When is your next PCI scan due?

The current PCI quarterly scan window (Q3 2026) ends September 30, 2026. 15 days remain. The next window opens October 1, 2026 and ends December 31, 2026.

Order a PCI scan

This page recalculates every day. Today is September 15, 2026.

Scan windows for 2026

The four quarterly scan windows this year.

A passing ASV scan is needed inside each window. Next year follows the same calendar quarters.

QuarterWindow opensWindow closesStatus
Q1 2026January 1, 2026March 31, 2026Closed
Q2 2026April 1, 2026June 30, 2026Closed
Q3 2026July 1, 2026September 30, 2026Open now
Q4 2026October 1, 2026December 31, 2026Upcoming
What the requirement says

Three things decide your real deadline.

At least once every three months

PCI DSS 4.0.1 Requirement 11.3.2 requires an external vulnerability scan by an Approved Scanning Vendor at least quarterly, with a passing result.

And after any significant change

A new public-facing system, a network change, or a payment page update calls for a scan outside the regular cycle.

Your acquirer sets the exact due date

Most acquirer and processor programs line the requirement up with calendar quarters. Their compliance portal is the final word on your date.

Running late

The fastest path to a passing scan.

Scanning is quick. Fixing findings is the part that takes time, so start before the last week of the quarter.

01

Order online

Pick the PCI package that matches your IP or domain count. Portal access is created automatically when payment goes through.

02

Launch an instant scan

No download and no setup call. Add your public-facing assets and start the scan right away.

03

Fix what fails, then rescan

Rescans are unlimited and included, so you can verify each fix until the scan passes.

04

Send the attestation

After a passing scan you receive the Attestation of Scan Compliance for your acquirer or QSA.

Common questions

PCI scan deadline questions, answered.

When does the current PCI quarterly scan window close?

The current PCI quarterly scan window (Q3 2026) ends September 30, 2026. 15 days remain. The next window opens October 1, 2026 and ends December 31, 2026. Most acquirer programs align quarterly ASV scans to calendar quarters; confirm the exact due date in your acquirer's compliance portal.

How often does PCI DSS require an ASV scan?

PCI DSS 4.0.1 Requirement 11.3.2 requires an external vulnerability scan by a PCI SSC Approved Scanning Vendor at least once every three months, plus a scan after any significant change to internet-facing systems in the cardholder data environment. The scan must produce a passing result.

What happens if I miss the quarter?

Your acquirer decides how a missed quarter is handled. Many charge a monthly non-compliance fee until a passing scan is on file. The fastest fix is to run a scan as soon as possible, remediate any failing findings, rescan, and submit the Attestation of Scan Compliance.

Can I still pass if I order near the end of the quarter?

Clone Systems creates portal access automatically when payment goes through, so you can launch a scan right away and rescans are unlimited. Remediation is the part that takes time, so leave room to fix findings before the window closes.

Ready when you are

Get a passing scan on file before the window closes.

Published prices, instant scan launch, unlimited rescans, and the attestation your acquirer asks for.

Order a PCI scan