Buy a PCI Scan Online: 7 Things to Check Before You Pay

Buying a PCI scan online takes minutes, but not every plan produces a valid ASV attestation. Check these seven things, from scope counting to rescans, before you pay.

Buy a PCI Scan Online: 7 Things to Check Before You Pay

Buy a PCI Scan Online: 7 Things to Check Before You Pay

You can buy a PCI scan online in minutes, but only a scan delivered through a PCI SSC Approved Scanning Vendor produces a valid Attestation of Scan Compliance. Before paying, confirm which ASV stands behind the product, how scope is counted, whether rescans and false positive disputes are included, and that the plan covers four quarterly scans.

Your acquiring bank or payment provider has sent the email. Your PCI validation is due, and this year it asks for a passing external vulnerability scan from an Approved Scanning Vendor. You search for a way to buy a PCI scan online, and the first page of results offers a free scan, a 45-day trial, a $149 plan, a $185 plan and a "bank-ready" bundle. They all say PCI. They are not all the same product, and some of them will not produce anything your bank will accept.

We run PCI ASV scans every day at Clone Systems, and most of the frustration we see from new customers has nothing to do with vulnerabilities. It comes from what they bought. A merchant buys a single-IP plan and discovers their store domain resolves to four addresses. Someone runs a free scan, uploads the result to their acquirer's portal and has it rejected. A first scan fails on an old TLS setting, and the plan they chose charges for the rescan. None of those problems is hard to avoid. They just are not visible at checkout.

This guide is the checklist we would want every merchant to run before they pay anyone, including us.

Can You Buy a PCI Scan Online, and What Are You Actually Buying?

Yes. External PCI scans are sold as annual online subscriptions by Approved Scanning Vendors and by companies that resell an ASV's service. What you are buying is not a single scan. It is a year of access to a scanning platform that lets you run the external scans PCI DSS Requirement 11.3.2 requires at least once every three months and after significant changes, rescan until you pass, and download the reports your acquirer asks for [1].

The Deliverable Is the Attestation, Not the Scan

The document that matters is the ASV scan report, and in particular its Attestation of Scan Compliance, often shortened to AOSC. It is the page that states, over the ASV's name, that your in-scope external systems passed. A passing result under the ASV program means no in-scope component carries a vulnerability scored 4.0 or higher on CVSS, and no finding falls into the categories the program treats as automatic failures [2]. A scan report without that attestation, or with the attestation from a scanner that is not an ASV, does not satisfy Requirement 11.3.2 however thorough the scan was [1]. We covered the distinction in more depth in why a vulnerability scan doesn't automatically make you PCI compliant.

Who Actually Needs to Buy One

More merchants than expected. Under PCI DSS v4.0.1, merchants completing SAQ A are required to have quarterly ASV scans of the e-commerce system that hosts the page which redirects to, or embeds, a PCI DSS compliant payment provider [3]. That covers a large share of small online stores whose owners reasonably assumed their payment provider handled everything. If that describes you, this explainer on why you are still being asked for an ASV scan walks through who is responsible for which asset.

The Clone Systems 7-Point PCI Scan Buyer's Checklist

These are the seven questions that decide whether an online PCI scan purchase gets you to a passing attestation without surprises. Each one comes from a problem we see new customers hit after checkout rather than before it.

1. Is there a PCI SSC listed ASV behind the product, and whose name will be on the attestation?

Only companies on the PCI Security Standards Council's list of Approved Scanning Vendors can perform the external scans Requirement 11.3.2 calls for, and the list is public [4]. Check it before you buy. Resellers are a legitimate and common way to buy ASV scans, and many reputable scanning products are delivered this way, Clone Systems' own partner program included. The question is simply which ASV's name appears on the Attestation of Scan Compliance. A seller who cannot answer that clearly is the one to avoid.

2. Will the report be accepted for compliance, or is it for internal use only?

Free scans and trials are useful for seeing what a scanner finds. They are frequently not compliance deliverables. At least one major ASV's free 45-day trial states plainly that its reports are watermarked and "not suitable for compliance reporting" [5]. That is a reasonable way to run a trial, and it is also a common reason we see a merchant's first upload to an acquirer portal rejected. If the purpose of the purchase is validation, confirm the plan issues a full, unwatermarked ASV scan report with an attestation.

3. How is scope counted, and does it match what you actually expose?

Online PCI scan plans are priced by the number of external targets, usually IP addresses or domains, and "one asset" does not always mean what the buyer assumes. In our scoping calls, the most common surprise is a store domain that resolves to several IP addresses because it sits behind a load balancer or CDN, followed by a checkout or login page that lives on a different subdomain from the storefront. Both have to be in scope if they are part of the system being validated, and the scan customer, not the ASV, is responsible for declaring that scope accurately [2]. We explain the load balancer case in detail in understanding load balancers in PCI ASV scanning.

4. Are rescans included, and are they unlimited within the quarter?

A first scan that fails is normal. What matters is whether fixing it costs you again. Requirement 11.3.2 expects vulnerabilities to be corrected and rescans performed until a passing result is achieved [1], so a plan that charges per rescan turns a routine TLS fix into an extra invoice. Look for rescans included for every in-scope target, without a cap, for the life of the subscription.

5. How are false positives disputed, and is that included?

Some findings on an ASV report will be wrong for your environment, most often because a vendor back-ported a security fix without changing the software version the scanner sees. The ASV program allows you to dispute those findings with written evidence, and the ASV must review it before the finding can be removed from the report [2]. Ask whether disputes are handled by people, how long they take and whether they cost extra. We wrote a full guide to why scanners flag patched systems and what evidence closes the finding.

6. Does the term cover four quarterly scans, and when does the clock start?

For your annual validation, an assessor or acquirer normally expects to see four passing quarterly scans in the most recent 12 months [1]. There is an exception for initial compliance: you do not need four passing scans in your first year if your most recent scan passed, you have a documented process requiring scans at least once every three months, and failing findings were corrected and rescanned [1]. Either way, the subscription should run for a full year from activation, not from the calendar year, so a purchase in November does not quietly expire in December.

7. Who helps when the scan fails, and how quickly?

This is the question most price comparisons skip. A scan platform that emails you a PDF of findings and a support queue measured in days is cheap until the week your validation is due. Ask whether you can reach an engineer, whether they will explain a finding in plain language, and whether they will help you whitelist the scanner correctly so that a firewall or WAF does not make your hosts look unreachable (why whitelisting your ASV scanner is the key to a valid PCI scan).

Want an ASV scan that answers all seven questions up front? Clone Systems is a PCI SSC Approved Scanning Vendor. Our online PCI ASV scanning plans start at $185 a year for one IP or domain, with quarterly scanning, certified compliance reports and free rescans included, and you can buy online and start scanning the same day.

How Much Does a PCI Scan Cost Online?

Less than most merchants expect, and price is a poor way to choose between plans that differ on the seven points above. In the published price lists we reviewed in September 2026, a single-IP or single-domain ASV scan subscription ranged from roughly $80 to $190 a year. Clone Systems' own online plans are $185 a year for one IP or domain, $625 for up to 10 and $1,575 for up to 25, with larger estates priced on request [6].

The price differences are real, but they are small next to the cost of buying the wrong thing. A plan that charges for rescans, excludes disputes or counts a load-balanced domain as four assets can easily cost more by the end of the year than a plan with a higher sticker price. Our PCI scan cost guide breaks down what drives the price in more detail.

ASV Scan vs Free PCI Scan: Which One Do You Need?

If you need to satisfy Requirement 11.3.2, you need an ASV scan that produces an attestation. A free scan can still be useful, and the two are not really competitors.

Free or trial PCI scanPaid ASV scan subscription
Who runs itVaries: an ASV's trial, a reseller, or a general scannerA PCI SSC listed ASV, directly or through a reseller
Attestation of Scan ComplianceOften not issued, or watermarkedIssued for each passing quarterly scan
Accepted by acquirers for 11.3.2Often noYes
RescansSometimes unlimited during trialShould be included for the full term
False positive disputesRarely offeredHandled by the ASV under program rules
Best used forSeeing what a scanner finds before you buyQuarterly validation and evidence for your SAQ

The practical approach is to use a free or trial scan to find and fix obvious problems, then buy the ASV subscription and run the scan that counts.

How Long Does It Take to Go From Purchase to a Passing ASV Scan?

The purchase takes minutes. The passing scan takes as long as your first round of fixes. In our experience, most of the elapsed time is spent on remediation and scope, not scanning.

A Realistic Timeline

  1. Day 0: Buy and define scope. List every external IP and hostname that is part of the system being validated, including checkout and login subdomains.
  2. Day 0 to 1: Whitelist the scanner. Allow the ASV's scanner addresses through any firewall, WAF or intrusion prevention system in front of in-scope hosts, so the scan sees what an attacker would see.
  3. Day 1: Run the first scan. External scans of a small scope typically complete within hours.
  4. Days 1 to 14: Fix or dispute findings. First scans commonly surface deprecated TLS versions, exposed administrative interfaces or missing patches (common reasons for PCI ASV scan failures). Anything that is genuinely a false positive goes to the ASV as a dispute with evidence.
  5. Rescan and download the attestation. Once no finding at or above CVSS 4.0 remains, the ASV issues the passing report and attestation for upload to your acquirer or payment provider.

Buying at least two to three weeks before your validation deadline leaves room for a failed first scan without turning it into an emergency.

Why External Scanning Is Worth Doing Well

It is tempting to treat this as paperwork. The threat data does not support that. Mandiant's M-Trends 2026 found that exploits were the most common initial infection vector for the sixth consecutive year, at 32% of intrusions where the vector was identified [7]. The internet-facing systems an ASV scan covers are exactly where those exploits land. A scan that is scoped correctly and acted on is one of the cheapest controls a small merchant can run.

Before You Check Out: The Three-Minute Scope Test

Run this before you choose a plan size. It prevents the most common reason merchants have to upgrade mid-year.

  1. Write down every hostname a customer touches before payment. Storefront, checkout, login, account pages and any subdomain that hosts the payment redirect or embedded payment form.
  2. Look up the IP addresses each hostname resolves to. Any DNS lookup tool will do. If one hostname returns several addresses, ask the ASV how they count it.
  3. Add any other internet-facing system in the same environment. Remote access, mail or admin portals that sit alongside the store are commonly in scope too.

The count you end up with is the plan size to buy. If it is noticeably higher than you expected, that is worth a five-minute conversation with the ASV before checkout, not after the first scan.

How Clone Systems Can Help

Clone Systems is a PCI SSC Approved Scanning Vendor and Managed Security Services Provider. Our ASV scanning is built around the checklist above: our name is on the attestation, reports are compliance-ready rather than watermarked, scope is counted in plain terms per IP or domain, rescans are included, and false positive disputes are reviewed by engineers rather than a ticket queue.

You can buy a PCI ASV scan online and begin scanning the same day, from a single IP or domain up to multi-site estates. If you are not sure how many assets you need, or whether you need an ASV scan at all, talk to our team before you buy and we will help you size it correctly. For merchants who want to go further than the quarterly minimum, our PCI scanning guide explains how authenticated internal scanning and penetration testing fit alongside the ASV scan.

Frequently Asked Questions

Can I buy a PCI scan online? Yes, external PCI ASV scans are sold online as annual subscriptions that include quarterly scanning, rescans and compliance reports. Make sure the product is delivered by a PCI SSC listed Approved Scanning Vendor so the report includes a valid Attestation of Scan Compliance.

How much does a PCI ASV scan cost? Published prices for a single IP or domain were roughly $80 to $190 a year in September 2026, with Clone Systems' plans starting at $185. Total cost depends more on how scope is counted and whether rescans and disputes are included than on the headline price.

Is a free PCI scan valid for compliance? Usually not; many free scans and trials produce watermarked or internal-only reports without an Attestation of Scan Compliance. They are useful for finding issues before you buy, but Requirement 11.3.2 needs a passing scan from an Approved Scanning Vendor.

How do I know if a PCI scan provider is an approved ASV? Check the Approved Scanning Vendors list published by the PCI Security Standards Council. If you are buying through a reseller, ask which ASV's name will appear on your Attestation of Scan Compliance.

How long does a PCI ASV scan take? The scan itself usually completes within hours for a small scope. Getting to a passing result typically takes days to two weeks, depending on how many findings need fixing or disputing.

Do I need a PCI scan if my payment provider hosts the checkout? Often yes; SAQ A merchants must have quarterly ASV scans of the website that redirects to or embeds the provider's payment page. Your payment provider scans its own systems, not the site that sends customers to it.

Conclusion

Buying a PCI scan online should take minutes, and with the right plan it does. The mistakes happen when the checklist is skipped: a free report that no acquirer will accept, a scope count that misses half the store, a rescan fee that arrives with the first failed finding. Ask the seven questions, run the three-minute scope test and choose the plan that answers them clearly, whoever sells it.

If you want an Approved Scanning Vendor that answers all seven before you pay, start with Clone Systems' online PCI ASV plans or reach our team at www.clone-systems.com/contact.

References

[1] PCI Security Standards Council: PCI DSS v4.0.1, Requirement 11.3.2 (external vulnerability scans by an ASV at least once every three months and after significant change, rescans until passing, and the initial-compliance applicability note), 2024. https://www.pcisecuritystandards.org/document_library/

[2] PCI Security Standards Council: ASV Program Guide (passing scan criteria, scan customer scope responsibilities, and the dispute process for false positives). https://www.pcisecuritystandards.org/document_library/

[3] PCI Security Standards Council: Resource Guide: Vulnerability Scans and Approved Scanning Vendors, July 10, 2024 (ASV scan requirements for SAQ A e-commerce merchants). https://blog.pcisecuritystandards.org/resource-guide-vulnerability-scans-and-approved-scanning-vendors

[4] PCI Security Standards Council: Approved Scanning Vendors list. https://www.pcisecuritystandards.org/assessors_and_solutions/approved_scanning_vendors/

[5] HackerGuardian: PCI Scan 45-Day Trial (trial reports watermarked and "not suitable for compliance reporting"). https://www.hackerguardian.com/products/pci-trial

[6] Clone Systems: CloneGuard pricing, PCI Compliance Scanning plans, September 2026. https://www.clone-systems.com/pricing?mode=pci

[7] Mandiant (Google Cloud): M-Trends 2026, March 2026 (exploits the most common initial infection vector for the sixth consecutive year, 32%). https://cloud.google.com/blog/topics/threat-intelligence/m-trends-2026

[8] Clone Systems: In our PCI ASV scanning work, the problems new customers hit most often come from what they bought rather than from the vulnerabilities found: a store domain that resolves to several IP addresses behind a load balancer or CDN, a checkout or login page on a separate subdomain left out of scope, and free or trial reports rejected by acquirer portals.

[9] Clone Systems: PCI Scan Cost 2026. www.clone-systems.com/pci-scan-cost-2026/

[10] Clone Systems: Your Payment Provider Handles Checkout. So Why Are You Still Being Asked for an ASV Scan? www.clone-systems.com/payment-provider-checkout-why-you-still-need-an-asv-scan/

[11] Clone Systems: Why Your Vulnerability Scanner Flags Patched Systems (And What Actually Closes the Finding). www.clone-systems.com/blog/why-your-vulnerability-scanner-flags-patched-systems

[12] Clone Systems: Common Reasons for PCI ASV Scan Failures and How to Resolve Them. www.clone-systems.com/common-pci-asv-scan-failures/

[13] Clone Systems: Approved Scanning Vendor (ASV) Services. www.clone-systems.com/approved-scanning-vendor

Ready when you are

Have a scoping question this post didn't answer?

A senior specialist will walk you through it. No junior sales handoffs, no scripted qualifying rounds.