Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

For the external PCI DSS vulnerability scan, choose a provider currently listed by the PCI Security Standards Council (PCI SSC) as an Approved Scanning Vendor (ASV), and confirm it will use its approved ASV scan solution for Requirement 11.3.2. Then compare scan coverage, administration, reporting, remediation and rescan support, and recurring-scan ownership. Internal scanning is a separate activity: a general-purpose scanner does not automatically satisfy the external ASV requirement, and a passing ASV report does not certify your overall PCI DSS compliance.

Do you need an ASV scan for PCI DSS?

PCI DSS requires internal and external vulnerability scans at least once every three months. Findings must be addressed and rescanned as part of the process. For the external scan under Requirement 11.3.2, the scan must be performed by a PCI SSC-listed ASV using that vendor’s approved ASV scan solution. See PCI SSC FAQ 1152 on scan frequency and the PCI SSC ASV program information.

That qualification is specific to the external ASV scan. Internal vulnerability scanning supports the entity’s own process for identifying vulnerabilities and ranking risks; it is not a substitute for the separate ASV requirement. PCI DSS describes the internal and external scanning requirements in its overview of PCI DSS, and its guidance on risk-ranking vulnerabilities explains the internal risk-ranking role.

How to compare ASV services and internal scanners

There are two related but distinct needs. Compare them by purpose before looking at product features.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
FortiGate-40F Firewall Appliance - 5 Gigabit Ethernet RJ45 Ports, Ideal for Small Businesses (Appliance Only, No Subscription) (FG-40F)
  • Compact and Efficient Design: The FortiGate 40F is designed for small to mid-sized businesses and enterprise branch offices, featuring a compact, fanless desktop form factor that ensures quiet operation and minimizes space usage.
  • Robust Connectivity Options: Equipped with 5 GE RJ45 ports, including 1 WAN port and 4 internal ports, this model provides essential connectivity and flexibility for various network configurations in a small-scale environment.
  • High-Performance Security: Offers up to 1 Gbps IPS throughput and 600 Mbps threat protection throughput, using Fortinet’s purpose-built security processor technology to deliver industry-leading performance and protection for SSL encrypted traffic.
  • Advanced Threat Protection: Integrated with Fortinet’s AI-powered FortiGuard Labs, the FortiGate 40F offers comprehensive cybersecurity, identifying and mitigating both known and unknown threats to maintain robust security across your network.
  • Simplified Management and Deployment: Features a user-friendly management console that provides comprehensive network automation and visibility, coupled with Zero Touch Integration with Fortinet’s Security Fabric for easy deployment.
Capability ASV service and approved scan solution Internal vulnerability scanning
Primary scope External, public-facing assets in the approved ASV scan workflow Internal environment, to support vulnerability identification and risk ranking
Qualification Provider must be currently listed by PCI SSC as an ASV; the provider’s approved solution must be used for Requirement 11.3.2 No ASV qualification is established as the requirement for internal scanning; use qualified internal staff or a third party appropriate to the entity’s process
Cadence At least once every three months; remediation and rescanning are part of the process At least once every three months; remediation and rescanning are part of the process
Evidence use ASV report documents the external scanning requirement; it does not establish overall PCI DSS compliance Results inform the entity’s vulnerability and risk-ranking process

The cadence and roles are described in PCI SSC FAQ 1152, the PCI DSS overview, and its risk-ranking FAQ. The Council’s ASV program page describes ASV qualification and listing. Do not assume one general-purpose scanner covers both needs.

What to check before choosing an ASV

Verify current listing and scope

Check the provider against the current PCI SSC ASV listing before purchase; listings can change. Confirm that the public-facing assets you need scanned can be included in the provider’s approved ASV workflow, and ask how targets are identified and kept current. The Council’s ASV program information describes the listing and qualification framework.

Rank #2
FortiGate-60F Network Security Appliance Plus 1 Year FortiGuard Unified Threat Protection (UTP) and FortiCare Premium (FG-60F-BDL-950-12)
  • HARDWARE PLUS SECURITY SERVICES: FortiGate-60F Firewall Appliance bundled with 1 year of FortiCare Premium and FortiGuard Unified Threat Protection.
  • UNIFIED THREAT PROTECTION (UTP): Secures against advanced online threats with comprehensive web filtering and anti-botnet technologies.
  • OPTIMIZED FOR MEDIUM-SIZED BUSINESSES: Tailored for businesses needing robust security without the infrastructure of larger enterprises.
  • RELIABLE CUSTOMER SUPPORT: FortiCare Premium ensures high-quality support and service continuity.
  • EFFECTIVE PROTECTION: Employs advanced filtering technologies to safeguard against sophisticated threats.

Ask how scan administration works

PCI SSC assesses scan administration as part of ASV qualification. Ask how the service handles target setup, scan preparation, scheduling, changes to public-facing assets, and requests for rescans. These are practical comparison questions, not capabilities that can be assumed to be identical across providers. The Council’s ASV program guidance outlines its qualification areas.

Understand findings and remediation support

ASV qualification includes testing whether a solution can find vulnerabilities and misconfigurations on the Council’s test infrastructure. Ask how findings are explained, prioritized or routed to the people who can fix them, and how a rescan is requested to verify remediation. The organization remains responsible for its environment and fixing findings; a service can assist with the workflow but does not take over that responsibility. PCI SSC’s scan-frequency guidance describes remediation and rescanning as part of the process in FAQ 1152.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
GL.iNet GL-MT5000 Brume 3 Wired VPN Security Gateway NO Wi-Fi
  • 【Up to 1100 Mbps VPN Speed 】 Hardware-accelerated WireGuard and OpenVPN-DCO deliver up to 1100 Mbps VPN throughput, over 3× faster than Brume 2 for smooth remote access and file transfers.
  • 【Three 2.5G Ports & Multi-WAN】Tri-port 2.5GbE design with flexible WAN LAN configuration supports multi-gigabit wired setups, dual-ISP Multi-WAN and failover to keep home and SOHO networks online.
  • 【Stealth VPN Obfuscation】VPN obfuscation disguises VPN traffic as regular HTTPS, helping you evade blocking, bypass restrictive networks and maintain stable, private connections.
  • 【DPI protection】Deep Packet Inspection with visual dashboards blocks adult/gambling/malicious sites, while SQM and QoS prioritize gaming, calls, and video when bandwidth is tight
  • 【OpenWrt & USB 3.0 Expansion】OpenWrt with 1GB DDR4 and 8GB eMMC lets you install plugins and build VPN, ad-blocking or NAS, while USB 3.0 Type‑C connects high-speed storage or 4G/5G dongles

Review report quality and evidence handling

PCI SSC tests ASV report output and requires official report templates. Ask to see a sample report and clarify how any supplemental certificate or letter is labeled relative to the official report. Confirm who retains the report and what your acquirer or other program stakeholders expect you to submit. PCI SSC explains report limitations in FAQ 1234; its SAQ workflow FAQ addresses the broader self-assessment process.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Does an ASV report mean you are PCI DSS compliant?

No. An ASV report is evidence for the external scanning requirement, not proof that the rest of PCI DSS has been reviewed or met. PCI SSC states: “this scan report is not an indication that any other PCI DSS requirements have been reviewed or are in place.” The statement appears in FAQ 1234, dated June 2025. Acquirers and payment brands may request scan reports or other documents, so confirm submission expectations with whoever manages your compliance program.

Rank #4
Ubiquiti Cloud Gateway Ultra (UCG-Ultra)
  • Runs UniFi Network for full-stack network management
  • Manages 30+ UniFi Network devices and 300+ clients
  • 1 Gbps routing with IDS/IPS
  • Multi-WAN load balancing
  • 0.96" LCM status display

Does outsourced payment processing remove the scan requirement?

Not necessarily. PCI SSC’s June 2026 FAQ says PCI DSS v4.x SAQ A includes Requirement 11.3.2 ASV scanning for covered e-commerce merchant webpages even when payment processing is outsourced to a third-party service provider. The FAQ specifically covers pages that redirect a transaction to the provider and pages that embed the provider’s payment page in an iframe. Check the current FAQ and the applicable SAQ instructions against your actual scope: PCI SSC FAQ 1604 on SAQ A and outsourced processing.

Build recurring scans into operations

Assign an owner for quarterly scheduling, changes to scanned assets, missed-scan escalation, remediation follow-up, report retention, and rescan requests. PCI SSC says periodic controls cannot be made timely by running them later and backdating the result; a missed period needs to be treated as missed, not retroactively cured. See PCI SSC FAQ 1572 on missed periodic activities. The ASV program page also says successful vendors undergo annual recertification, another reason to confirm current listing status rather than relying on an old procurement record.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.