Skip to main content
Category: PCI DSS Compliance

Approved Scanning Vendor

Also known as: ASV, ASV scan solution provider
Simply put

An Approved Scanning Vendor (ASV) is a company approved by the PCI Security Standards Council (PCI SSC) to perform external vulnerability scans of an organization's internet-facing systems. The vendor's scanning solution must be tested and approved by PCI SSC before the company is added to the official List of Approved Scanning Vendors. These external scans support PCI DSS compliance efforts, though they are only one part of a broader set of security requirements.

Formal definition

An Approved Scanning Vendor (ASV) is an organization qualified by PCI SSC to conduct external vulnerability network scanning services using an ASV scan solution that PCI SSC has tested and approved prior to listing the vendor on its List of Approved Scanning Vendors. ASV scanning addresses the external vulnerability scanning obligations defined within PCI DSS; practitioners should confirm the applicable requirement text and numbering against the current published version of PCI DSS, as these differ between versions. The ASV program qualifies vendor companies and their staff through PCI SSC training and is distinct from the assessment activities performed by QSAs and internal scanning controls. ASV scans are limited to external, internet-facing components and do not by themselves establish overall PCI DSS compliance or cover internal scanning, penetration testing, or other required controls.

Why it matters

External-facing systems are continuously exposed to automated probing and exploitation attempts, and misconfigurations or unpatched vulnerabilities on internet-facing components can create pathways toward systems that store, process, or transmit cardholder data. The Approved Scanning Vendor program gives organizations a way to satisfy the external vulnerability scanning obligations within PCI DSS using a scanning solution that PCI SSC has tested and approved, rather than relying on unvetted tooling. Because the ASV scan solution is validated by PCI SSC before the vendor is added to the official List of Approved Scanning Vendors, the program provides a degree of assurance about the consistency and rigor of the scanning methodology.

It is important to understand the boundaries of what ASV scanning provides. ASV scans are limited to external, internet-facing components and do not by themselves establish overall PCI DSS compliance. They do not cover internal vulnerability scanning, penetration testing, or the many other controls PCI DSS requires. An organization can pass ASV scans and still have significant gaps in its security posture. For this reason, ASV scanning should be treated as one input into a broader compliance and security program, not as a substitute for the full set of PCI DSS requirements or for the assessment activities performed by other qualified parties.

Practitioners should also confirm the applicable external scanning requirement text and numbering against the current published version of PCI DSS, since requirement wording and numbering differ between versions. Relying on a fixed requirement reference from an older version can lead to misalignment between what is actually being validated and what the current standard requires.

Who it's relevant to

Merchants and service providers
Organizations that must meet PCI DSS obligations use an ASV to satisfy the external vulnerability scanning portion of their compliance efforts. They should select a company from PCI SSC's List of Approved Scanning Vendors and treat passing scans as one component of compliance rather than as evidence of full PCI DSS conformance.
Compliance officers and PCI program managers
Those responsible for coordinating PCI DSS validation need to distinguish ASV scanning from internal scanning, penetration testing, and QSA assessment activities. They should confirm the relevant external scanning requirement against the current published PCI DSS version, since numbering and wording differ across versions, and ensure ASV results feed into the broader control set.
Security engineers and vulnerability management teams
Engineers who remediate findings work with ASV scan results to address vulnerabilities on internet-facing systems. They should recognize that ASV scans are limited to external components and that internal scanning and other required controls must be managed separately.
Scanning vendor companies and their staff
Companies seeking to become or remain an ASV must have their scan solution tested and approved by PCI SSC before listing, and their staff and security personnel complete the ASV training program covering the relevant Payment Card Industry material.

Inside ASV

PCI SSC Qualification
An Approved Scanning Vendor is an organization qualified and listed by the PCI Security Standards Council to perform external vulnerability scans. The vendor and its scanning solution undergo a validation process defined by the Council, and only listed ASVs are recognized for satisfying ASV scan requirements.
External Vulnerability Scanning
ASVs conduct scans of internet-facing systems and network perimeters in the cardholder data environment scope. These scans are performed remotely from outside the entity's network and are distinct from internal vulnerability scans, which an entity may perform itself or through qualified internal resources.
ASV Scan Report
The output of an ASV engagement, including identified vulnerabilities, severity ratings, and a determination of whether the scan meets a passing state. The report structure and passing criteria follow the ASV Program Guide published by the PCI SSC; practitioners should confirm current requirement numbering and wording against the published PCI DSS version in effect.
Scope and Attestation
ASV scans cover the externally accessible components of the cardholder data environment as scoped by the entity. The entity remains responsible for defining and confirming scope accuracy, while the ASV validates the scan results against program criteria.
Remediation and Rescan Cycle
When a scan does not reach a passing state, identified issues are remediated and the affected components are rescanned. Passing status may require resolution of vulnerabilities at or above defined severity thresholds set in the ASV Program Guide.

Common questions

Answers to the questions practitioners most commonly ask about ASV.

Does passing an ASV scan mean my organization is PCI DSS compliant?
No. An ASV scan addresses only the external vulnerability scanning obligation within PCI DSS and produces a passing scan report for that specific control. PCI DSS compliance encompasses many other requirements across network security, access control, data protection, monitoring, and policy that an ASV scan does not assess. A passing scan is one input to your overall validation, not evidence of full compliance. Confirm the current requirement scope against the published PCI DSS version, since requirement numbering and wording differ between versions.
Can I use any qualified security firm or my internal team to perform the required external scans?
Not for the external scanning obligation that requires ASV validation. The scans that must be performed by an ASV can only be conducted by a vendor that PCI SSC has approved and listed as an Approved Scanning Vendor. Internal teams and non-ASV security firms may perform other testing, including internal vulnerability scans, but they cannot produce the ASV scan report where one is required. Confirm which scans require an ASV against the current published standard, as this can vary by version.
How often do external ASV scans need to be performed?
PCI DSS specifies a recurring cadence for external ASV scans as well as scanning after significant changes to the in-scope external environment. Because the exact cadence, wording, and requirement numbering differ between PCI DSS versions, confirm the current frequency and triggering conditions against the published standard that applies to your assessment rather than assuming a fixed interval.
What counts as a passing ASV scan, and what happens if vulnerabilities are found?
An ASV scan is evaluated against defined criteria, and vulnerabilities above a certain severity generally cause the scan to fail until they are remediated or, where permitted, resolved through a documented process such as a false positive determination or dispute handled with the ASV. In such cases you typically remediate and rescan to achieve a passing result. Because scoring criteria and dispute handling are defined in the applicable ASV program documentation and PCI DSS version, confirm the specifics against current published materials.
Which systems fall within the scope of an ASV scan?
ASV scanning is directed at the externally accessible, internet-facing components that are in scope for PCI DSS, including public-facing IP addresses and domains associated with the cardholder data environment and its connected systems. Defining scope accurately, including all external entry points, is the responsibility of the scanned organization; understating scope can leave in-scope systems unscanned. Internal-only systems are addressed by other testing requirements, not by the ASV external scan. Validate your scope determination against the current standard and your assessor's guidance.
How do ASV scans relate to penetration testing and internal vulnerability scans?
These are distinct activities that address different requirements. ASV scans are automated external vulnerability scans performed by an approved vendor against internet-facing systems. Internal vulnerability scans and penetration testing are separate obligations under PCI DSS with their own methods, scope, and cadence, and they are not satisfied by an ASV scan. Penetration testing in particular is a more in-depth, often manual exercise that goes beyond automated scanning. Confirm the exact requirements and their numbering against the current published PCI DSS version.

Common misconceptions

An ASV scan alone demonstrates full PCI DSS compliance.
An ASV scan addresses only the external vulnerability scanning obligation. PCI DSS includes many other requirements, and internal scans, penetration testing, and additional controls are governed separately. A passing ASV scan is one input to an overall validation effort, not proof of complete compliance.
ASVs perform internal vulnerability scans and penetration testing.
The ASV role concerns external, internet-facing vulnerability scanning. Internal vulnerability scans and penetration testing are distinct activities with their own requirements and are not covered by the ASV qualification itself, though an ASV organization may offer such services under a different capacity.
Any commercial vulnerability scanning tool satisfies the ASV requirement.
Only scans performed by a vendor listed as an ASV by the PCI SSC, using a validated scanning solution and following the ASV Program Guide, are recognized for the ASV scan requirement. The tool label alone does not confer ASV standing.

Best practices

Confirm the vendor is currently listed as an Approved Scanning Vendor on the PCI SSC website before engaging, and verify the specific scanning solution used is covered by that listing.
Define and document your external scope accurately, including all internet-facing components of the cardholder data environment, since scan completeness depends on correct scoping by the entity.
Treat ASV scanning as one element of a broader PCI DSS program, and separately plan for internal vulnerability scans, penetration testing, and other applicable controls governed under the current published standard.
Establish a remediation and rescan workflow so vulnerabilities at or above the defined severity thresholds are resolved and the affected components are rescanned to reach a passing state.
Review ASV scan reports for accuracy of scope, disputed findings, and severity determinations, and follow the ASV Program Guide dispute process where results appear to be false positives.
Verify current ASV Program Guide criteria and PCI DSS requirement wording against the version in effect rather than relying on a fixed requirement number, as numbering and passing criteria can change between versions.