External vulnerability scans to meet PCI DSS requirements

Quarterly external vulnerability scans compliant with PCI DSS v4.0 requirements, performed by Approved Scanning Vendors (ASV). Reports are ready for QSA auditors to demonstrate payment environment compliance.

asv scanning

What is ASV scanning?

ASV (Approved Scanning Vendor) scanning is a PCI DSS requirement for entities that process payment card transactions.

ASV Scanning

Mandatory requirement

Mandated by the PCI DSS standard for all merchants

  • Item 1
  • Item 2
  • Item 3

PCI Council approved

Globally recognized certification and compliance

  • Item 1
  • Item 2
  • Item 3

External scanning

Tests from outside the security perimeter

  • Item 1
  • Item 2
  • Item 3
PCI DSS ASV External Scans

external scans

Quarterly external scans

Vulnerability scans scheduled four times a year to ensure continuous security for your systems.

Regular schedule

Quarterly scans in accordance with the PCI schedule

  • Item 1
  • Item 2
  • Item 3

In-depth testing

Comprehensive analysis of known and zero-day vulnerabilities

  • Item 1
  • Item 2
  • Item 3

Official report

Actionable results for PCI DSS-required ASV assessments

  • Item 1
  • Item 2
  • Item 3

pci dss

PCI DSS v4.0

Compliance with the latest PCI DSS version 4.0 requirements with enhanced security controls.

Up-to-date requirements

Alignment with PCI DSS v4.0 and its additional controls

  • Item 1
  • Item 2
  • Item 3

Strong authentication

Multi-factor and compliant identity management

  • Item 1
  • Item 2
  • Item 3

Risk management

Third-party and cloud service risk assessment

  • Item 1
  • Item 2
  • Item 3

automated reports

Automated reports for auditors

Formal scan reports for your QSA auditors, complete with evidence and detailed recommendations.

PCI DSS Automated Reports for Auditors

AoC format

Attestation of Compliance meeting PCI Council requirements

  • Item 1
  • Item 2
  • Item 3

Recommendations

Detailed remediation advice for each vulnerability

  • Item 1
  • Item 2
  • Item 3

Remediation tracking

Rescans to validate the remediation of identified issues

  • Item 1
  • Item 2
  • Item 3

Testimonials

The platform centralizes both our PCI compliance for online billing operations and our broader IT vulnerability management, which simplifies our security oversight.

CISO, energy

CISO

Quarterly ASV scans and the supplementary pentest provide us with a comprehensive view of our PCI DSS compliance, with reports that are directly actionable for our QSA auditors.

Payment Security Manager, Finance

Payment Security Manager

FAQ

From asset mapping to automated remediation.

What is an ASV (Approved Scanning Vendor)?

An ASV is a service provider certified by the PCI Security Standards Council, authorized to perform the external vulnerability scans required by the PCI DSS standard. Any entity that processes, stores, or transmits payment card data must have these scans performed by an approved ASV to demonstrate compliance to their auditors.

hidden category

How does Cyberwatch help ASVs (Approved Scanning Vendors)?

Cyberwatch helps ASVs carry out their missions by automating the detection, qualification, and tracking of their clients' vulnerabilities. Our platform centralizes scans, prioritizes flaws based on their criticality, provides proof of remediation, and facilitates the production of reports compliant with PCI DSS requirements. It reduces analysis time, makes audits more reliable, and improves the traceability of remediations.

hidden category

Why must PCI DSS scans be performed quarterly?

The PCI DSS standard requires an external scan at least every quarter to quickly detect any new vulnerabilities exposed on systems that process payments. This frequency ensures ongoing monitoring of the external attack surface, rather than a one-off annual check, which is insufficient given the rapid evolution of threats and configurations.

hidden category

What happens if a critical vulnerability is detected during an ASV scan?

When an ASV scan detects a critical vulnerability, the report is considered non-compliant. The organization must then remediate the vulnerability (via patching, reconfiguration, or disabling the vulnerable service), rerun a scan on the affected components to verify the fix, and repeat this cycle until a report with no critical vulnerabilities is obtained, which is a requirement for PCI DSS certification.

hidden category

Does an ASV scan replace other internal security controls?

No, an ASV scan only covers the external attack surface exposed to the Internet for regulatory compliance purposes. It does not replace continuous vulnerability management across the entire application perimeter, which requires ongoing monitoring beyond just PCI DSS requirements.

hidden category