First, understand what "failed" means
A PCI ASV scan is an outside check of your internet-facing systems (your website, your server, your firewall) by a PCI Approved Scanning Vendor. It fails if the scanner finds any issue rated medium severity or higher (a CVSS score of 4.0 or above), or any issue the PCI Council calls an automatic failure, such as an exposed database or a known-vulnerable version of software. One finding is enough to fail the whole scan. That is why a site that has been fine for years can suddenly fail after a certificate expires or a hosting provider changes a setting.
Second, decide which of the three situations you're in
- It's a real problem. Something on your side needs fixing: an old TLS version, an expired certificate, an open port, unpatched software. This is the most common case. Our guides on the common reasons scans fail and what to fix before your next scan cover each one. Fix it, then rescan.
- It's a false positive. The scanner flagged something that isn't actually a risk in your setup. This happens more than people expect (see the list below). You don't fix it, you dispute it with evidence.
- It's out of scope. The scan hit something that isn't yours or isn't part of your card environment: a shared IP at your host, a neighbor's system, a decommissioned server still in DNS. You correct the scope and rescan.
The famous false positives
These trip up merchants every quarter. Each one is real, well known, and disputable.
- The TCP source port firewall issue. Some firewalls let traffic through if it comes from certain source ports (often 20, 53, or 88). Scanners flag it as a firewall bypass. If your firewall actually filters by destination and state, this is disputable with your firewall configuration as evidence.
- CDN and proxy findings. If your site sits behind a CDN or a web application firewall, the scanner is looking at the CDN's servers, not yours. Findings about the CDN's TLS settings or headers are usually the CDN's responsibility and are disputable with the CDN's own documentation.
- Load balancers and multiple IPs. A load balancer can answer differently on each scan, and a scan of one IP can surface a backend server that isn't in scope. Our guide on load balancers and PCI ASV scanning explains how to scope these correctly.
- The scanner was blocked. If your firewall or hosting provider blocked the scanner's addresses, the scan is incomplete and can be reported as a failure. Whitelist the ASV scanner range first (ours is 38.123.140.0/25), then rescan. Our whitelisting guide has the steps.
- A patched version that still reports the old number. Some Linux distributions backport security fixes without changing the version number the scanner sees. Disputable with the package changelog showing the fix.
How to dispute a finding
Under the PCI ASV program, you can dispute any finding you believe is a false positive, is compensated for by another control, or is out of scope. You submit evidence, the ASV reviews it, and if it holds up, the finding is marked as an exception and no longer fails the scan. With Clone Systems, you submit disputes and exception requests inside the portal under Options. Our security team reviews them, usually within 24 hours, and you rescan as soon as the exception is approved. Rescans are free and unlimited until you pass.
Your deadline
PCI requires a passing scan every three months, and your processor usually expects one by the end of each calendar quarter: March 31, June 30, September 30, and December 31. Some processors charge a monthly non-compliance fee once you miss the date. The fee stops once you submit a passing scan, so the goal is speed, not perfection: fix or dispute the findings, rescan, and pass. Our guide on PCI scan deadlines covers the dates and what processors typically require.
If you don't have a scanning vendor, or want a second opinion
You can buy a PCI ASV scan from Clone Systems online and run it today. Starter is $185 a year for one IP or domain, and every package includes unlimited rescans until you pass, so a failed first scan costs nothing extra. You get the same attestation report your processor asks for. If your findings are hard to read, the optional AI Remediation Assistant explains each one in plain language and tells you what to change; it runs privately in our own data center, so your scan data never goes to an outside AI service.
Buy a PCI scan and run it today · Talk to a specialist
Guides for the specific fixes
- Common reasons PCI ASV scans fail and how to resolve them
- What to fix before your next ASV scan
- Whitelisting the ASV scanner for a valid PCI scan
- Load balancers and PCI ASV scanning
- Making sense of PCI ASV reports
- PCI scan deadlines
- Why you still need an ASV scan with a payment provider checkout
Clone Systems has been a PCI Security Standards Council Approved Scanning Vendor since 2007. This page is general guidance, not a substitute for your processor's specific requirements.
