ASV Vulnerability Scanning
PCI DSS Requirement 11.3.2 asks for quarterly external vulnerability scans performed by a PCI SSC Approved Scanning Vendor. This page explains what that means and what we are building — scan scheduling is not available yet.
- We are not an Approved Scanning Vendor. Under Requirement 11.3.2 the quarterly external scan is only valid when it comes from a vendor listed by the PCI Security Standards Council, so this will always be a partnership with an ASV rather than a scan we run ourselves.
- Available today: the SSL/TLS scanner, which tests transport encryption against Requirement 4.2.1 and returns a pass or fail per control with the evidence behind it.
Vendors we plan to integrate with
These are the scanning vendors we intend to support first. Nothing is connected yet. Always confirm a vendor's current ASV status on the PCI Security Standards Council website before engaging them — listings change.
Key Features
- InsightVM scanning
- Real-time dashboards
- API integration
Integration planned — not yet available.
Key Features
- VMDR platform
- Continuous monitoring
- Compliance reporting
Integration planned — not yet available.
Key Features
- Nessus scanning
- Risk-based prioritization
- Asset discovery
Integration planned — not yet available.
What we intend to build
The workflow we are aiming for once an ASV partnership is in place. None of it is live today.
Planned
- Quarterly scan scheduling
- Comprehensive port scanning
- Service enumeration
- Vulnerability identification
Planned
- ASV directory access
- Provider comparison tools
- Automated scan coordination
- Compliance verification
Planned
- ASV scan report generation
- Compliance status tracking
- Historical scan data
- Executive summary reports
Planned
- CVSS scoring integration
- Risk-based vulnerability ranking
- Remediation recommendations
- Patch management guidance
Quarterly Scanning
Perform quarterly external vulnerability scans by approved scanning vendor (ASV).
External Network Scanning
Scan all externally accessible IP addresses and services for vulnerabilities.
Compliance Documentation
Generate required ASV scan reports for PCI compliance validation.
Want this when it ships?
Tell us and we will let you know. In the meantime you can engage an ASV directly, and use our SSL/TLS scanner for Requirement 4.2.1 today.