What Happens When You Miss a Quarterly PCI ASV Scan

A missed quarterly PCI ASV scan leaves a gap in your attestation file that cannot be cured retroactively. This post covers what the lapse means for your compliance status, and the 5-step plan to close the gap.

What Happens When You Miss a Quarterly PCI ASV Scan

What Happens When You Miss a Quarterly PCI ASV Scan

A missed quarterly PCI ASV scan creates a gap in your Attestation of Scan Compliance file. PCI DSS Requirement 11.3.2 needs a passing external ASV scan at least once every three months, in each of four calendar quarters. The lapsed quarter cannot be cured retroactively. You remediate, rescan until it passes, and document the gap.

In our assessments, this is the standard pattern. A missed quarterly PCI ASV scan is almost never discovered on the day it happens. It surfaces weeks or months later, when an acquirer, a QSA, or an incident reviewer opens the attestation file and finds the missing quarter. The client then has to explain why the gap exists, what the systems were doing during it, and why they believe the environment was still protected. That explanation is far harder to give with a clean attestation beside it than without one.

The timing of this question is not accidental. CISA added four known exploited vulnerabilities to its catalog on September 8, 2026, including flaws in Adobe Commerce and Magento and in two Microsoft Windows components [3]. IBM's 2026 Cost of a Data Breach Report, based on breaches at 602 organizations between March 2025 and February 2026, puts the global average breach cost at $4.99 million, with financial services breaches averaging $6.3 million [2]. A quarter without a passing scan is the window where those numbers stop being theoretical, and it is also the gap an assessor will ask you to explain.

Clone Systems' position, from the assessment side of this: a lapsed scan quarter is not a scheduling slip. It is a compliance gap in the attestation file, and its cost is paid at the worst possible moment, during an audit, a renewal, or an incident review. Below we break down what the lapse actually means, what it costs, the difference between a rescan and a fresh scan, and the five steps we run to close the gap.

What Happens When You Miss a Quarterly PCI ASV Scan?

It means you no longer hold current compliance evidence for the external scanning obligation. PCI DSS Requirement 11.3.2 requires evidence of passing external scans, performed by an ASV, at least once every three months [1]. "Quarterly" does not mean a scan somewhere near the date. PCI SSC guidance expects a scan in each of the four calendar quarters, Q1 through Q4, and a pair of back to back scans on day 90 and day 91 of a quarter does not satisfy the intent of continuous monitoring [4]. A passing scan is valid for one quarter from its scan date [4]. So if the Q2 window passes with no passing scan, your attestation file has a hole in it, and a Q3 scan does not erase that hole.

A failed scan and a missed scan are different problems. A failed scan means you scanned, found findings at or above the CVSS 4.0 threshold, and have not yet remediated them to a pass [4]. A missed scan means there is no valid passing scan for the quarter at all, so there is nothing to remediate into, because nothing was run, or what was run did not produce a passing attestation. The first is a fix problem. The second is an evidence problem, and evidence problems are the ones that surface in a review.

The 3-Question Lapse Check

Run this against your own attestation file in about five minutes:

  1. Do I have a passing attestation for every calendar quarter this year, Q1 through Q4? If the year is over, check all four. If it is not over, check every quarter that has already closed.
  2. Is the most recent attestation within 90 days of today? If not, you are already inside the next gap window, even if you have not missed it on paper yet.
  3. Did the environment change in a way the current attestation does not cover? A new storefront, a migrated checkout, or a redeployed payment page can make an otherwise current scan the wrong evidence [1].

If any answer is no or unclear, you are closer to a lapse than the calendar suggests. That is the point of the check: to find the gap before the reviewer finds it.

Why a Missed Scan Quarter Is a Compliance Gap, Not a Scheduling Slip

Because the obligation is about evidence on a cadence, not about effort. Requirement 11.3.2 was added to SAQ A in PCI DSS v4.x specifically because breaches of external facing web properties had been targeting SAQ A merchant environments at alarming rates [1]. The standard's logic is that the external, internet facing link between your store and the payment provider is exactly the part an attacker can reach without a breach of the perimeter, so it must be proven, on a schedule, by a passing scan from an ASV [1].

That framing changes how a lapse should be treated. A scheduling slip is a late email. A compliance gap is a missing page in a document that a third party will rely on. In our assessments, the first cost of a lapsed quarter is almost never the fine. It is the narrative. Once the gap is visible, the questions stop being "did you scan this quarter" and become "what else did you not do, and how do we know the environment held during the gap." The longer the gap sits, the more the narrative shifts from an oversight to a pattern.

What Does a Lapsed ASV Quarter Actually Cost You?

Three things, and only the first of them is a number on an invoice.

Compliance status. With no passing scan for the quarter, you cannot attest to Requirement 11.3.2 for that period [1]. Whether that blocks you from accepting cards depends on your acquirer and processor. Some will suspend or flag the account, others will impose penalties, and the exposure can carry fines reported in the range of $5,000 to $100,000 per month depending on the processor and the severity of the violation [5]. The practical risk is not one outcome. It is that you do not control which one your acquirer chooses, and you are explaining it without a passing attestation in hand.

Exposure. This is the part that is not on the invoice. The external systems that Requirement 11.3.2 exists to protect are the same systems that CISA flagged when it added four known exploited vulnerabilities to the catalog on September 8, 2026, including Adobe Commerce and Magento and Microsoft Windows components [3]. A quarter with no scan is a quarter where you have no independent measurement of what an external attacker could reach. IBM's 2026 data is the backstop: the global average breach cost is $4.99 million, financial services breaches average $6.3 million, and only 18% of organizations had applied AI agents to vulnerability management, so the exposure a missed scan leaves open is not being watched [2].

Credibility. When the gap is discovered during a review, the cost is the trust the reviewer places in the rest of your file. A single unexplained gap raises the question of whether the other quarters were scanned on time, rescan validated, and documented properly. The recovery below is designed to give you a clean answer to that question.

ASV Rescan vs New ASV Scan: Which Do You Need?

A rescan re tests the same in scope range after you have remediated the findings that caused a failure. A new scan establishes a fresh, current attestation for the quarter you are in now. After a missed quarter, you need the second one, and here is why.

RescanNew (fresh quarterly) scan
What it provesThe same findings are fixedA current, passing attestation for this quarter
When it appliesYou scanned this quarter and failedA quarter passed with no valid passing scan
Can it close a lapsed quarter?No, it has no attestation to closeIt gives you a current quarter, but not the missing one
What you must do about the gapNothing, it was not a gapDocument the lapsed quarter and the recovery

The distinction matters because a rescan cannot be applied to a quarter that never produced a passing attestation. There is nothing to rescan into. You remediate what a current scan finds, run a fresh scan until it passes, and then you file the new attestation with a dated note that names the lapsed quarter and explains what happened and how you closed it. We covered the boundary between what an external scan proves and what it does not in internal vs external vulnerability scanning.

If you are rebuilding a broken attestation file, Clone Systems is a PCI SSC Approved Scanning Vendor. Our PCI ASV external vulnerability scanning runs a full in scope external scan, handles remediation rescans until it passes, and produces the Attestation of Scan Compliance your assessor checks. Talk to our team about your current gap before you file anything.

The Clone Systems 5-Step ASV Lapse Recovery Plan

This is the sequence we run with clients who walk in with a gap in their attestation file. It is also a useful checklist for anyone recovering a lapsed quarter.

Step 1. Date the gap. Establish exactly which calendar quarter has no passing attestation, and the date the window closed. A gap you can date precisely is a gap you can explain. A gap you describe vaguely is a gap a reviewer will probe.

Step 2. Re run a full external scan. Scan the entire current in scope range, not a single IP and not the subset that was scanned last time. If the environment changed during the gap, the scope may be larger than the old attestation assumed [1].

Step 3. Triage against CVSS. Any finding with a CVSS score of 4.0 or higher will fail the scan, so remediate those first and fast [4]. Do not let a clean but incomplete remediation block the pass.

Step 4. Verify the scan setup. Confirm the scanner IPs are whitelisted through your firewall and WAF, and that the scan scope matches the live environment. A scan that hits a 403 or a blocked scanner reads as a failure, and a stale scope gives you the wrong evidence. We covered the patched system that still looks vulnerable, and the evidence that actually closes a finding, in why your vulnerability scanner flags patched systems.

Step 5. Rescan to a pass and document. Run the scan until it passes, then file the new attestation with a short, dated note: the quarter that lapsed, why it lapsed, what you did, and the date of the passing scan. That note is what turns a gap into a closed, explained item.

On cadence, the same logic that makes a missed quarter a problem is the reason a quarterly floor is not a program. You should be scanning more often than the minimum on the systems that change fastest, and a missed window is usually a sign the calendar was set to the standard, not to the environment. We wrote that out in how often should you run vulnerability scans. If you are deciding which ASV to put back in place, the buyer side is covered in buy a PCI scan online and PCI scan cost.

How Clone Systems Can Help

We run the external scanning obligation end to end. As a PCI SSC Approved Scanning Vendor, our PCI ASV external vulnerability scanning covers the full in scope external range, handles remediation and rescans until the result passes, and returns the Attestation of Scan Compliance your assessor will check. When a client arrives with a lapsed quarter, the same five steps above are the engagement: date the gap, re scan the full range, triage against CVSS, verify the setup, and file the recovery with a dated note.

If you are not sure whether you have a gap, the five minute lapse check above takes about the length of a coffee. If the answer is yes and you would rather not explain the gap to your acquirer, start with a conversation about your attestation file. We will tell you which quarter is missing, and what it takes to close it.

Frequently Asked Questions

What happens if I miss a quarterly PCI ASV scan? You have a gap in your Attestation of Scan Compliance file, because PCI DSS Requirement 11.3.2 requires a passing external ASV scan at least once every three months and the lapsed quarter cannot be cured retroactively. You recover by remediating, running a fresh passing scan, and documenting the gap for your assessor.

How often must a PCI ASV scan be completed? At least once every three months, with a passing scan in each of the four calendar quarters, Q1 through Q4 [1]. A pair of back to back scans does not satisfy the requirement, and a passing scan is valid for one quarter from its scan date [4].

Does a lapsed ASV quarter make me non-compliant? For the lapsed period, yes, because you cannot attest to Requirement 11.3.2 for a quarter with no passing scan [1]. Whether your processor suspends the account or imposes penalties depends on your acquirer and the severity [5].

Can I still accept credit cards if I missed a PCI scan? It depends on your acquirer and payment processor. Some continue processing while flagging or fining you, and others may suspend the account until you show current compliance evidence [5].

How do I get back into compliance after a missed ASV scan? Run the Clone Systems 5-Step ASV Lapse Recovery Plan: date the gap, re run a full external scan, remediate findings at CVSS 4.0 or higher, verify the scan setup, and rescan to a pass [4]. Then file the new attestation with a dated note explaining the lapsed quarter and the recovery.

Conclusion

A missed quarterly PCI ASV scan is the kind of problem that looks small on the day it happens and large on the day someone asks. The scan itself is a cheap fix. The gap in the attestation file is the real problem, because it is the one part of compliance you cannot generate after the fact, and it is the one a reviewer will ask you to explain. Date the gap, re scan the full range, triage against CVSS, verify the setup, and document the recovery with a dated note. Close the gap before the reviewer finds it, and start that at www.clone-systems.com.

References

[1] PCI Security Standards Council: Resource Guide: Vulnerability Scans and Approved Scanning Vendors, July 10, 2024 (Requirement 11.3.2 requires passing external ASV scans at least once every three months; the external scanning obligation was added to SAQ A in PCI DSS v4.x because of breaches targeting SAQ A merchant environments). https://blog.pcisecuritystandards.org/resource-guide-vulnerability-scans-and-approved-scanning-vendors

[2] IBM (Ponemon Institute): Cost of a Data Breach Report 2026, July 29, 2026 (global average breach cost $4.99 million; financial services $6.3 million; one in four malicious breaches AI enabled at an average of $6 million; only 18% of organizations apply AI agents to vulnerability management; 602 organizations, March 2025 to February 2026). https://newsroom.ibm.com/2026-07-29-ibm-study-one-in-four-malicious-breaches-are-ai-enabled,-costing-companies-6-million-on-average

[3] CISA: CISA Adds Four Known Exploited Vulnerabilities to Catalog, September 8, 2026 (four KEV additions: Adobe Commerce and Magento, two Microsoft Windows vulnerabilities, and N-able N-central). https://www.cisa.gov/news-events/alerts/2026/09/08/cisa-adds-four-known-exploited-vulnerabilities-catalog

[4] Evervault: ASV Scans: What They Are, When You Need Them, and How They Work, November 7, 2025 (quarterly means four separate calendar quarters per PCI SSC guidance; a passing scan is valid for one quarter; a finding with a CVSS score of 4.0 or higher causes an automatic failure). https://evervault.com/blog/pci-asv-scanning-requirements

[5] PCICompliance.com: PCI Scan Failed? Steps to Fix & Achieve Compliance, January 27, 2026 (non-compliance can carry fines reported at $5,000 to $100,000 per month depending on the processor and severity; vendor reported figure). https://www.pcicompliance.com/pci-scan-failed-what-to-do/

[6] Clone Systems: In our assessments, a missed quarterly PCI ASV scan is almost never discovered on the day it happens. It surfaces weeks or months later, when an acquirer, a QSA, or an incident reviewer opens the attestation file and finds the missing quarter.

[7] Clone Systems: How Often Should You Run Vulnerability Scans? www.clone-systems.com/blog/how-often-should-you-run-vulnerability-scans

[8] Clone Systems: Buy a PCI Scan Online: 7 Things to Check Before You Pay. www.clone-systems.com/blog/buy-pci-scan-online

[9] Clone Systems: PCI Scan Cost 2026. www.clone-systems.com/blog/pci-scan-cost-2026

[10] Clone Systems: Internal vs External Vulnerability Scanning: Why PCI DSS Requires Both. www.clone-systems.com/blog/internal-vs-external-vulnerability-scanning-why-pci-dss-requires-both

[11] Clone Systems: Why Your Vulnerability Scanner Flags Patched Systems (And What Actually Closes the Finding). www.clone-systems.com/blog/why-your-vulnerability-scanner-flags-patched-systems

[12] Clone Systems: PCI ASV External Vulnerability Scanning service page. www.clone-systems.com/pci-asv-scan-external-vulnerability-scanning/

[13] Clone Systems: Contact and consultation. www.clone-systems.com/contact

Ready when you are

Have a scoping question this post didn't answer?

A senior specialist will walk you through it. No junior sales handoffs, no scripted qualifying rounds.