validates one specific external vulnerability-scanning requirement. PCI DSS compliance also depends on the organisation’s wider technical, operational and governance controls and the appropriate annual validation process.
Vectra combines ASV scanning support with one of Australia’s most experienced PCI consulting teams. This helps customers move from a failed scan to a practical remediation plan and defensible compliance evidence.
Long-standing experience supporting PCI DSS programmes across Australian organisations.
Guidance on scope, findings, remediation, rescanning and evidence requirements.
QSA assessment, SAQ assistance, penetration testing and compliance advisory when required.
Translate scanner output into actionable remediation rather than leaving customers with a report alone.
Maintain scheduling, target scope, report access and evidence across the year.
Support simple merchant environments and larger estates with multiple public services.
Talk to Vectra about ASV onboarding, scan scope, quarterly scanning, failed findings, rescanning or integration with your wider PCI compliance programme.
Tell us about your payment environment, external assets and current PCI validation pathway.
Contact the PCI Team →Complete the form below and our ASV Team will be in touch to discuss your scanning requirements.
| Cookie | Duration | Description |
|---|---|---|
| cookielawinfo-checkbox-analytics | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics". |
| cookielawinfo-checkbox-functional | 11 months | The cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional". |
| cookielawinfo-checkbox-necessary | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary". |
| cookielawinfo-checkbox-others | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other. |
| cookielawinfo-checkbox-performance | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance". |
| viewed_cookie_policy | 11 months | The cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data. |