ASV pricing
Qualys PCI ASV cost 2026: no published price, and what drives the quote
Qualys is an Approved Scanning Vendor and publishes no price for the work. The page it does publish offers a free trial and routes to sales. What is knowable is the meter: ASV scanning is priced against the count of internet-facing IPs in scope, which is why renewal surprises are almost always footprint surprises. Count your in-scope IPs before the conversation, not after.
Updated July 2026
Published price
None
Free trial, then a sales conversation
The meter
Internet-facing IPs in scope
Count them before the renewal call
How it is sold
Inside the wider Qualys platform
What Qualys publishes, in its own words
Qualys describes the product plainly on its PCI ASV page: “As an Approved Scanning Vendor (ASV), Qualys has been authorized by the PCI Security Standards Council to conduct the quarterly scans required to show compliance with PCI DSS.” That is the whole of what is published about the service. There is no price attached to it. The page offers a free trial and routes to sales, and the Qualys listings on AWS Marketplace route to a private offer rather than a listed rate.
So this page carries no Qualys figure, because there is not one to carry. That is not a gap we are apologising for. It is the actual state of the market, and knowing it changes how you buy: if someone hands you a Qualys ASV number they did not get from Qualys against your own scope, they are guessing, and a guess at a vendor’s undisclosed price is worth nothing in a negotiation.
There is a structural reason the number is hard to pin down even from Qualys. ASV scanning is sold inside the wider Qualys platform rather than as a shelf product, so what you pay depends on what else you buy. For some buyers a standalone ASV price does not really exist as a product. That is worth knowing before you ask for one.
The meter: internet-facing IPs in scope
The mechanic that survives the absence of published pricing is the one that matters most. ASV pricing scales with the count of internet-facing IPs in scope. That single fact explains the most common renewal surprise in this category: the bill grew because the external footprint did. Nobody added a line item. The estate quietly got bigger, and the meter read it.
The defence is unglamorous and it works. Audit your internet-facing IP inventory on a schedule, quarterly at minimum. Take dead addresses out of scope rather than paying to scan them. Segment so the cardholder data environment stays small, which is the same behaviour PCI rewards everywhere else. And on any multi-year term, ask for threshold protection in writing so growth does not reprice you mid-contract. You do not need to know the bands to do any of that.
Do the count first. Walking into a scoping call already knowing how many external addresses you expose, which of them are live, and which you intend to retire is the difference between negotiating and being told.
Three deployment shapes
| Scenario | What the deployment contains | What decides the quote |
|---|---|---|
| Small e-commerce, a handful of internet-facing IPs | Standalone PCI ASV scanning, quarterly scans, Attestation of Compliance generation | The external target count, and whether rescans and disputes are included or metered |
| Mid-market SaaS, dozens of internet-facing IPs plus web apps | PCI ASV scanning across a larger external footprint, quarterly scans, compliance portal | Target count, the split between network targets and web applications, and scan frequency above the quarterly minimum |
| Enterprise, ASV inside the wider platform | PCI ASV as one capability alongside internal scanning, asset inventory, and integration with CMDB and ITSM tooling | Bundled versus standalone, total assets under management, modules in scope, and contract term |
No fee column, because Qualys publishes no fee. These are the shapes the deployment takes and the variables that move the number. Take them into the scoping call as your question list, and get the answers in writing against your own IP count.
The questions that decide your quote
How many external targets are in scope. This is the meter, so it is the first question and the one you should answer yourself before anyone answers it for you.
Network targets or web applications. They are scoped and tested differently, and a quote that blurs them is a quote you cannot compare with anyone else’s.
Are rescans and disputes included or metered. This one is quietly the most expensive detail on the list. Requirement 11.3.2 needs four passing scans a year, not four attempts. A first scan that fails is normal, and it is what happens next that decides whether you have bought compliance or bought four attempts at it. If rescans are metered, a bad quarter costs money as well as time. Ask explicitly, and ask the same about dispute handling, since false positives are routine and someone has to work them.
Scan frequency above the quarterly minimum. Quarterly is the floor, not the recommendation. Plenty of environments want monthly or continuous external scanning for reasons that have nothing to do with PCI, and that is a different product conversation with a different number attached.
Bundled or standalone. The biggest swing on the list. ASV inside a platform purchase and ASV on its own are not the same buy, and the honest starting point is whether you want the rest of the platform on its own merits.
Who attests. Scanning and attestation are not automatically the same line item, and the point of the exercise is the attestation. Confirm the ASV attests to the passing scan, and that the output is the document your acquirer actually wants.
When Qualys fits and when it does not
Qualys fits enterprises with existing or planned investment in the wider platform, where ASV scanning is one capability among several they were going to buy anyway. It fits organisations that need genuine enterprise-grade reporting, compliance automation, and integration with broader IT operations tooling such as CMDB, ITSM and SIEM. And it fits buyers who want vendor consolidation across PCI, ISO 27001, SOC 2, internal scanning and cloud security rather than a drawer full of point tools.
Qualys is the wrong shape for a small merchant who needs ASV scanning and nothing else. The mismatch is structural rather than a price gap anyone can quantify: Qualys sells a platform whose ASV scanning is one capability inside it, so a buyer with a handful of internet-facing addresses and one compliance obligation is buying a platform to use a corner of it. Vendors who sell PCI ASV as a standalone product are built for that buyer. Qualys is also a weak pick for anyone already consolidated on another vulnerability management platform internally, since the consolidation pitch is the whole argument and it falls flat when you have already consolidated somewhere else.
Negotiating with Qualys
Three tactics. First, bring your own IP count. The meter is the negotiation, and arriving with an audited, deliberately trimmed external inventory does more for the number than any amount of haggling over a rate you cannot see. Second, run a real competitive process against the other platform vendors and the standalone ASVs, because a credible alternative quote on your actual scope is the only leverage available when nobody publishes anything. Third, be honest with yourself about which product you need. If the requirement is quarterly ASV scanning of a small internet-facing footprint, say so, and price that against vendors who sell exactly that.
Then get the mechanics in writing: rescans and disputes included or metered, what triggers a scope true-up, and threshold protection across the term. Those clauses govern your worst case, and unlike a benchmark that does not exist, they are things Qualys can actually put in your contract.
Qualys on the PCI SSC ASV directory
Qualys is listed in the official PCI SSC Approved Scanning Vendor directory.
Frequently asked
Qualys does not publish a price for it. The PCI ASV page on qualys.com offers a free trial and routes to sales, and the AWS Marketplace listings route to a private offer rather than a listed rate, so there is no published figure to quote and we have not invented one. The mechanic behind the quote is knowable, though, and it is the thing worth acting on: ASV pricing scales with the count of internet-facing IPs in scope. That is why the most common renewal surprise is a bill that grew because the external footprint did. Count your in-scope IPs before the renewal conversation, not after it.
Continue reading
Tenable PCI cost
The per-asset model, and what it means if you already run Nessus.
Rapid7 PCI cost
ASV scanning bought alongside InsightVM.
SecurityMetrics ASV cost
The one ASV that puts any price in public.
PCI scanning + pen test cost
The full ASV plus pen test market.
Level 2 PCI cost
What changes at 1M to 6M transactions per year.
SAQ D cost
What the full-scope self-assessment actually involves.