Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minutePC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Include every system that is in scope for your PCI DSS assessment, and map the internal and externally reachable systems separately. The right scan population depends on your payment environment and validation path—not on a universal list of IP addresses. Internal scans and external ASV scans have different performer and follow-up rules, and a scan report by itself does not establish PCI DSS compliance.
How to determine what belongs in scan scope
Start with the systems included in the entity’s applicable PCI DSS assessment. The scan population should cover all of those in-scope systems, with findings handled through the required remediation and rescan process. PCI SSC’s guidance on quarterly vulnerability scans describes the general expectation as passing scans covering all in-scope systems. The exact assets depend on the entity’s environment and assessment context; a generic IP checklist cannot determine scope for every merchant.
- Identify the applicable validation path. Determine which PCI DSS assessment and SAQ, if any, apply to the entity. Use the requirements and scoping guidance for that path rather than assuming every payment setup has the same scan obligations.
- Establish the in-scope system population. Use the assessment scope to identify the systems that must be included. Do not omit a system merely because payment processing is partly or wholly handled by a service provider; check the specific requirements that apply to the merchant’s pages and environment.
- Separate internal and external scan populations. Identify which in-scope systems are internal and which are externally reachable, then apply the relevant scan track to each. The external asset scope must also be addressed through the applicable ASV process.
- Keep the population connected to follow-up. Track findings, remediation, and required rescans against the same in-scope systems so that unresolved issues or omitted assets do not disappear from the assessment process.
Internal scans and external ASV scans are different requirements
PCI DSS Requirement 11.3.1 covers internal vulnerability scans; Requirement 11.3.2 covers external vulnerability scans. Both are due at least once every three months, but the required performer and follow-up differ.
| Scan track | Requirement | Who performs it | Cadence | Follow-up |
|---|---|---|---|---|
| Internal vulnerability scans | 11.3.1 | Qualified personnel who are organizationally independent of the systems being scanned. A QSA or ASV is not required. | At least once every three months. | Resolve high-risk and critical vulnerabilities, then rescan to confirm resolution. Keep the scan tool current. |
| External vulnerability scans | 11.3.2 | A PCI SSC Approved Scanning Vendor (ASV). | At least once every three months. | Remediate and rescan as needed to meet ASV Program Guide passing criteria. |
For internal scans, qualification and independence matter: PCI SSC’s SAQ D material gives a network administrator responsible for the network as an example of someone who should not be responsible for scanning that network. External scans, by contrast, must be performed by an ASV. Do not treat an internal scanning tool or an internal scan report as a substitute for the external ASV requirement.
#1 Best Overall
Cadence, remediation, and passing-scan evidence
PCI SSC says quarterly scans should be conducted as close to three months apart as possible. Its FAQ 1087 states that 90 days is the maximum time that should pass between quarterly scans. If an unforeseen event disrupts a planned scan, conduct it as soon as possible.
Scanning is a cycle, not a calendar-only task. Run the required scan, address the findings according to the applicable requirement, and perform rescans where required to confirm resolution or meet the ASV passing criteria. For external scans, PCI SSC’s FAQ 1152 says a passing scan generally has no automatic-fail condition and no vulnerability with a CVSS score of 4.0 or higher. Apply the current ASV Program Guide and assessment requirements rather than relying on a generic interpretation of a score.
Rank #2
FAQ 1152 describes the general evidence pattern as passing scans at least once every three months for the four previous quarters, covering all in-scope systems and following through with necessary remediation and rescans. Assessment-path-specific details can matter, so check the SAQ and current PCI DSS standard that apply to the entity.
SAQ A e-commerce merchants may still need an ASV scan
Outsourcing payment processing does not automatically remove a merchant’s external scanning responsibility. PCI SSC’s June 2026 SAQ A guidance says that merchants with e-commerce pages that redirect transactions to a compliant third-party service provider, or contain that provider’s embedded payment page or form, have ASV scanning responsibilities for those merchant webpages.
Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Repair Windows errors before they cause bigger problems3Fix the driver behind crashes, sound loss and screen glitchesRank #3
- 【Wi-Fi Network Connection】NetumScan wifi barcode scanner can connect to Wi-Fi TCP, UDP and other network protocols, support Internet MQTT/HTTP protocol, and enable cloud server data transmission.
- 【Bluetooth Data Transfer】Bluetooth barcode scanner can be directly applied to Android, iOS, Windows, Mac OS system devices, support HID, BLE and SPP (secondary development) modes data transmission.
- 【Powerful Barcode Recognition】Wireless 2d barcode scanner supports mainstream 1D and 2D barcode scanning, such as QR code, Data Matrix, PDF 417, FedEx, USPS, VIN, etc. It can scan barcodes from different media, not only printed barcodes, but also screen barcodes.
- 【Convenient and Rechargeable】NetumScan barcode scanner comes with a charging cradle, providing power at any time, ensuring full-day work. When it is out of range reading in Auto Mode, the scanned data will be automatically saved to the scanner memory buffer and transmitted to the host when back to the wireless coverage.
- 【Small and Sturdy】NetumScan barcode reader is suitable for all-day use, with a battery life of up to 40 hours per charge. It has a rugged design, dust-proof and moisture-proof. Moreover, the built-in long-life trigger guarantees a continuous productivity of 10 million times, for the best reliability. This scanner can be used in the most practical way according to different scanning tasks, in various solutions such as retail, warehousing, manufacturing, logistics, etc.
The PCI SSC resource guide published in 2024 explains the rationale: compromise of the merchant page could affect its connection to the third party’s payment page. This clarification is specific to the described merchant-page cases. For another payment arrangement, check the applicable SAQ and current PCI SSC guidance rather than assuming the same conclusion applies.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.A scan report is not proof of overall PCI DSS compliance
An ASV report documents vulnerability-scan results; it does not certify that the entity meets every PCI DSS requirement. PCI SSC FAQ 1234, published June 2025, states: “The ASV will produce a scan report that details the results of the vulnerability scan — this scan report is not an indication that any other PCI DSS requirements have been reviewed or are in place.”
Rank #4
Use scan results as evidence for the scan requirement, alongside the rest of the assessment evidence. Ask the acquirer or relevant payment brand what report-submission expectations apply. If selecting an external scanning service, verify that the provider is currently listed by PCI SSC as an ASV and clarify the external asset scope for the assessment.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

