Failed your PCI scan? Here's what to do right now.

If your payment processor, bank, or scanning vendor just told you that you failed a PCI scan, take a breath. A failed scan is not a fine, not a breach, and not the end of your ability to take cards. It is a list of things to fix, and most merchants pass on the next scan once they know what the list means. This page walks you through it in plain language.

Failed your PCI scan? Here's what to do right now.

First, understand what "failed" means

A PCI ASV scan is an outside check of your internet-facing systems (your website, your server, your firewall) by a PCI Approved Scanning Vendor. It fails if the scanner finds any issue rated medium severity or higher (a CVSS score of 4.0 or above), or any issue the PCI Council calls an automatic failure, such as an exposed database or a known-vulnerable version of software. One finding is enough to fail the whole scan. That is why a site that has been fine for years can suddenly fail after a certificate expires or a hosting provider changes a setting.

Second, decide which of the three situations you're in

  1. It's a real problem. Something on your side needs fixing: an old TLS version, an expired certificate, an open port, unpatched software. This is the most common case. Our guides on the common reasons scans fail and what to fix before your next scan cover each one. Fix it, then rescan.
  2. It's a false positive. The scanner flagged something that isn't actually a risk in your setup. This happens more than people expect (see the list below). You don't fix it, you dispute it with evidence.
  3. It's out of scope. The scan hit something that isn't yours or isn't part of your card environment: a shared IP at your host, a neighbor's system, a decommissioned server still in DNS. You correct the scope and rescan.

The famous false positives

These trip up merchants every quarter. Each one is real, well known, and disputable.

  • The TCP source port firewall issue. Some firewalls let traffic through if it comes from certain source ports (often 20, 53, or 88). Scanners flag it as a firewall bypass. If your firewall actually filters by destination and state, this is disputable with your firewall configuration as evidence.
  • CDN and proxy findings. If your site sits behind a CDN or a web application firewall, the scanner is looking at the CDN's servers, not yours. Findings about the CDN's TLS settings or headers are usually the CDN's responsibility and are disputable with the CDN's own documentation.
  • Load balancers and multiple IPs. A load balancer can answer differently on each scan, and a scan of one IP can surface a backend server that isn't in scope. Our guide on load balancers and PCI ASV scanning explains how to scope these correctly.
  • The scanner was blocked. If your firewall or hosting provider blocked the scanner's addresses, the scan is incomplete and can be reported as a failure. Whitelist the ASV scanner range first (ours is 38.123.140.0/25), then rescan. Our whitelisting guide has the steps.
  • A patched version that still reports the old number. Some Linux distributions backport security fixes without changing the version number the scanner sees. Disputable with the package changelog showing the fix.

How to dispute a finding

Under the PCI ASV program, you can dispute any finding you believe is a false positive, is compensated for by another control, or is out of scope. You submit evidence, the ASV reviews it, and if it holds up, the finding is marked as an exception and no longer fails the scan. With Clone Systems, you submit disputes and exception requests inside the portal under Options. Our security team reviews them, usually within 24 hours, and you rescan as soon as the exception is approved. Rescans are free and unlimited until you pass.

Your deadline

PCI requires a passing scan every three months, and your processor usually expects one by the end of each calendar quarter: March 31, June 30, September 30, and December 31. Some processors charge a monthly non-compliance fee once you miss the date. The fee stops once you submit a passing scan, so the goal is speed, not perfection: fix or dispute the findings, rescan, and pass. Our guide on PCI scan deadlines covers the dates and what processors typically require.

If you don't have a scanning vendor, or want a second opinion

You can buy a PCI ASV scan from Clone Systems online and run it today. Starter is $185 a year for one IP or domain, and every package includes unlimited rescans until you pass, so a failed first scan costs nothing extra. You get the same attestation report your processor asks for. If your findings are hard to read, the optional AI Remediation Assistant explains each one in plain language and tells you what to change; it runs privately in our own data center, so your scan data never goes to an outside AI service.

Buy a PCI scan and run it today · Talk to a specialist

Guides for the specific fixes

Clone Systems has been a PCI Security Standards Council Approved Scanning Vendor since 2007. This page is general guidance, not a substitute for your processor's specific requirements.

Ready when you are

Need to pass your next PCI scan?

Our automated PCI ASV scan is bought and run online today. Every package includes unlimited rescans until you pass, so a failed first scan costs nothing extra.