What Is a PCI Approved Scanning Vendor (ASV)?

An ASV is a company approved by the PCI Security Standards Council to run the external vulnerability scans PCI DSS requires every three months. Clone Systems has held ASV status since 2007.

What Is a PCI Approved Scanning Vendor (ASV)?

An Approved Scanning Vendor, or ASV, is a company qualified by the PCI Security Standards Council to run the external vulnerability scans that PCI DSS requires. Before a scanning solution can appear on the Council's list of Approved Scanning Vendors, it has to pass the Council's own testing, and the vendor has to requalify every year. Clone Systems has held ASV status continuously since 2007.

What an ASV actually does

An ASV scans your internet-facing systems from the outside, the same vantage point an attacker has. The scan looks for known vulnerabilities, weak configurations, exposed services and out-of-date software on every external IP address and domain in scope for your cardholder data environment. The ASV then reviews the findings, resolves false positives, and issues a report plus an Attestation of Scan Compliance that you can hand to your acquiring bank or QSA as evidence. Learn more about what a vulnerability scan checks and how it works.

What PCI DSS requires

PCI DSS Requirement 11.3.2 calls for external vulnerability scans performed by a PCI SSC Approved Scanning Vendor at least once every three months, with evidence of a passing result. Requirement 11.3.2.1 additionally calls for external scans after any significant change to your environment, such as a new server, a new external IP address, or a material change to network architecture.

Scans run by your own team or by a vendor that is not an ASV do not satisfy Requirement 11.3.2, no matter how thorough they are. The approval is part of the requirement.

What counts as a passing scan

A passing external scan means two things. First, no vulnerability carries a CVSS base score of 4.0 or higher. Second, none of the automatic failure conditions are present, which include things like default or guessable accounts, unsupported software, and certain insecure services being reachable from the internet.

If your scan fails, the path forward is to remediate the findings and rescan. You are not judged on a single perfect scan per quarter. What matters is showing a set of scan results that together demonstrate all in-scope systems were scanned and all applicable vulnerabilities were identified and addressed at least once every three months. This is why unlimited rescans matter more than most buyers realise when they are comparing vendors on price alone.

Scanning and penetration testing are not the same thing

A vulnerability scan is automated and runs on a schedule. A penetration test is a manual, human-led effort to actually exploit what is found and to chain weaknesses together. PCI DSS asks for both, and they answer different questions. At Clone Systems, penetration testing is complementary with our vulnerability scanning services, because for some merchants it is a requirement rather than an optional extra.

How to choose an ASV

Accuracy and false positive handling

A scanner that floods you with false positives costs your team real hours every quarter. Ask how false positives are reviewed and disputed, and whether that review is included or billed.

Rescans

Find out whether rescans are unlimited or metered. A failed scan is normal. Paying per rescan turns a routine remediation cycle into an unpredictable bill.

Track record

Ask how long the vendor has held ASV status. The Council requalifies ASVs annually, so a long unbroken record says something that a recent approval cannot.

Support during remediation

The scan report tells you what is wrong. Ask whether the vendor will help you understand and fix it, or whether you are on your own after the PDF arrives.

What happens at renewal

Ask what the second year costs and whether the price is locked.

Why merchants choose Clone Systems

Clone Systems has been in business since 1998 and a PCI SSC Approved Scanning Vendor since 2007. Our packages include scanning at the required cadence, unlimited rescans, and the Attestation of Scan Compliance your acquirer will ask for. Scans run from our own approved infrastructure, and our team reviews results rather than handing you raw scanner output. View PCI ASV scanning packages and pricing.

Frequently asked questions

How often do I need an ASV scan?

At least once every three months, and again after any significant change to your external environment.

Can I use my own scanning tool instead?

Not for PCI DSS Requirement 11.3.2. The scan has to be performed by an Approved Scanning Vendor using a solution the PCI Security Standards Council has tested and approved.

What happens if my scan fails?

You remediate the findings and rescan. Our packages include unlimited rescans, so a failed scan does not cost you anything extra.

What is the difference between an ASV scan and an internal vulnerability scan?

An ASV scan looks at your environment from the public internet and must be run by an approved vendor. Internal scans look at systems inside your network and are covered by a separate requirement. Most merchants need both.

Do I get documentation I can give to my bank?

Yes. Every passing scan produces an Attestation of Scan Compliance along with the full scan report.

How long does a scan take?

Most scans complete within a few hours, depending on how many IP addresses and domains are in scope.

Ready when you are

Have a scoping question this post didn't answer?

A senior specialist will walk you through it. No junior sales handoffs, no scripted qualifying rounds.