- An ASV scan proves a point in time. It does not prove the next ninety days.
- New hostnames, forgotten staging IPs, and cloud misconfigurations appear between quarters.
- Treat scanning as an operating rhythm — inventory, scan, fix, retest — not as a certificate chase.
Passing an ASV scan still matters. For many merchants and service providers it is a contractual fact of life. The mistake is treating that PDF as a security posture rather than as a snapshot.
The internet-facing surface of a modern company is not a static /24. It is a set of DNS records, load balancers, cloud IPs, partner portals, and “temporary” test hosts that somehow never got decommissioned. Those change weekly. Quarterly scanning, done as a scramble before the QSA arrives, will always lag that reality.
The scan you passed in March does not know about the hostname marketing launched in April.
What the quarterly scan does not see
ASV programs are scoped to the cardholder-data environment’s internet presence. Scope debates are real, and they are where a lot of risk hides. A forgotten VPN concentrator, an old WordPress marketing site on the same brand domain, or a cloud bucket with a public ACL will not magically appear on last quarter’s target list.

- Shadow IT and abandoned subdomains that still resolve.
- Cloud IPs that rotate when an autoscaling group or CDN origin changes.
- Exceptions that were “temporary” during the last failing scan and never closed.
A better operating model
High-performing teams keep a living inventory of external assets, scan on a cadence that matches how often they ship, and treat remediation as a queue with owners — not as a week of panic before the ASV window. Retest is part of the same loop. A finding that is “accepted” without an expiry date is just an untracked hole.
A cadence that actually works
Weekly authenticated checks are not always realistic. What is realistic: refresh the external inventory continuously, scan internet-facing systems at least monthly, and re-scan the moment a production hostname or origin changes. Escalations should fire on new criticals, not on a human remembering to open the portal.
Make the next scan boring
The goal is not a heroic clean report once a year. It is a rhythm where the next scan is a continuation of last month’s work. If your last clean report is older than your last production deploy, update the inventory, scan what is actually live, and close what the last certificate never saw.
Keep going
Want this as a working program?
This article is a point of view. If you want to see how teams run it in practice, talk with us.
Talk to our team
