PCI DSS

What is a PCI compliance scan?

Short answer

A PCI scan is a vulnerability scan of the systems in your cardholder data environment, required by PCI DSS Requirement 11.3. External scans have to be run at least once every three months by an Approved Scanning Vendor (ASV) listed by the PCI Security Standards Council, and internal scans on the same quarterly cadence by qualified staff or a third party. Both are also required after any significant change, and you remediate what they find and rescan to show the fix.

Last updated

External scans and ASVs

The external half of Requirement 11.3 has to be performed by an Approved Scanning Vendor, a company the PCI Security Standards Council has qualified for the purpose. The ASV scans your internet-facing in-scope addresses, grades the findings, and issues a report. A scan with no vulnerability scored at or above the ASV threshold is a passing scan, and that is what satisfies the requirement. Your own scanning tool, however good, does not substitute for the ASV report.

Internal scans

Internal vulnerability scanning covers the systems inside your environment on the same cadence. It does not need an ASV: qualified internal staff or a third party can run it, as long as whoever runs it is organizationally independent of the systems being scanned. Version 4 also expects authenticated scanning where systems accept credentials, which finds a great deal that an unauthenticated scan from outside cannot see.

After significant change, not only on the calendar

A new internet-facing service, a change to the network topology, a new component in the cardholder data environment: each triggers a scan outside the quarterly rhythm. Teams that treat scanning as a quarterly ritual tend to fail this part, because the change that introduced the exposure happened in week two and nothing looked until week thirteen.

A scan is not a penetration test

Scanning is automated and looks for known vulnerabilities. Penetration testing, Requirement 11.4, is a human attempting to break in, at least once every 12 months, covering the perimeter and the segmentation that keeps the cardholder data environment separate. Service providers test segmentation more often than merchants do. Both are required, and one does not cover for the other.

What to do with the findings

Rank them, fix what the requirement obliges you to fix, and rescan or retest until the result is clean. Requirement 6.3.3 requires patches for critical vulnerabilities within one month of release; other security patches go in on a timeframe your own risk ranking sets. Keeping the scan reports and the remediation record is part of the evidence an assessor or an acquirer asks for.

Where Keel fits

Keel tracks scanning (11.3) and penetration testing (11.4) at that second level, as controls with owners and status, and the scan reports attach to them as evidence. The defined requirements beneath them, such as the separate internal and external scan duties, are not tracked one by one. Remediation of each finding can be tracked as a task with an assignee and a due date, linked to the control it belongs to. Keel does not perform scans and is not an ASV.

FAQ

How often is a PCI scan required?

At least once every three months for both internal and external scans, and again after any significant change to the in-scope environment.

What is an ASV?

An Approved Scanning Vendor: a company qualified by the PCI Security Standards Council to perform the external vulnerability scans PCI DSS requires. The Council publishes the list of them.

What counts as a passing ASV scan?

A scan report with no vulnerability scored at or above the threshold the ASV Program Guide sets. If you fail, you remediate and rescan within the same period rather than waiting for the next quarter.

Do I need scans if I use a hosted payment page?

Often yes, for the systems still in scope, and your SAQ states which requirements you have to meet. Fully outsourced merchants on SAQ A have the smallest obligation, but the pages that redirect to the processor are still yours to protect.

Can I use my own vulnerability scanner?

For internal scans, yes, if whoever runs them is independent of the systems scanned. The external quarterly scan has to come from an ASV.

Next step

Get audit-ready with Keel

The AI-native GRC platform for SMBs: one control-and-evidence graph across SOC 2, ISO 27001, HIPAA, PCI DSS, NIST CSF, and more. Start free, no credit card.