When is your next PCI scan due?
The current PCI quarterly scan window (Q3 2026) ends September 30, 2026. 15 days remain. The next window opens October 1, 2026 and ends December 31, 2026.
This page recalculates every day. Today is September 15, 2026.
The four quarterly scan windows this year.
A passing ASV scan is needed inside each window. Next year follows the same calendar quarters.
| Quarter | Window opens | Window closes | Status |
|---|---|---|---|
| Q1 2026 | January 1, 2026 | March 31, 2026 | Closed |
| Q2 2026 | April 1, 2026 | June 30, 2026 | Closed |
| Q3 2026 | July 1, 2026 | September 30, 2026 | Open now |
| Q4 2026 | October 1, 2026 | December 31, 2026 | Upcoming |
Three things decide your real deadline.
At least once every three months
PCI DSS 4.0.1 Requirement 11.3.2 requires an external vulnerability scan by an Approved Scanning Vendor at least quarterly, with a passing result.
And after any significant change
A new public-facing system, a network change, or a payment page update calls for a scan outside the regular cycle.
Your acquirer sets the exact due date
Most acquirer and processor programs line the requirement up with calendar quarters. Their compliance portal is the final word on your date.
The fastest path to a passing scan.
Scanning is quick. Fixing findings is the part that takes time, so start before the last week of the quarter.
Order online
Pick the PCI package that matches your IP or domain count. Portal access is created automatically when payment goes through.
Launch an instant scan
No download and no setup call. Add your public-facing assets and start the scan right away.
Fix what fails, then rescan
Rescans are unlimited and included, so you can verify each fix until the scan passes.
Send the attestation
After a passing scan you receive the Attestation of Scan Compliance for your acquirer or QSA.
PCI scan deadline questions, answered.
When does the current PCI quarterly scan window close?
The current PCI quarterly scan window (Q3 2026) ends September 30, 2026. 15 days remain. The next window opens October 1, 2026 and ends December 31, 2026. Most acquirer programs align quarterly ASV scans to calendar quarters; confirm the exact due date in your acquirer's compliance portal.
How often does PCI DSS require an ASV scan?
PCI DSS 4.0.1 Requirement 11.3.2 requires an external vulnerability scan by a PCI SSC Approved Scanning Vendor at least once every three months, plus a scan after any significant change to internet-facing systems in the cardholder data environment. The scan must produce a passing result.
What happens if I miss the quarter?
Your acquirer decides how a missed quarter is handled. Many charge a monthly non-compliance fee until a passing scan is on file. The fastest fix is to run a scan as soon as possible, remediate any failing findings, rescan, and submit the Attestation of Scan Compliance.
Can I still pass if I order near the end of the quarter?
Clone Systems creates portal access automatically when payment goes through, so you can launch a scan right away and rescans are unlimited. Remediation is the part that takes time, so leave room to fix findings before the window closes.
Get a passing scan on file before the window closes.
Published prices, instant scan launch, unlimited rescans, and the attestation your acquirer asks for.