If you've looked around our site, you've probably noticed two different services: PCI scanning and penetration testing. They sound similar, and PCI DSS asks for both, so it's easy to wonder if you need one, the other, or both. Here's the real difference, and how to tell which one your business needs.

What a PCI Vulnerability Scan Is

A PCI vulnerability scan is automated. Software checks your external IP addresses for known weak spots: outdated software, weak SSL/TLS settings, open ports that shouldn't be open, and other issues that show up in security databases. It runs fast, usually in minutes to a few hours, and nobody has to sit there running it by hand.

PCI DSS requires this scan at least once a quarter (Requirement 11.3.2), and it has to come from an Approved Scanning Vendor (ASV) like ServerScan. Every ServerScan plan includes unlimited scans, so you can run one after every change instead of waiting and hoping nothing broke before your next quarterly deadline.

What a Penetration Test Is

A penetration test goes deeper than a scan. It doesn't just check your systems against a list of known issues, it actually tries to exploit what it finds, the same way an attacker would. ServerScan's penetration testing runs on automated attack-simulation technology built by our security team, not a person manually working through your systems, so you get that extra depth without a multi-week engagement.

PCI DSS requires a penetration test at least once a year (Requirement 11.4.1-11.4.3), from both outside and inside your network. If you use network segmentation to wall off your cardholder data environment, you also need segmentation testing: every six months if you're a service provider, once a year if you're a merchant.

Why PCI DSS Asks for Both

A scan and a pentest catch different things. A scan is broad and fast. It checks thousands of known vulnerabilities across every IP address you give it, on a schedule, at a low cost. A pentest is narrower and deeper. It actively attempts to exploit what it finds, chaining smaller issues together the way an attacker would, instead of just listing them separately.

Neither one replaces the other. That's why PCI DSS wants quarterly scans to catch the common stuff continuously, and an annual pentest to catch what a basic scan isn't built to find.

Which One Do You Need?

Almost every merchant that accepts cards needs quarterly ASV scans, whether you're filling out SAQ A or SAQ D. Not sure which SAQ applies to you? Take a look here.

Whether you also need an annual pentest, and how often, depends on your PCI DSS level and how your environment is scoped. Service providers and larger merchants almost always need one. If you're smaller and mostly rely on a third party to handle cardholder data, check with your acquiring bank or QSA. When in doubt, ask us. We'd rather point you at the right service than sell you something you don't need.

What ServerScan Offers

ServerScan runs both. Our PCI ASV scanning covers your quarterly requirement, with unlimited scans included so you can rescan for free after every fix. Our penetration testing covers your annual requirement, running on automated testing technology built by our security team, with a free scoping call to figure out what your environment actually needs.

Still not sure which one applies to you? Contact our support team. We'll walk through your setup with you, free, before you buy anything.