Skip to content

PCI DSS quarterly ASV scans: what they cover and how to pass

By Sam Rivera, Founder, SentinelPanda · April 18, 2026 · 3 min read · PCI DSS

ASV scans are the most visible recurring PCI obligation: four passing attestations a year on every internet-facing system in scope. Knowing how the scan thinks is how you stop them from owning your quarter-end.

Who and what gets scanned

An Approved Scanning Vendor is a company qualified by the PCI Security Standards Council to perform external vulnerability scans for PCI DSS validation. ASVs use scanning tooling configured to PCI-specific rules and produce a standardised report with a Compliant or Non-Compliant attestation.

The scope of an ASV scan is every internet-facing IP address in the CDE plus connected-to systems — the perimeter of your in-scope environment. Internal systems behind the perimeter are scanned separately under Req 11.3.1, but those internal scans are not ASV-validated.

Pass criteria and the CVSS threshold

The pass bar for PCI ASV scans is "no vulnerabilities with a CVSS base score of 4.0 or higher" with certain PCI-specific overrides. CVSS 4.0+ covers medium, high, and critical severity findings; CVSS 0-3.9 (low) findings do not block a passing scan.

Some findings can be accepted as false positives or compensating-controlled with the ASV's agreement — the ASV applies its own analyst review and the attestation reflects the final, reviewed result. A purely-tool output is not the final word; the ASV signs the report.

What scanners look for

  • Outdated software with known CVEs above the CVSS threshold.
  • Weak or expired TLS configurations (deprecated cipher suites, TLS 1.0/1.1 if exposed, weak DH parameters).
  • Default credentials still present on services.
  • Information disclosure (server banners, directory listings, debug pages).
  • Web application vulnerabilities at the perimeter — though deeper application testing is the role of penetration testing, not the ASV scan.
  • Misconfigured cryptographic services.

How to pass on the first attempt

When a scan fails

A failed scan is not a compliance failure for the year — it is a quarterly milestone you have to repair within the same quarter. Remediate the high-severity findings, request a rescan from your ASV, and use the latest passing scan as the quarterly evidence. Most ASVs include a defined number of rescans in the engagement; large environments may need extras.

If a finding cannot be fully remediated in time (a vendor patch is not yet available, for example), you can document a compensating control or an accepted-risk justification and submit it for ASV review. The ASV decides whether the documented mitigation supports a passing attestation.

Cadence and timing

PCI requires four passing ASV scan attestations per year — not just four scans. Plan one scan window per quarter with remediation runway built in. The latest passing scan of each quarter is what counts as the quarterly evidence; failed scans plus passing rescans within the same quarter satisfy the requirement.

Service providers running segmentation testing every six months should align the ASV cadence so reports are ready when SAQ or ROC fieldwork starts. Out-of-band scans (after a major change to perimeter infrastructure) are also recommended even if not strictly required.

Completing a PCI DSS SAQ PCI scoping

Run your compliance program in one workspace.