Here is the thing about picking an ASV: the scan itself is the same everywhere. Every ASV is certified by the PCI Security Standards Council, and they all test against the same rules, so a passing scan from any of them meets PCI DSS Requirement 11.3.2. What actually differs is price, rescan fees, support, and contract terms. That is where you should look.
Why the scan is not the differentiator
To get on the PCI SSC list of Approved Scanning Vendors, a company has to pass the same certification testing and follow the same program guide as everyone else. The checks, the scoring, and the pass or fail rules come from the standard, not from the vendor. A cheap scan and an expensive scan look for the same holes. So do not ask whose scanner is best. Ask what happens around the scan, especially when one fails, because most businesses fail one eventually.
1. Are rescans free and unlimited?
This is the big one. Your first scan usually finds something: an old TLS setting, a subdomain nobody remembered, a plugin that needs an update. You fix it and scan again, and that is normal. But some vendors charge you every time, so a $200 price tag turns into $600 by the end of the year. Others include unlimited rescans in the base price. Ask, and get the answer in writing.
2. What does it cost at your IP count?
Vendors price per IP address, per scan, or as a flat subscription, and which one is cheapest depends on how many IPs you actually need to scan. Not sure how many that is? Read our guide on which IP addresses to scan first, because it changes your scope and your bill. Then get quotes at that number, not the teaser price for a single IP.
3. Are there platform or setup fees?
Some services add a platform fee or an account fee on top of the scan price, and some charge to generate the attestation paperwork your bank wants. Ask for the all-in yearly number, meaning four quarterly scans, any rescans, and the reports. Our ASV scan cost guide breaks down the fee structures we see and what they add up to.
4. How do you dispute a false positive?
Scans sometimes flag things that do not apply to you, and the classic case is a package that was patched but still reports an old version number. Every ASV has to have a dispute process, but the experience varies a lot. Some sort it out in a day with a real person, while others charge a fee or take weeks. Ask how you file one, what it costs, and how long it usually takes.
5. What support do you get?
When a scan fails, the report can be dense. The difference between a good vendor and a bad one is whether someone will explain what a finding means and how to fix it, or whether you are left alone with a 40-page PDF. Ask if support costs extra, whether it is phone or email only, and where the team is based.
6. Do they help with the SAQ?
The scan is only half the paperwork. The Self-Assessment Questionnaire is the other half, and picking the right one matters, so our guide to which SAQ to complete walks through it. Some scanning vendors include SAQ help and the forms, and others treat it as a paid add-on.
7. What are the contract terms?
Look for auto-renewal terms, cancellation windows, and multi-year lock-ins. If a vendor offers quarterly billing, that is a low-risk way to try them before committing to a year.
8. What if you cannot pass?
Ask if there is a guarantee. If you fix everything in the report and still cannot get a passing scan, do you get your money back? A vendor that is confident in its support will say yes.
How ServerScan answers all eight
You are going to ask, so here it is. ServerScan is $59 a quarter or $188 a year for one IP address or domain. Rescans are free and unlimited, and there are no platform fees and no dispute fees. SAQ guidance and all the forms are included, support is US-based by phone or email, and you can bill quarterly if you want to start small. If you cannot get a passing scan with what we give you, we refund the whole purchase. Whichever vendor you pick, make them answer all eight questions first.