
External vulnerability scans to meet PCI DSS requirements
Quarterly external vulnerability scans compliant with PCI DSS v4.0 requirements, performed by Approved Scanning Vendors (ASV). Reports are ready for QSA auditors to demonstrate payment environment compliance.
asv scanning
What is ASV scanning?
ASV (Approved Scanning Vendor) scanning is a PCI DSS requirement for entities that process payment card transactions.

Mandatory requirement
Mandated by the PCI DSS standard for all merchants
- Item 1
- Item 2
- Item 3
PCI Council approved
Globally recognized certification and compliance
- Item 1
- Item 2
- Item 3
External scanning
Tests from outside the security perimeter
- Item 1
- Item 2
- Item 3

external scans
Quarterly external scans
Vulnerability scans scheduled four times a year to ensure continuous security for your systems.
Regular schedule
Quarterly scans in accordance with the PCI schedule
- Item 1
- Item 2
- Item 3
In-depth testing
Comprehensive analysis of known and zero-day vulnerabilities
- Item 1
- Item 2
- Item 3
Official report
Actionable results for PCI DSS-required ASV assessments
- Item 1
- Item 2
- Item 3

pci dss
PCI DSS v4.0
Compliance with the latest PCI DSS version 4.0 requirements with enhanced security controls.
Up-to-date requirements
Alignment with PCI DSS v4.0 and its additional controls
- Item 1
- Item 2
- Item 3
Strong authentication
Multi-factor and compliant identity management
- Item 1
- Item 2
- Item 3
Risk management
Third-party and cloud service risk assessment
- Item 1
- Item 2
- Item 3
automated reports
Automated reports for auditors
Formal scan reports for your QSA auditors, complete with evidence and detailed recommendations.

AoC format
Attestation of Compliance meeting PCI Council requirements
- Item 1
- Item 2
- Item 3
Recommendations
Detailed remediation advice for each vulnerability
- Item 1
- Item 2
- Item 3
Remediation tracking
Rescans to validate the remediation of identified issues
- Item 1
- Item 2
- Item 3
Testimonials
FAQ
From asset mapping to automated remediation.
What is an ASV (Approved Scanning Vendor)?
An ASV is a service provider certified by the PCI Security Standards Council, authorized to perform the external vulnerability scans required by the PCI DSS standard. Any entity that processes, stores, or transmits payment card data must have these scans performed by an approved ASV to demonstrate compliance to their auditors.
How does Cyberwatch help ASVs (Approved Scanning Vendors)?
Cyberwatch helps ASVs carry out their missions by automating the detection, qualification, and tracking of their clients' vulnerabilities. Our platform centralizes scans, prioritizes flaws based on their criticality, provides proof of remediation, and facilitates the production of reports compliant with PCI DSS requirements. It reduces analysis time, makes audits more reliable, and improves the traceability of remediations.
Why must PCI DSS scans be performed quarterly?
The PCI DSS standard requires an external scan at least every quarter to quickly detect any new vulnerabilities exposed on systems that process payments. This frequency ensures ongoing monitoring of the external attack surface, rather than a one-off annual check, which is insufficient given the rapid evolution of threats and configurations.
What happens if a critical vulnerability is detected during an ASV scan?
When an ASV scan detects a critical vulnerability, the report is considered non-compliant. The organization must then remediate the vulnerability (via patching, reconfiguration, or disabling the vulnerable service), rerun a scan on the affected components to verify the fix, and repeat this cycle until a report with no critical vulnerabilities is obtained, which is a requirement for PCI DSS certification.
Does an ASV scan replace other internal security controls?
No, an ASV scan only covers the external attack surface exposed to the Internet for regulatory compliance purposes. It does not replace continuous vulnerability management across the entire application perimeter, which requires ongoing monitoring beyond just PCI DSS requirements.
