Qantid
Class BTechnical testingRenews

PCI ASV External Scanning

Quarterly external vulnerability scanning of your cardholder data environment, delivered through an Approved Scanning Vendor.

Fee & intake

Sign in to see the engagement fee (plus 7.5% VAT), complete the intake form, save a draft if you need to, then pay to submit.

Renews
Every 12 months

Regulatory and standards basis

This engagement is performed against the following instruments. Each is cited in the deliverable at the point it is relied on.

  • PCI DSS v4.0.1 Requirement 11.3.2
  • PCI SSC ASV Program Guide

Who this is for

  • Merchants and service providers in PCI scope

What you receive

  1. 01Four quarterly ASV scans with passing scan reports
  2. 02Remediation support between scans
  3. 03False positive dispute handling

How the engagement runs

  1. Phase 1

    Scope and authorisation

    You define targets and sign a Testing Authorisation Form. Every in-scope target must have verified ownership — DNS TXT record, well-known file, cloud role or written attestation — before any traffic is sent.

  2. Phase 2

    Preflight

    Targets are resolved, shared hosting is detected and flagged, and your emergency contact is notified that testing is beginning. Any gate failure aborts the run.

  3. Phase 3

    Automated testing

    An industry-standard toolchain is run against the verified scope, mapped to OWASP ASVS, MASVS or PCI DSS 11.4 as applicable. All raw output is retained.

  4. Phase 4

    Triage and manual validation

    Findings are deduplicated across tools and false positives eliminated with a recorded reason. Every critical and high finding is then reproduced and confirmed by a consultant, who also performs a scoped manual pass on business logic.

  5. Phase 5

    Reporting and retest

    You receive the report with reproduction steps and evidence, plus one free retest within 90 days.

Accreditation disclosure

Passing scan reports are issued by a PCI SSC Approved Scanning Vendor. Qantid manages the programme and remediation; the ASV signs the scan report.

Questions

Who approves the deliverable?

A named member of the engagement team reviews it and a partner approves it. Their name, title and credentials are printed on the report, and the approval is recorded against the engagement in the portal.

Who signs it?

Passing scan reports are issued by a PCI SSC Approved Scanning Vendor. Qantid manages the programme and remediation; the ASV signs the scan report.

Is this a manual or an automated test?

Both, and we are specific about the split. An automated toolchain covers known vulnerability classes — misconfiguration, known CVEs, injection, weak TLS, exposed services, dependency issues and secrets. A consultant then reproduces and confirms every critical and high finding, and performs a scoped manual pass on business logic: authentication flows, authorisation boundaries, insecure direct object references, workflow abuse and race conditions. We do not describe this as a fully manual test, because it is not.

What is explicitly not included?

This is not a load or stress test, not a social engineering assessment, not a physical security assessment, and not a source code review, unless you purchase those separately. Denial-of-service testing is never performed.

What do you need from us before testing starts?

A signed Testing Authorisation Form from someone with authority to give it, and proof of ownership for every in-scope target. We will also give you the static IP addresses our scanners egress from so you can allowlist them.

What happens next year?

The portal reminds you 90, 60 and 30 days before it is due, and you start a new version of this engagement pre-filled from the answers you gave last time. You update only what has changed, and you see a side-by-side of what changed before you submit.

Where do our documents live?

In private storage, accessible only through short-lived signed links, with every view and download logged. Nothing is attached to email. Our sub-processors and data residency are published on the trust page.

How do we pay?

By card through Stripe after you complete intake in the portal. You can save a draft without paying; submission happens only after payment succeeds.

Related engagements in Cybersecurity and Assurance

Business Continuity and Disaster Recovery Plan

Continuity and recovery planning built from a business impact analysis, with recovery objectives that reflect what your infrastructure can actually deliver.

CBN Risk-Based Cybersecurity Framework Assessment

An assessment against the CBN Risk-Based Cybersecurity Framework, producing the evidence base for your annual return.

Incident Response Plan and Playbooks

An incident response plan with scenario playbooks, written so an on-call engineer at 3am can follow it.