All posts
ComplianceJuly 28, 20267 min read

Why an Annual ASV Scan Is No Longer Enough

PCI still requires approved scanning. Attackers do not wait for the next quarter. Here is how teams close the gap between the certificate and the real network.

Tribal ResearchCompliance

Network cabling in a data center rack
  • An ASV scan proves a point in time. It does not prove the next ninety days.
  • New hostnames, forgotten staging IPs, and cloud misconfigurations appear between quarters.
  • Treat scanning as an operating rhythm — inventory, scan, fix, retest — not as a certificate chase.

Passing an ASV scan still matters. For many merchants and service providers it is a contractual fact of life. The mistake is treating that PDF as a security posture rather than as a snapshot.

The internet-facing surface of a modern company is not a static /24. It is a set of DNS records, load balancers, cloud IPs, partner portals, and “temporary” test hosts that somehow never got decommissioned. Those change weekly. Quarterly scanning, done as a scramble before the QSA arrives, will always lag that reality.

The scan you passed in March does not know about the hostname marketing launched in April.

What the quarterly scan does not see

ASV programs are scoped to the cardholder-data environment’s internet presence. Scope debates are real, and they are where a lot of risk hides. A forgotten VPN concentrator, an old WordPress marketing site on the same brand domain, or a cloud bucket with a public ACL will not magically appear on last quarter’s target list.

Developer reviewing security-related code on a laptop
New services ship faster than scan calendars. Inventory has to keep up.
  • Shadow IT and abandoned subdomains that still resolve.
  • Cloud IPs that rotate when an autoscaling group or CDN origin changes.
  • Exceptions that were “temporary” during the last failing scan and never closed.

A better operating model

High-performing teams keep a living inventory of external assets, scan on a cadence that matches how often they ship, and treat remediation as a queue with owners — not as a week of panic before the ASV window. Retest is part of the same loop. A finding that is “accepted” without an expiry date is just an untracked hole.

A cadence that actually works

Weekly authenticated checks are not always realistic. What is realistic: refresh the external inventory continuously, scan internet-facing systems at least monthly, and re-scan the moment a production hostname or origin changes. Escalations should fire on new criticals, not on a human remembering to open the portal.

Make the next scan boring

The goal is not a heroic clean report once a year. It is a rhythm where the next scan is a continuation of last month’s work. If your last clean report is older than your last production deploy, update the inventory, scan what is actually live, and close what the last certificate never saw.

PCI ASVVulnerability managementExternal attack surface

Keep going

Want this as a working program?

This article is a point of view. If you want to see how teams run it in practice, talk with us.

Talk to our team

Continue reading

Why an Annual ASV Scan Is No Longer Enough | Blogs