Get Demo
↑

PCI DSS ASV Scans: Quarterly External Scan Requirements and How to Pass

PCI DSS v4.0.1 Requirement 11.3.2 - quarterly ASV external vulnerability scans, pass criteria (CVSS), rescans, and SAQ A applicability.

Published: September 2026 Compliance · PCI DSS 8-12 min read

Requirement 11.3.2 requires external vulnerability scans by a PCI SSC Approved Scanning Vendor at least once every three months, with vulnerabilities resolved until the ASV Program Guide passing criteria are met - plus scans after significant changes (11.3.2.1).

Related: Requirement 11 · QSA vs ISA vs ASV · Segmentation testing · SAQ A.

Gotcha: Internal vulnerability scanning (11.3.1) is separate from ASV external scanning (11.3.2). Passing an ASV scan does not satisfy penetration testing (11.4.x) or segmentation testing (11.4.5 / 11.4.6).

What 11.3.2 Requires

After Significant Change (11.3.2.1)

External vulnerability scans are also performed after any significant change, covering affected system components as specified in the requirement.

How to Pass (ASV Program Guide)

SAQ A Callout

For PCI DSS v4.x, ASV requirements were added to SAQ A for e-commerce systems hosting redirect or embedded TPSP payment pages - see the PCI SSC ASV Resource Guide (July 2024) and the SAQ A guide.

Scope Practice

The scan customer confirms in-scope IPs and domains. The ASV performs discovery and lists additional components identified. A dispute and false-positive process exists for contested findings.

How CyberSilo Helps

Map PCI DSS v4.0.1 Controls to Continuous Evidence

CyberSilo CSA and ThreatHawk SIEM help US merchants and service providers collect QSA-ready evidence across SAQ and ROC validation paths.

Frequently Asked Questions

What score fails an ASV scan?

Generally a CVSS Base score of 4.0 or higher, plus listed automatic failures - then rescan until you pass.

Do I need four passing scans before my first ROC?

An initial assessment may accept fewer if the latest scan is passing and policy and remediation evidence exist; thereafter maintain quarterly passing scans.

Can any vulnerability scanner brand be used?

For 11.3.2 compliance attestation, the scanner must be a PCI SSC-listed ASV using an approved ASV scan solution.

Requirement 11 · QSA vs ISA vs ASV · Segmentation testing · SAQ A · PCI hub

📰 More from CyberSilo

Latest Articles

Stay ahead of evolving cyber threats with our expert insights

✅ Link copied!