PCi

PCI Assessments Center

Loading your workspace…

PCiPCI Assessments Center
Glossary · PCI DSS v4.0.1

ASV — Approved Scanning Vendor

An Approved Scanning Vendor (ASV) is an organisation approved by PCI SSC to perform the external vulnerability scans required by PCI DSS Requirement 11.3.2.

What it means in practice

External scans must run at least once every three months and must achieve a passing result under the ASV Program Guide.
Internal vulnerability scans under Requirement 11.3.1 do not need an ASV, but do need qualified and organisationally independent personnel.

Not sure how this affects your assessment?

The free SAQ selector walks the official PCI SSC v4.0.1 decision flow, records every answer and re-derives the recommendation server-side with a confidence score.

Definitions paraphrased from the PCI DSS v4.0.1 standard and the PCI SSC Glossary of Terms, Abbreviations and Acronyms. Independent summary; not endorsed by PCI SSC.