Recommended Free Tools
The settings that matter depend on the scan’s purpose: internal vulnerability scanning under PCI DSS Requirement 11.3.1, external ASV scanning under 11.3.2, or a web-application scan. Keep those workflows distinct. For internal scans, configure authentication where systems support it; for an external PCI scan, use the vendor’s designated ASV workflow and a PCI SSC-listed ASV. Neither a PCI-labelled template nor a passing scan report proves full PCI DSS compliance.
Start by identifying the required scan
PCI DSS separates internal vulnerability scans from external vulnerability scans conducted by an Approved Scanning Vendor (ASV). A web-application scan is a separate workflow where applicable; it does not replace either required vulnerability scan.
| Scan purpose | What to configure | Key distinction |
|---|---|---|
| Internal vulnerability scan, Requirement 11.3.1 | Use an internal scan workflow and enable authenticated scanning where required. Provide sufficient privileges for thorough detection. | Credentials belong in the internal workflow, not in the external ASV scan. |
| External vulnerability scan, Requirement 11.3.2 | Use the vendor’s ASV scan solution through a PCI SSC-listed ASV; include the complete applicable external scope and ensure it is reachable. | A general vulnerability-management scan is not automatically an ASV scan. |
| Web-application scan | Use an appropriate web-application scanning workflow where applicable. | It is distinct from the internal and external vulnerability-scanning workflows. |
PCI SSC describes internal and external vulnerability scans at least once every three months, with remediation and rescanning as needed. For external scans, FAQ 1152 describes the general passing characteristic as having no CVSS score of 4.0 or higher and no automatic failure: PCI SSC FAQ 1152. Apply the criteria in the applicable ASV process to the actual report.
Set scope, reachability, and cadence before tuning options
Include the systems that belong in scope
For an external scan, verify that all in-scope internet-facing systems, public IP addresses, and relevant DNS names are included. Qualys recommends discovering active public IPs before defining scope. Network controls may need to allow the scanner’s external IP addresses to reach the in-scope components; otherwise, a scan can miss assets or fail to test them as intended. See Qualys PCI merchant guidance.
#1 Best Overall
Keep scans close to three months apart
“Quarterly” does not mean that a scan can be scheduled at any point in a calendar quarter regardless of the previous scan date. PCI SSC says scans should be as close to three months apart as possible, with 90 days the maximum interval: PCI SSC FAQ 1087. Track the date of each scan and leave room for operational delays.
Configure internal scans for authenticated coverage
PCI DSS Requirement 11.3.1.2 calls for authenticated internal vulnerability scans. Credentials need sufficient privileges to reach the resources necessary for thorough detection. Systems that cannot accept credentials require documented exceptions, and accounts used for scanning must be managed appropriately, including where they can be used for interactive logins. PCI SSC states that this requirement became mandatory after 31 March 2025; see the PCI DSS v4.0 SAQ D for Service Providers.
In Qualys, the configuration pattern is to create authentication records containing credentials for target IPs and enable authentication in the option profile actually used by the scan. Merely storing credentials is not enough if authentication is disabled in that profile. In Tenable, use the internal PCI scan workflow and configure credentials there so the scanner can enumerate issues such as missing patches and client-side vulnerabilities.
Choose the vendor workflow that matches the purpose
Qualys
For quarterly external PCI scanning, Qualys VM documentation identifies the Payment Card Industry (PCI) Options profile. Check that the right assets and DNS names are selected and that scanner traffic can reach them. For authenticated internal scanning, configure target authentication records and enable authentication in the scan’s option profile. These are vendor workflow choices; PCI DSS specifies required outcomes and evidence, not one universal setting for every Qualys profile. See Qualys VM option profiles.
Tenable
Tenable provides an Internal PCI Network Scan template for internal Requirement 11.3.1 scanning and a PCI Quarterly External Scan template for external Requirement 11.3.2 scanning. Its separate PCI web-application template applies where web-application scanning is appropriate. Tenable’s ASV scan instructions say not to configure credentials for PCI ASV scans: those scans represent an external threat perspective, and credentials alter the scan intent and can cause complications or PCI failures. Keep authentication in the internal workflow. See Tenable PCI scanning guidance.
Tenable’s Advanced Settings show Safe Checks enabled by default; Tenable describes it as disabling plugins that may adversely affect the remote host. Template performance defaults differ between internal and external scans. Treat these as operational defaults, not PCI DSS requirements. Tenable also says ASV results follow their own rules, so do not assume general recast rules change PCI ASV results. The relevant template and settings guidance is in Tenable’s PCI scanning documentation.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Handle results, remediation, and evidence correctly
Review whether the report covers the intended scope and whether its results satisfy the applicable scanning requirements. Remediate findings and rescan as needed; retain the scan results and evidence of remediation and rescanning. Do not treat a vendor’s generic “PCI” label as proof that a scan followed the ASV process, or as a substitute for validating the ASV’s status and scan solution.
A passing ASV report is not a certification of the rest of the environment. PCI SSC explains: “The ASV will produce a scan report that details the results of the vulnerability scan — this scan report is not an indication that any other PCI DSS requirements have been reviewed or are in place.” See PCI SSC FAQ 1234 (June 2025).
Free tools Windows power users keep installed
One-click scans. No signup required.
Check whether the ASV requirement applies to your SAQ
Applicability depends on the merchant’s actual SAQ and environment. PCI SSC FAQ 1604 says SAQ A for PCI DSS v4.x includes external ASV scanning for covered merchant e-commerce pages that redirect customers to a third-party processor or embed the processor’s payment iframe, even when payment processing is outsourced. That example should not be generalized to every merchant; confirm the applicable SAQ and scope with the relevant assessment guidance. See PCI SSC FAQ 1604.
Quick Recap
Common configuration mistakes
- Using an authenticated internal profile for an external ASV scan, or adding credentials to Tenable’s PCI ASV workflow against its instructions.
- Leaving in-scope internet-facing CDE systems, public addresses, or relevant paths out of the external scan scope.
- Assuming that a generic PCI-labelled scan means the vendor is acting as the ASV for that scan.
- Scheduling scans more than 90 days apart or failing to retain remediation and rescan evidence.
- Treating defaults such as Tenable Safe Checks or performance settings as PCI DSS requirements.
- Reading an ASV scan report as proof that all PCI DSS requirements have been assessed.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

