Approved Scanning Vendor ASV

Someone who determines if an organization is compliant with PCI DSS external scanning requirements.

Back to Glossary

An Approved Scanning Vendor is someone who determines whether an organization meets PCI DSS external scanning requirements.

ASVs perform an external vulnerability scan of an organization’s network or website from the outside looking inward, using similar methods to hackers, such as penetration testing. In addition to determining if it is PCI DSS compliant, these scans from service providers can provide insight into any data security changes that need to be made and can help organisations ensure firewalls are operating correctly, avoiding data breaches.

All compliant companies need a quarterly network scan by an Approved Scanning Vendor (ASV). A list of these can be found here.