If you pay SecurityMetrics for quarterly scans today and are thinking about a different vendor, this page explains what ServerScan does differently and how to switch without missing a quarter. The scan itself is standardized, because every Approved Scanning Vendor is certified against the same rules. What differs is how you pay, what comes with the plan, and how much help you get when a scan fails.
ServerScan sells quarterly PCI ASV scans. A plan costs $59 a quarter or $188 a year per IP address or domain, with unlimited rescans and no fees for retests or false-positive disputes.
How you pay
As of September 2026, the SecurityMetrics online store sells its quarterly ASV scan product as an annual payment for each domain or IP address, and the product expires one year after purchase. With ServerScan you can pay by the quarter instead, so you are never paying for a year you might not need. Our quarterly plan is $59 per IP address or domain, and if you would rather pay once for the year, it is $188, which works out to $47 a quarter. If you scan several addresses, we offer discounts for those too. The full details are on our pricing page.
What every ServerScan plan includes
Every plan comes with unlimited rescans at no extra charge, as often as you want, so you can scan every day if you like. You get an Attestation of Scan Compliance with every passing scan, the SAQ forms and help choosing the right one, the ServerScan trust seal for your site, and US-based email support from the day you sign up. There are no retest fees, no platform fees, and no charge for disputing a false positive or asking our support team to review a finding. And if your site can't pass our scan and our support team can't get you there, we refund your order in full.
If your site is behind Cloudflare
A site behind Cloudflare or another CDN is where most scan trouble starts. The scanner can end up testing Cloudflare's edge instead of your server, or get blocked by the firewall and come back with timeouts that don't count as a pass. Our guide to ASV scan errors behind Cloudflare covers the fixes. Getting the scan to reach your real server is routine work for our support team, and it is included for every customer at no extra charge.
Can I switch ASVs in the middle of the year?
Yes. PCI DSS asks for a passing ASV scan at least once every three months, and it does not care which approved vendor runs it, so you can change vendors between any two quarters. Because the SecurityMetrics scan product runs for a year from purchase, check when yours comes up for renewal and decide before then, but you don't have to wait for it to run out before you start with us. The easiest time is a few weeks before your next quarterly scan is due, which leaves room to fix anything the first scan finds and rescan before the deadline.
Will my bank accept a scan from a new ASV?
Yes, as long as the vendor is on the PCI Security Standards Council's list of Approved Scanning Vendors. Your bank or acquirer needs a passing scan each quarter, not a scan from any particular vendor. Send the new Attestation of Scan Compliance the same way you sent the old one, usually with your Self-Assessment Questionnaire, or upload it to your bank's compliance portal if it uses one. If your bank set you up with a scanning vendor as part of its own program, ask it how to submit a scan from a different ASV before your next deadline, so the switch doesn't show up as a missed quarter.
What happens to my old vendor's scan history?
It stays with your old vendor, so download your past scan reports and attestations before that account closes. Your bank or assessor can ask to see the last four quarters of passing scans, and some of those will have come from SecurityMetrics. From your first ServerScan scan on, your reports and attestations are kept in your ServerScan account, where you can get them whenever you need them.
How fast can I get a passing scan after switching?
Often the same day. Sign-up takes a few minutes, and you can run your first scan straight away with the same IP addresses and domains you scanned before. A scan takes anywhere from about an hour to more than four, depending on how quickly your server answers, and your Attestation of Scan Compliance is emailed to you when it passes. One thing to check first: if your firewall or WAF lets your old vendor's scanners through, add our range as well, because nothing may block an ASV scan while it runs and a blocked scan doesn't count. Our FAQ lists the range, and our guide to which IP addresses to scan helps if you want to check your list.
Do I need to rescan after fixing a failure?
Yes. A failed scan only turns into a pass when a new scan shows the problem is gone, so fix what the report lists and scan again. With ServerScan that costs nothing, and because unlimited scanning is included, you can fix an issue and rescan the same day instead of waiting for your next quarterly window. Our guide to common PCI scan failures covers the fixes for the problems we see most.
Getting started
Choose quarterly or annual billing, add your IP address or domain, and run your first scan. You can sign up for PCI scanning here, and every plan detail is on our pricing page.
Details about SecurityMetrics are taken from the SecurityMetrics online store and the PCI Security Standards Council's list of Approved Scanning Vendors as of September 2026, and may have changed since. ServerScan is not affiliated with SecurityMetrics.