An ASV scan is an external vulnerability scan of a merchant's internet-facing systems, run by a company PCI SSC has specifically certified as an Approved Scanning Vendor. It's how a merchant demonstrates compliance with PCI DSS Requirement 11.3.2, which calls for external scanning at least once a quarter, plus again after any significant change to the environment.
Who actually needs one
Only SAQ types that include Requirement 11: SAQ A, A-EP, B-IP, C, and D. That covers any merchant with even a limited externally-facing footprint — including SAQ A merchants who just have a redirect or iframe checkout page. SAQ B, C-VT, P2PE, and SPoC merchants are off the hook here, since those environments don't have a persistent, merchant-owned, externally-scannable IP presence.
Key things to tell a merchant
It has to be run by a PCI SSC-certified ASV — merchants can't self-administer this scan the way they might for internal scanning.
The ASV controls the scan configuration, severity levels, and report — the merchant can only initiate/schedule it and define what's in scope. Getting scope right (accurate and complete) is on the merchant.
Network segmentation can shrink what's in scope significantly — isolating the cardholder data environment from everything else reduces cost and complexity.
One failing scan isn't the end of the world. Rescans are expected, and multiple scan reports across the quarter can be combined to show everything in scope eventually came back clean.
Keep scan reports on file — three years, in line with the ASV Program Guide — since acquirers or payment brands may ask for them as evidence.
Internal scans are a different animal
Internal vulnerability scanning (Requirement 11.3.1) is recommended with similar rigor but doesn't have to be performed by an ASV — qualified internal or independent personnel can handle it. Don't let a merchant confuse the two.
