The PCI DSS conversation almost everyone has before signing is about the assessment itself: scoping, evidence, sampling, the ROC or SAQ. The conversation almost nobody has ahead of time is about what happens in between, because the requirements that run between assessments don’t have a dramatic kickoff moment. They just run, quietly, all year.
What Is an Approved Scanning Vendor (ASV)?
An Approved Scanning Vendor is a company PCI SSC has certified to perform the external vulnerability scans PCI DSS requires on a quarterly basis. An ASV scan is separate from your annual assessment. It’s a standing, recurring requirement for any organization storing, processing, or transmitting cardholder data, and PCI SSC maintains a public list of qualified vendors, currently numbering in the mid-80s.
What runs between assessments
Quarterly external vulnerability scans, performed by a PCI SSC Approved Scanning Vendor, are a separate, standing requirement, not a nice-to-have. PCI DSS 4.0.1 has also pushed the standard further toward continuous compliance generally, with more requirements framed around ongoing operation rather than a once-a-year snapshot. None of that shows up in the same conversation as the annual report, and it’s easy for it to fall through the gap between “our QSA handles PCI” and “who’s actually watching the scans.”
The scanning cadence, specifically
An Approved Scanning Vendor runs external vulnerability scans on a 90-day cycle, and PCI SSC maintains a list of roughly 85 approved vendors qualified to perform them. That’s a standing obligation independent of your annual ROC or SAQ, one that keeps running whether or not anyone’s actively thinking about it that quarter. A missed or failed scan doesn’t wait for your next assessment to become a problem.
What “continuous” changed
PCI DSS 4.0.1 introduced targeted risk analyses and a customized approach to meeting certain requirements, both of which assume an organization is actively monitoring and adjusting its own controls, not just producing evidence once a year that they existed at some point. That shift puts more weight on what happens between assessments than earlier versions of the standard did.
What Happens If a Quarterly Scan Fails?
A failed ASV scan doesn’t automatically mean a security incident, but it does mean the finding has to be remediated and the scan re-run until it passes clean, and that cycle has to complete within the quarter it’s due, not whenever it’s convenient. Falling behind on scanning cadence is one of the more common ways companies drift out of compliance between annual assessments, not because of a single dramatic failure, but because a missed quarter turns into two, and nobody’s tracking the gap until the next ROC or SAQ comes due and the evidence isn’t there.
Internal Scanning Matters Too, Just Differently
External ASV scanning gets the most attention because it’s the piece with a named vendor and a fixed cadence, but PCI DSS also expects internal vulnerability scanning on a regular basis, and that piece doesn’t require an Approved Scanning Vendor, it can be done in-house or by whichever QSA firm supports the engagement. The distinction is worth knowing, because a QSA who only ever asks about the external ASV report is only checking half of what actually keeps a CDE monitored between assessments.
How ASV Scanning Relates to Penetration Testing
ASV scanning and penetration testing aren’t the same requirement, and confusing them is a common way companies think they’re covered when a gap actually exists. Quarterly ASV scans are automated, external vulnerability scans focused on identifying known vulnerabilities across your internet-facing systems. PCI DSS separately requires penetration testing, at least annually and after any significant change, which is a more manual, exploit-driven exercise testing whether an identified weakness can actually be leveraged. A vendor who only ever discusses scanning cadence with you may not be the same one responsible for making sure the penetration testing requirement is met on its own schedule, and it’s worth confirming which firm owns which piece rather than assuming one covers both.
What Counts as In-Scope for Quarterly Scanning?
Not every system on your network needs to be scanned quarterly, only those that are part of, or directly connected to, your cardholder data environment. That sounds simple until your environment changes: a new payment integration, a cloud migration, or a third-party service added mid-year can quietly expand what belongs in scope for the next scan cycle without anyone updating the scanning configuration to match. An ASV can only scan what it’s told is in scope, which means the accuracy of that scope definition is really on you and whichever firm is helping you maintain it, not something the scan itself catches if it’s wrong. A QSA who revisits your scope definition alongside each quarterly cycle, rather than only at the annual assessment, is more likely to catch that kind of drift before it becomes a gap in your evidence.
Where the quality of the relationship shows up
This is where a QSA firm’s day-to-day habits matter more than what’s on the engagement letter. Does a finding from a quarterly scan get flagged to you as it’s found, or does it wait for the next scheduled check-in? Is ASV scanning something the same firm coordinates, or a separate vendor relationship you’re managing on your own? None of this gets asked in an RFP, because it’s hard to evaluate before you’ve lived through a few quarters with a vendor.
What this means for how you think about “done”
There’s a temptation to treat the signed AOC as the finish line and everything after as maintenance. It’s a reasonable instinct, and it’s incomplete. The months between assessments are where most of an actual PCI DSS relationship plays out, and they’re worth as much attention when you’re choosing a QSA as the initial engagement is.
An assessor who treats the time between reports as real, ongoing work, not a formality until next year’s kickoff call, isn’t just easier to work with. They’re the reason a finding gets caught in month four instead of month eleven, which is often the difference between a quick fix and a scramble right before your next assessment is due.
Common Questions About PCI DSS Scanning and Continuous Compliance
How often is a PCI ASV scan required? PCI DSS requires external vulnerability scans by an Approved Scanning Vendor at least once every 90 days, independent of when your annual assessment happens.
What changed with PCI DSS 4.0.1 and continuous compliance? PCI DSS 4.0.1 introduced a customized approach and targeted risk analyses for certain requirements, both of which assume ongoing monitoring and adjustment rather than a once-a-year demonstration that a control existed at some point.
Does my QSA handle ASV scanning too? Not automatically. ASV scanning and the annual QSA assessment can be handled by the same firm or by separate vendors, so it’s worth confirming which applies to your engagement.
Is internal vulnerability scanning also required? Yes. PCI DSS requires internal scanning on a regular basis in addition to quarterly external ASV scans, though internal scanning doesn’t require an Approved Scanning Vendor and can be performed in-house or by your QSA firm.
Contact us to talk through your ongoing PCI DSS program, or learn more about how Insight Assurance supports the full cycle, not just the annual report.
