Definition · Known Vulnerabilities (CVEs)
What is ASV Scan?
An Approved Scanning Vendor (ASV) is an organisation the PCI Security Standards Council has qualified to perform the external vulnerability scans that PCI DSS requires. Both the vendor and its scan solution go through the Council’s approval process, and the vendor’s staff must include qualified personnel who review results rather than forwarding raw scanner output.
How the process works
The merchant or service provider supplies the external IP addresses and domains in scope, the ASV scans them, and the ASV produces a report in the Council’s prescribed format — an attestation, an executive summary and detailed findings. The scan customer is responsible for confirming that the scope covers every internet-facing component of the cardholder data environment; an ASV cannot certify what it was never pointed at.
Passing, and disputing
An ASV scan is graded, not merely reported. The ASV Program Guide — not the vendor and not the customer — defines which findings are failing conditions, and the report must show no failing items for the scan to pass. Some categories fail automatically regardless of scoring, for example the presence of injection flaws or of services that should not be internet-facing at all.
Where a finding is a false positive or is compensated for by another control, the customer can raise a dispute with evidence. The ASV assesses it and, if accepted, may mark the item as an exception for that scan. Rescans after remediation are normal: the quarterly requirement is for a passing scan, so a failing scan followed by fixes and a clean rescan within the period is the usual route.
Why pre-scanning helps
Nothing in the programme stops you from finding the same issues first. Discovering unknown assets, closing unnecessary TCP ports, fixing weak cipher suites and patching known CVEs before the ASV arrives turns a failing scan and a rescan cycle into a single pass.
Related concepts
See PCI DSS external scanning for where the requirement sits in the standard, and vulnerability management, service fingerprinting and network segmentation for the practices that shape what an ASV sees.