Merchants ask this every quarter: “We pass our ASV scan. Why do we also need a penetration test?” The answer is in the standard. PCI DSS Requirement 11.3 covers vulnerability scanning, including the quarterly external scan by an Approved Scanning Vendor. Requirement 11.4 covers penetration testing. They are separate requirements with separate evidence, and neither one satisfies the other. This guide explains what each is, what each finds, and what happens when a company treats them as interchangeable.
What an ASV scan is
An ASV scan is an automated external vulnerability scan of your internet-facing PCI systems, run by a company on the PCI Security Standards Council’s list of Approved Scanning Vendors, using a scanning solution the Council has validated. Requirement 11.3.2 requires one at least every three months, with rescans until a passing result, and after any significant change (11.3.2.1). The scan is unauthenticated and non-intrusive: it fingerprints services, checks versions against known vulnerabilities, tests for a defined set of configuration weaknesses, and produces a pass or fail against the ASV Program Guide’s criteria.
Requirement 11.3.1 separately requires internal vulnerability scans at least every three months, authenticated where possible, with high-risk and critical findings remediated and rescanned. Internal scans do not have to be run by an ASV. Our managed vulnerability scanning covers that side.
What a PCI penetration test is
A penetration test under Requirement 11.4 is a manual engagement by a qualified, independent tester who tries to break in, from outside (11.4.3) and from inside (11.4.2), against the network layer and the application layer, following a documented methodology (11.4.1), with exploitable findings fixed and retested (11.4.4) and segmentation tested on its own schedule (11.4.5, and every six months for service providers under 11.4.6). The full requirement is explained in PCI DSS penetration testing requirements.
Side by side
| ASV scan (11.3.2) | Penetration test (11.4) | |
|---|---|---|
| Who performs it | A PCI SSC Approved Scanning Vendor | A qualified, organizationally independent tester (internal or external firm) |
| How | Automated, unauthenticated, from the internet | Manual, with tooling, from outside and inside, authenticated where in scope |
| Cadence | At least every 3 months, and after significant changes | At least every 12 months, and after significant changes; segmentation every 12 months (6 for service providers) |
| Scope | Internet-facing PCI systems | The entire CDE perimeter and critical systems, network and application layers, segmentation controls |
| What it finds | Known vulnerabilities by version, exposed services, weak configurations, certificate problems | Exploitable chains, authorization flaws, business logic abuse, segmentation failures, what an attacker can actually reach |
| Output | Pass/fail attestation for the acquirer | A report with findings, evidence, remediation, and a retest; an attestation letter for the QSA |
| Retest | Rescan until passing | Retest of remediated findings required (11.4.4) |
| Evidence for | Requirement 11.3.2 | Requirement 11.4 |
What the scan finds that the test does not
Scale and cadence. A scan looks at every host every quarter and catches the new vulnerability in a version you forgot you were running. A penetration test happens once a year and goes deep rather than wide. The two are complementary because vulnerabilities are published every day and a test cannot be run every day; the scan is the cheap, frequent check that keeps the perimeter from drifting between tests.
What the test finds that the scan does not
Almost everything that causes a cardholder data breach:
- Authorization flaws in the payment application. A scanner cannot tell that order ID 1042 belongs to someone else. This is the top item in the OWASP API Security Top 10 and invisible to any scan.
- Business logic abuse. Price manipulation, coupon stacking, refund flows that do not check ownership.
- Chained findings. Two medium-severity scan results that together give administrative access. A scan lists them separately; a tester connects them and proves it.
- Segmentation failures. Whether an attacker on the guest wireless network can reach the payment server. A scan from the internet never looks.
- Credential and identity weaknesses. Default credentials, password reuse, missing MFA on remote access, Active Directory attack paths.
- Whether detection fires. A tester’s report says what your monitoring saw. A scan does not know.
The data says these are the paths that matter: exploitation of vulnerabilities started 31% of breaches in 2025 and a third party was involved in 48%, while 62% involved the human element. (Verizon 2026 Data Breach Investigations Report) The scan covers part of the first number. The test covers all three.
What goes wrong when they are confused
- Passing scans, failed RoC. The QSA asks for the 11.4 penetration test reports, and there are none. The company has four clean ASV attestations and no evidence for the requirement that matters.
- A scan report labeled “penetration test.” Some vendors sell an automated scan with a report template as a pentest. The report has no methodology, no manual findings, no segmentation test and no retest; a QSA recognizes it in the first page.
- The penetration test used to satisfy the quarterly scan. It cannot: 11.3.2 requires an ASV, and a test does not happen quarterly.
- Segmentation assumed from the diagram. The scan cannot test it. Only a penetration tester starting from the wrong side of the firewall can. This is the most common 11.4 finding in a first assessment.
What a compliant year looks like
| When | What |
|---|---|
| Every quarter | ASV external scan (11.3.2) and internal vulnerability scan (11.3.1), rescans to passing |
| Once a year | External penetration test (11.4.3) and internal penetration test (11.4.2), retest of findings (11.4.4) |
| Once a year (merchants) or every six months (service providers) | Segmentation penetration test (11.4.5 / 11.4.6) |
| After every significant change | Rescan and retest as the methodology defines |
Frequently asked questions
Can our penetration tester also run the ASV scan? Only if the firm is a PCI SSC Approved Scanning Vendor. Most penetration testing firms, including us, are not, and the two purchases are normally separate.
Does a passing ASV scan mean we are secure? It means no known vulnerabilities in the ASV criteria were detected from the internet on that day. It says nothing about the application’s authorization logic, the internal network, or segmentation.
How much does each cost? ASV scanning is priced by the ASV, usually per IP per year. Our fixed penetration testing prices for each 11.4 component are on the PCI penetration testing cost page.
Do we need both if we outsource payments to a hosted page? Your scope may shrink to an SAQ that requires only the ASV scan. Confirm with your acquirer; if any system in your control can affect cardholder data security, 11.4 still applies.
The short version
The ASV scan is the quarterly, automated, external check the standard requires under 11.3. The penetration test is the annual, manual, inside-and-outside engagement it requires under 11.4. Both are mandatory, they find different things, and the one most companies are missing is the second. Our PCI DSS penetration testing page explains how we deliver it; scope a test to get the price in writing.
Written by
Invadel Team
Senior penetration testers writing from real engagements, the same team that scopes, tests, and reports for our clients. About Invadel →