The PCI DSS requires that different types of scans be performed, and at different intervals. We are often asked what the difference is between external ASV scans, internal vulnerability scans, penetration tests, segmentation tests, and application code scans. It is important to understand the differences between these scan types and the corresponding requirements of each:

Quarterly External Vulnerability Scans (Requirement 11.3.2) - ASV scans, at least once every three months by an ASV. All vulnerability scans performed by ServerScan are ASV-certified and satisfy this PCI DSS requirement.

Quarterly Internal Vulnerability Scans (Requirement 11.3.1) – At least once every three months from inside your network. The PCI DSS (Version 4) now requires that these be "authenticated" scans (Requirement 11.3.1.2).

Annual Penetration Testing (Requirement 11.4.1-11.4.3) - At least once a year by a qualified penetration tester. Penetration tests performed by ServerScan can be used to satisfy this requirement.

Segmentation Testing (Requirement 11.4.5 and 11.4.6) – Annually for merchants, every six months for service providers. Segmentation penetration tests performed by ServerScan satisfy this requirement.

Payment Page Integrity Monitoring (Requirement 11.6.1) - As of PCI DSS Version 4, payment pages must be monitored for unauthorized changes to security-impacting HTTP headers and script contents, as received by the consumer's browser. ServerScan is developing a solution to help satisfy this requirement — contact our support team for details.

Do you still have any questions about the vulnerability scanning requirements for PCI DSS compliance? Please call our knowledgeable customer support team at 615-241-2344 or email us for help getting started with our external vulnerability scanning and penetration testing services.