Skip to main content

What an ASV does, and why Requirement 11.3.2 admits nobody else

Requirement 11.3.2 is the only requirement in PCI DSS Requirement 11 that names a credential. Requirement 11.3.2.1, the post-change external scan, deliberately does not.

By Abhinav A
August 20, 20266 min read

An Approved Scanning Vendor is a company PCI SSC has qualified to scan the internet-facing parts of a cardholder data environment and declare the result a pass or a fail. It is the only credential PCI DSS v4.0.1 names anywhere in Requirement 11, and 11.3.2 is the only requirement in Requirement 11 that cannot be met through the customised approach.

That answers the question most people are really asking: whether the scanner they already own, their cloud provider's vulnerability service or their existing supplier can produce the quarterly external scan. For 11.3.2, no. For 11.3.2.1, the external scan after a significant change, yes, and the standard says so in a parenthesis almost nobody quotes.

What Requirement 11.3.2 says

Verbatim from PCI DSS: Requirements and Testing Procedures, v4.0.1 (June 2024), external vulnerability scans are performed as follows:

  • At least once every three months.
  • By a PCI SSC Approved Scanning Vendor (ASV).
  • Vulnerabilities are resolved and ASV Program Guide requirements for a passing scan are met.
  • Rescans are performed as needed to confirm that vulnerabilities are resolved per the ASV Program Guide requirements for a passing scan.

Where its neighbours carry a customised approach objective, 11.3.2 carries this instead: "This requirement is not eligible for the customized approach." It is the only requirement in Requirement 11 that does. No alternative design and no in-house equivalent satisfies it. The credential is the requirement.

"Every three months" means 90 to 92 days

PCI DSS defines its own timeframes rather than borrowing the calendar. Table 4 defines "every three months (quarterly)" as "at least once every 90 to 92 days, or on the nth day of each third month", and states the intent plainly: the activity happens "at an interval as close to that timeframe as possible without exceeding it". Scan on 5 January and again on 28 April and you have scanned in two different calendar quarters while overrunning the interval by three weeks. Days are the unit, and this is the commonest way a complete-looking scan history fails.

What a passing scan actually means

The standard does not define it. It defers: vulnerabilities are resolved and "ASV Program Guide requirements for a passing scan are met". The pass and fail rules live in the ASV Program Guide, which PCI SSC revises separately — which is why 11.3.2 reads as a reference rather than a threshold.

What you receive is two artefacts, not one. The Qualification Requirements for Approved Scanning Vendors oblige every ASV to report on the current PCI SSC template and add: "Each ASV scan report must be accompanied by an Attestation of Scan Compliance in the form then available in Appendix A of the ASV Program Guide." The attestation is the summary; the report is the evidence beneath it. A tool export with no attestation is not an ASV scan.

A failed scan followed by a passing rescan inside the window is normal, not a blemish: testing procedure 11.3.2.b has the assessor examine "the ASV scan report from each scan and rescan run in the last 12 months". Keep the failures; they are evidence. A first assessment is the one relaxation, where four passing scans are not required if the most recent one passed and earlier findings were corrected in a rescan.

Some of the work is unavoidably yours. The standard puts target-environment specifics — load balancers, third-party providers, ISPs, protocols in use, scan interference — on the scan customer to settle with the ASV. An ASV cannot know which of your public addresses belong to the cardholder data environment. Declaring them is your job, and an incomplete target list is the surest way to hold a worthless passing scan.

How to choose one

The useful checks trace to a published document rather than to a sales conversation. The clauses below are from Qualification Requirements for Approved Scanning Vendors, v3.0 (February 2017).

CheckThe clause behind it
Are they on the ASV List?§1.3: "If a security company is not on this list, its work product is not recognized by PCI SSC."
Is their entry red?§5.3: an ASV in Remediation has its listing "appear in red". It may still scan, but against a remediation period of typically 90 days
When do they requalify?§5.2.1: annually, subject to fees, training, a passing annual ASV Lab Scan Test and "satisfactory feedback from the ASV Company's Scan Customers". The ASV must tell you the PCI SSC ASV Feedback Form exists; unfavourable feedback alone can trigger remediation
Do they also supply or manage your controls?§2.2.1: if the ASV developed, owns, configured or manages a firewall, IDS/IPS, encryption, logging, file-integrity or anti-virus solution you use, it "must fully disclose" that "in a separate document attached to each applicable scan report"
Does remediation advice only point at their own products?§2.2.1: recommending its own solution obliges an ASV to "also recommend other market options that exist", and it must not "state or imply that the PCI DSS … requires use of the ASV Company's products or services"

11.3.2.1, the external scan that admits everybody else

Immediately after it, the standard adds a second external scanning requirement with a different trigger and a different rule on who may perform it. External vulnerability scans are performed after any significant change as follows:

  • Vulnerabilities that are scored 4.0 or higher by the CVSS are resolved.
  • Rescans are conducted as needed.
  • Scans are performed by qualified personnel and organizational independence of the tester exists (not required to be a QSA or ASV).
11.3.211.3.2.1
TriggerAt least once every three monthsAfter any significant change
Who may perform itA PCI SSC Approved Scanning VendorQualified personnel with organisational independence — "not required to be a QSA or ASV"
Bar for successVulnerabilities resolved, ASV Program Guide requirements for a passing scan metVulnerabilities scored 4.0 or higher by the CVSS resolved
Customized approachNot eligibleEligible — the requirement carries a customised approach objective

The parenthesis is not peculiar to 11.3.2.1. It appears in six requirements across v4.0.1 — 11.3.1.3, 11.3.2.1, 11.4.2, 11.4.3, 11.4.5 and 11.4.6 — of which 11.3.2.1 is the only one about external scanning. Across the family, 11.3.2 is the exception; the open door is the rule.

It also reaches the smallest merchants. The SAQ Instructions and Guidelines record that "to mitigate these common breaches, Requirements 11.3.2 and 11.3.2.1 are included in SAQ A" — the questionnaire filed by fully outsourced e-commerce merchants whose payment page redirects to a compliant third party or embeds one. See which SAQ applies to you.

Significant changes are frequent. PCI DSS says what must at minimum be evaluated as one: new or replaced hardware, software or networking equipment in the CDE; any change to the flow or storage of account data, to the CDE boundary or to assessment scope; any change to supporting infrastructure such as directory services, time servers or logging; and any change to the third-party providers supporting the CDE. Move on that list more often than every 90 days and 11.3.2.1 fires between ASV scans — and it does not wait for the next quarterly window, because the good-practice note ties it to the change itself, performed "as part of the change process and before the change is considered complete".

Two requirements, one credential

11.3.2 is closed. No customised approach, no in-house equivalent, no substitute supplier — the only decisions left are which ASV, against what declared target list, and how tightly the 90-day interval is held. 11.3.2.1 is open, names no credential, and an entity that changes faster than quarterly will meet it more often than it meets 11.3.2.

Neither is a penetration test. Requirement 11.4 is a separate obligation with its own frequency and its own rule on who may perform it, and a passing ASV scan discharges no part of it — see ASV scan, internal scan and penetration test compared.

About the author

Abhinav A

Lead — VAPT & Security Assessments

Leads Security Brigade's VAPT delivery team, having progressed from Security Consultant to Team Lead. Has executed advanced penetration tests across BFSI, fintech, QSR, and telecom — including ICICI Bank, Domino's, and Jubilant FoodWorks.