ServerScan is a PCI Approved Scanning Vendor. We have been scanning for compliance since 2015 and have completed more than 10,000 scans. Everything we offer is below, with what it costs and who it is for.

PCI ASV Scanning

External network vulnerability scanning, certified by the PCI Security Standards Council. This is the service that satisfies the quarterly external scanning requirement in PCI DSS, requirement 11.3.2, and it is what most merchants come to us for.

We scan your server at the IP address or hostname you nominate, looking for the weaknesses attackers actually use. That includes SQL injection, cross-site scripting, remote code execution, and unpatched software. If something fails, the report tells you what to fix rather than leaving you to interpret a score.

Every subscription includes all of the following.

  • Unlimited rescans. Scan as often as you like, whenever you like. Fixing a finding and scanning again costs nothing.
  • ASV Attestation of Scan Compliance certificates with every passing scan, kept in your account so you can produce one when your bank or assessor asks.
  • Self-Assessment Questionnaire help, including the forms and guidance on choosing the right one.
  • US-based support by phone and email, from people who will look at your findings with you.
  • The ServerScan trust seal for your website.

Pricing is $59 per quarter or $188 per year, per IP address. The annual plan covers all four quarterly scans in one payment and saves $48 against paying quarterly. There are no retest fees, no platform fees, and no charge for asking support to review a finding. See full pricing or sign up now.

Scanning more than one address? We discount multiple IP addresses and domains. Tell us what you need and we will follow up with a price.

Penetration Testing

A penetration test is a different thing from a vulnerability scan, and the two are often confused. A scan finds known weaknesses automatically and runs on a schedule. A penetration test is a person, or an automated system built to behave like one, actively trying to chain those weaknesses into a real intrusion.

PCI DSS asks for both. Requirement 11.3.2 is the quarterly external scan. Requirement 11.4 is penetration testing, and a scan does not satisfy it.

Penetration tests are quoted per project, because the price depends on scope. How many addresses, how many applications, and how deep you want us to go all change the work involved. Read more about our penetration testing or request a quote and we will come back with scope, timing and cost.

If you are not sure which one you need, we have written a comparison of scanning versus penetration testing.

Free Payment Page Check

A free tool, with no sign-up and nothing published. Give it the address of your checkout page and we load it once, from our own network, then tell you how it is being served.

You get the security headers the page returned, the TLS and certificate details we saw, and a list of the scripts written into the page's HTML, marking which ones come from a domain other than yours. That last part is the beginning of the script inventory that PCI DSS requirement 6.4.3 asks every merchant to keep.

It is one request, made once, so be clear about its limits. It cannot see scripts that a tag manager adds after the page starts running, it cannot tell you what changed since yesterday, and it is not a pass or a fail. It is a free look at how your checkout is configured today.

It costs nothing. Check your payment page, or read what a payment page script inventory involves.

Payment Page Monitoring

The free check above reads your checkout once. Monitoring reads it every day and compares it against every previous day, which is the part PCI DSS requirement 6.4.3 actually asks for. Every word of that requirement is about keeping an inventory current rather than producing one.

You get a dated list of every script on the page, so the answer is "this one first appeared on 14 September" rather than "there are seven of them". It holds the written business justification you record against each script and flags the ones still missing theirs. It keeps a record of which days a scan reached the page, so a quiet week means we looked and nothing moved. It emails you when something new appears, and every week when nothing has. At the end of it you can export a dated inventory as a spreadsheet or a printable report for an assessor.

It is not a pass or a fail and it is not an ASV scan. It produces an inventory and a record of changes, and it never issues a verdict on your site.

There are two ways to buy monitoring, and they are priced differently. Added to a scanning subscription it is $20 a quarter or $64 a year, making that subscription $79 a quarter or $252 a year including the scan itself. On its own, without a scan, it is $24 a quarter or $77 a year. Read more about payment page monitoring, or try the free check first to see what is on your checkout today.

Security Verified Site Seal

A trust seal you can place on your website showing that the domain is scanned by an Approved Scanning Vendor. It is designed to give visitors a reason to trust a checkout they have not used before.

The seal is included with every scanning subscription at no extra cost. Read more about the site seal.

Which service do you need?

Most merchants who take card payments online need the quarterly ASV scan, and that is the place to start. If your bank or assessor has asked for evidence of compliance, that is what they mean.

Add penetration testing if your assessor has asked for requirement 11.4, or if you handle enough card data that an annual test is worth the cost on its own merits.

Use the free payment page check any time, whether you are a customer or not. It is the quickest way to see what a checkout page is actually loading.

Add payment page monitoring if your checkout loads scripts you do not control, which is nearly every checkout, or if you have been asked for the script inventory in requirement 6.4.3. Run the free check first. If it comes back with third party scripts on the page, that list is the thing monitoring keeps current.

Still unsure? Our frequently asked questions cover the common cases, and our support team will tell you honestly if you need less than you think.

Pricing at a glance

Service Price
PCI ASV Scanning, quarterly $59 per quarter, per IP address
PCI ASV Scanning, annual $188 per year, per IP address
Penetration Testing Quoted per project
Free Payment Page Check Free, no sign-up
Payment Page Monitoring $24 per quarter or $77 per year on its own, or $20 a quarter added to a scanning subscription
Security Verified Site Seal Included with any scanning subscription

We guarantee our work. If your site cannot pass our PCI compliance scan and our support team cannot get you there, we refund your order in full. See our refund policy for details, or go straight to pricing.