Approved Scanning Vendors (ASV)
ASVs are companies certified by the PCI SSC to help implement certain PCI DSS requirements. They validate a company's compliance with the PCI DSS, and give you a certification so you can prove that compliance to your customers and acquiring bank. ASVs are only one of a few authorized groups to give you certificates of compliance, so it will almost always be necessary you work with one.
What Is an ASV Scan?
An ASV scan checks your network for weak spots, and you need one every three months under PCI DSS Requirement 11.3.2. A certified scanning company runs it for you from outside your network, so your own staff can't do it themselves.
The scan looks at every system you have connected to the internet and finds spots a hacker could break through.
Once you pass, you get a report you can hand to your bank or payment processor. It proves your systems are safe from known holes right now, but it doesn't prove you're compliant on everything else, just this one piece.
How are ASVs qualified to test my system?
ASVs undergo a rigorous annual testing and retesting policy in order to maintain their ASV status. The PCI SSC is very strict on who is allowed to become an ASV, and they also charge large annual fees to maintain ASV status. These two components ensure that Approved Scanning Vendors are very serious and well established companies that are capable of keeping up with changing security measures, and able to deliver accurate information to you about your security needs. You can be sure that you are covered if you have received passing scan reports or PCI certificates from an ASV, along with the completion of your other PCI compliance requirements.
While ASVs can sometimes offer a wide array of security services, they mainly help companies get PCI certificates through vulnerability scanning. The basics of PCI compliance require an external vulnerability scan in order to check for possible weaknesses in your system that could be exploited by attackers. Only ASVs have the necessary certification from the PCI SSC to give you the attestation of compliance you need for your acquiring bank.
PCI SSC's own FAQ notes that "certificates" are not an officially recognized compliance validation artifact — the recognized deliverable is the ASV Attestation of Scan Compliance, along with the underlying scan report. The documentation you'll receive here at ServerScan is your Attestation of Scan Compliance and executive scan reports. Most ASVs don't provide "PCI certificates" in a literal sense; their equivalent is a copy of your passing scan report and Attestation of Scan Compliance.
What Counts as a Passing Scan?
Every issue gets a score from 0 to 10, called a CVSS score. Score 4.0 or higher and that's a fail. Under 4.0, you pass, but it's still worth fixing when you can.
A few things fail you no matter the score: an old operating system with no security updates, a database anyone online can reach, SQL injection, cross-site scripting, or an outdated SSL version.
Your report shows exactly what failed and why, so you're not guessing.
How often do I need ASV scanning?
PCI scanning is normally required to be done quarterly. You should prepare for your quarterly ASV scan by scanning a few weeks prior to your due date, so you have time for remediation and rescanning. ServerScan makes this process simple by offering unlimited scans with every purchase. No matter what length of time you sign up for, you will not only have the ability to run unlimited scans for no extra charge, you will be able to schedule scans as often as you like, to help remind you when due dates are near, and to make sure you never miss a deadline with your bank.
What Happens If My Scan Fails?
Scans fail all the time, and it's not a violation, it just means you have something to fix. Your report shows exactly what we found and why it failed, so you or your host know what to do next.
If you have an active ServerScan plan, rescans are free and unlimited. Fix the problem, scan again, and repeat as many times as you need, for as long as your plan stays active. Not sure what a finding means? Just ask our support team.
Do I Still Need Scanning If I Use a Hosted or Iframe Checkout?
Yes, in most cases. Even if your checkout sends people to a payment processor, or loads their form in an iframe, you probably still need scans. That's new under PCI DSS v4.0, as part of SAQ A. The old rules let hosted and iframe checkouts skip scanning, and that's probably where you heard you didn't need one.
Your exact answer depends on your SAQ type and how your checkout works, so ask your bank or a QSA to be sure. But if you take payments on your site at all, just assume you need to scan every quarter. Check our FAQ for more.