ASV pricing

Rapid7 PCI compliance cost 2026: the ASV comes from MegaplanIT

Rapid7 does not attest your PCI scan. In its own words: “Rapid7 partners with MegaplanIT, a third-party ASV partner, which means we can help you achieve compliance with PCI DSS.” InsightVM is a capable vulnerability scanner, it is just not the entity that signs your attestation. Rapid7 publishes no price for PCI ASV, so what follows is the shape of the deal rather than a number.

Updated July 2026

Who attests

MegaplanIT

Rapid7’s third-party ASV partner, not Rapid7

Published ASV price

None

InsightVM pricing page shows no ASV price

Pricing model

Per-asset, Insight platform bundled

Read this before you read anything else about Rapid7 and PCI

Rapid7 is not an approved scanning vendor. It says so itself, on its retail industry page: “Rapid7 partners with MegaplanIT, a third-party ASV partner, which means we can help you achieve compliance with PCI DSS.” That single sentence is worth more to a buyer than any price, because it changes what you are buying. The attestation on your quarterly external scan, the document your acquirer actually wants, comes from MegaplanIT.

This is not a knock on the scanner. InsightVM finds the same classes of issue an ASV scan looks for, and if you run it for internal vulnerability management it is doing real work. But Requirement 11.3.2 is not satisfied by finding vulnerabilities. It is satisfied by an approved scanning vendor attesting that your internet-facing footprint passed. Those are different jobs. A buyer who signs for InsightVM assuming the attested quarterly report falls out of it has bought a good tool and not the compliance artefact.

So the first question on the first call is not what it costs. It is which legal entity is the ASV of record, whether your contract is with Rapid7 or with the partner, and who you raise a dispute with at quarter end. Look up whichever name you are given in the PCI SSC Approved Scanning Vendor directory, and get it into the contract.

Why there is no price here

Rapid7 publishes no price for PCI ASV. Its InsightVM pricing page carries no ASV price and does not mention ASV. There is no rate card behind that, no list price, nothing to quote. A figure invented for this page would land in your head as “Rapid7 ASV costs about that much”, and you would carry it into a negotiation as if it were a fact. It would not be one, so it is not here.

What is knowable is what the number is built from. Ask for the quote broken out along these lines and you can check the arithmetic yourself:

  • External targets in scope. This is the meter the product runs on. Not your total asset count, the internet-facing subset that carries or protects cardholder data.
  • Network targets versus web applications. These are usually priced differently. Get the split before you get the total.
  • Rescans and disputes: included or metered. Requirement 11.3.2 needs four passing scans a year, not four attempts. If rescans meter, your real annual cost depends on how clean your estate is, which is a fact about you, not about the vendor.
  • Scan frequency above the quarterly minimum. Many buyers want monthly. That is a choice, not an obligation, and it is priced.
  • Bundled or standalone. Whether the ASV line is priced inside the platform deal or beside it changes what you can negotiate and what you can drop later.
  • Who attests. The partner arrangement means the answer is not automatically the company on the invoice.

Three deployment shapes

ScenarioWhat the deployment actually contains
Small e-commerce, PCI-only, roughly a dozen assetsInsightVM entry tier for internal scanning, plus the partner ASV engagement for quarterly external scans and the attestation. Two relationships, two portals. For a buyer whose only requirement is the attestation, this is a platform purchase to reach a feature the platform vendor does not itself perform.
Mid-market SaaS already running InsightVM, roughly 80 assetsThe vulnerability management platform is already justified for non-PCI reasons and already operated daily. The ASV requirement is an increment on top of it, routed through the partner. Internal authenticated scanning is the thing you are actually paying InsightVM for; the attestation is a bolt-on.
Enterprise fintech consolidating the Insight platformInsightVM plus InsightIDR (SIEM) plus InsightAppSec plus InsightCloudSec, bought as one platform decision. PCI ASV is a rounding error inside this conversation and should not drive it. Judge the consolidation on the security operations case, then handle the attestation separately.

The useful comparison between these shapes is not fee against fee. It is whether the platform underneath is justified by something other than PCI, because that is the question the ASV line cannot answer for you.

The Insight platform consolidation economics

Rapid7's economic argument is platform consolidation. The Insight platform unifies vulnerability management (InsightVM), SIEM and XDR (InsightIDR), application security testing (InsightAppSec), cloud security posture management (InsightCloudSec), and threat intelligence (Threat Command). Whether that beats assembling point vendors is a calculation only you can run, and it is not one we can run for you: it depends on which modules you would genuinely deploy, at what asset count, against quotes that none of these vendors publish. Be sceptical of any figure that claims otherwise, including a vendor's. Consolidation savings are quoted against a best-of-breed stack the buyer usually would not have bought in full.

The consolidation argument matters most at the tier where the integration overhead of running multiple point vendors becomes operationally meaningful: enough tools that somebody's week is spent moving findings between consoles. At that tier the bundle is usually priced to win the platform decision rather than the individual product decision, which is worth knowing when you decide what to put in the scope.

The consolidation argument does not work for buyers who only need PCI ASV. It is the wrong fit twice over: you would be buying a platform to reach one requirement, and the platform vendor is not the one who signs the attestation for it. Vendors who are themselves approved scanning vendors and sell ASV standalone are built around exactly that job. For larger buyers genuinely evaluating platform consolidation, the Rapid7 conversation is worth having on its own merits.

When Rapid7 wins and when it does not

Rapid7 wins for buyers consolidating multiple security operations point products onto a single platform, for buyers who specifically want SIEM (InsightIDR) plus vulnerability management from one vendor, and for buyers transitioning from on-premise Nexpose to cloud-delivered InsightVM. In all three cases the reason to buy is the security operations case, and the PCI attestation rides along through the partner rather than driving the decision.

Rapid7 does not win for buyers who only need PCI ASV, because Rapid7 is not the ASV: you would buy a vulnerability management platform and still get your attestation from MegaplanIT. It also does not win for buyers already standardised on another vulnerability management platform, where forced migration is rarely justified by a PCI line item, or for buyers who specifically want best-of-breed point products in each security capability category.

Negotiating with Rapid7

Three tactics. First, settle the attestation question before the commercial one: which entity is the ASV of record, who holds the contract, who runs the dispute queue, and what the turnaround is when a false positive is blocking a passing scan at quarter end. That is the part of the deal that will actually cost you something, and it is cheapest to fix before signature. Second, if you genuinely want several modules, negotiate them as one conversation rather than sequentially, because a vendor competing for a platform decision has more to play with than one adding a line to an existing account. The corollary matters more: do not add modules to the scope for leverage you will pay for annually. Third, run a real competitive process on your actual external footprint. In a market with no published prices, an alternative quote is the only pressure that exists.

Separate the compliance requirement from the platform ambition in your own head before the first call. The PCI obligation is quarterly external scanning attested by an approved vendor. Everything else in the proposal is a choice you are making for other reasons, and it should survive being priced on its own.

For multi-year contracts, negotiate asset-count flexibility explicitly. Per-asset pricing models have tier-step jumps, and locking the asset-band pricing through the contract term is the most valuable cost-control clause. Do the same for the external target count on the ASV line, because that count grows quietly every time somebody stands up a new subdomain.

Check who actually attests your scan

The PCI SSC Approved Scanning Vendor directory is the authoritative list. Look up the entity named in your proposal before you sign.

Search the ASV directory

Frequently asked

No. Rapid7 reaches PCI ASV scanning through a partner. In Rapid7's own words, on its retail industry page: "Rapid7 partners with MegaplanIT, a third-party ASV partner, which means we can help you achieve compliance with PCI DSS." The attestation on your quarterly external scan comes from MegaplanIT, the approved scanning vendor, not from Rapid7. This matters if you are buying InsightVM expecting an attested quarterly scan report to fall out of it. InsightVM is a capable vulnerability scanner and it will find the same classes of issue an ASV scan looks for, but finding them and attesting them are different jobs done by different entities. Check the PCI SSC Approved Scanning Vendor directory for whichever name is proposed to you, and get the attesting entity written into the contract.

Continue reading