ASV pricing
Rapid7 PCI compliance cost 2026: the ASV comes from MegaplanIT
Rapid7 does not attest your PCI scan. In its own words: “Rapid7 partners with MegaplanIT, a third-party ASV partner, which means we can help you achieve compliance with PCI DSS.” InsightVM is a capable vulnerability scanner, it is just not the entity that signs your attestation. Rapid7 publishes no price for PCI ASV, so what follows is the shape of the deal rather than a number.
Updated July 2026
Who attests
MegaplanIT
Rapid7’s third-party ASV partner, not Rapid7
Published ASV price
None
InsightVM pricing page shows no ASV price
Pricing model
Per-asset, Insight platform bundled
Read this before you read anything else about Rapid7 and PCI
Rapid7 is not an approved scanning vendor. It says so itself, on its retail industry page: “Rapid7 partners with MegaplanIT, a third-party ASV partner, which means we can help you achieve compliance with PCI DSS.” That single sentence is worth more to a buyer than any price, because it changes what you are buying. The attestation on your quarterly external scan, the document your acquirer actually wants, comes from MegaplanIT.
This is not a knock on the scanner. InsightVM finds the same classes of issue an ASV scan looks for, and if you run it for internal vulnerability management it is doing real work. But Requirement 11.3.2 is not satisfied by finding vulnerabilities. It is satisfied by an approved scanning vendor attesting that your internet-facing footprint passed. Those are different jobs. A buyer who signs for InsightVM assuming the attested quarterly report falls out of it has bought a good tool and not the compliance artefact.
So the first question on the first call is not what it costs. It is which legal entity is the ASV of record, whether your contract is with Rapid7 or with the partner, and who you raise a dispute with at quarter end. Look up whichever name you are given in the PCI SSC Approved Scanning Vendor directory, and get it into the contract.
Why there is no price here
Rapid7 publishes no price for PCI ASV. Its InsightVM pricing page carries no ASV price and does not mention ASV. There is no rate card behind that, no list price, nothing to quote. A figure invented for this page would land in your head as “Rapid7 ASV costs about that much”, and you would carry it into a negotiation as if it were a fact. It would not be one, so it is not here.
What is knowable is what the number is built from. Ask for the quote broken out along these lines and you can check the arithmetic yourself:
- External targets in scope. This is the meter the product runs on. Not your total asset count, the internet-facing subset that carries or protects cardholder data.
- Network targets versus web applications. These are usually priced differently. Get the split before you get the total.
- Rescans and disputes: included or metered. Requirement 11.3.2 needs four passing scans a year, not four attempts. If rescans meter, your real annual cost depends on how clean your estate is, which is a fact about you, not about the vendor.
- Scan frequency above the quarterly minimum. Many buyers want monthly. That is a choice, not an obligation, and it is priced.
- Bundled or standalone. Whether the ASV line is priced inside the platform deal or beside it changes what you can negotiate and what you can drop later.
- Who attests. The partner arrangement means the answer is not automatically the company on the invoice.
Three deployment shapes
| Scenario | What the deployment actually contains |
|---|---|
| Small e-commerce, PCI-only, roughly a dozen assets | InsightVM entry tier for internal scanning, plus the partner ASV engagement for quarterly external scans and the attestation. Two relationships, two portals. For a buyer whose only requirement is the attestation, this is a platform purchase to reach a feature the platform vendor does not itself perform. |
| Mid-market SaaS already running InsightVM, roughly 80 assets | The vulnerability management platform is already justified for non-PCI reasons and already operated daily. The ASV requirement is an increment on top of it, routed through the partner. Internal authenticated scanning is the thing you are actually paying InsightVM for; the attestation is a bolt-on. |
| Enterprise fintech consolidating the Insight platform | InsightVM plus InsightIDR (SIEM) plus InsightAppSec plus InsightCloudSec, bought as one platform decision. PCI ASV is a rounding error inside this conversation and should not drive it. Judge the consolidation on the security operations case, then handle the attestation separately. |
The useful comparison between these shapes is not fee against fee. It is whether the platform underneath is justified by something other than PCI, because that is the question the ASV line cannot answer for you.
The Insight platform consolidation economics
Rapid7's economic argument is platform consolidation. The Insight platform unifies vulnerability management (InsightVM), SIEM and XDR (InsightIDR), application security testing (InsightAppSec), cloud security posture management (InsightCloudSec), and threat intelligence (Threat Command). Whether that beats assembling point vendors is a calculation only you can run, and it is not one we can run for you: it depends on which modules you would genuinely deploy, at what asset count, against quotes that none of these vendors publish. Be sceptical of any figure that claims otherwise, including a vendor's. Consolidation savings are quoted against a best-of-breed stack the buyer usually would not have bought in full.
The consolidation argument matters most at the tier where the integration overhead of running multiple point vendors becomes operationally meaningful: enough tools that somebody's week is spent moving findings between consoles. At that tier the bundle is usually priced to win the platform decision rather than the individual product decision, which is worth knowing when you decide what to put in the scope.
The consolidation argument does not work for buyers who only need PCI ASV. It is the wrong fit twice over: you would be buying a platform to reach one requirement, and the platform vendor is not the one who signs the attestation for it. Vendors who are themselves approved scanning vendors and sell ASV standalone are built around exactly that job. For larger buyers genuinely evaluating platform consolidation, the Rapid7 conversation is worth having on its own merits.
When Rapid7 wins and when it does not
Rapid7 wins for buyers consolidating multiple security operations point products onto a single platform, for buyers who specifically want SIEM (InsightIDR) plus vulnerability management from one vendor, and for buyers transitioning from on-premise Nexpose to cloud-delivered InsightVM. In all three cases the reason to buy is the security operations case, and the PCI attestation rides along through the partner rather than driving the decision.
Rapid7 does not win for buyers who only need PCI ASV, because Rapid7 is not the ASV: you would buy a vulnerability management platform and still get your attestation from MegaplanIT. It also does not win for buyers already standardised on another vulnerability management platform, where forced migration is rarely justified by a PCI line item, or for buyers who specifically want best-of-breed point products in each security capability category.
Negotiating with Rapid7
Three tactics. First, settle the attestation question before the commercial one: which entity is the ASV of record, who holds the contract, who runs the dispute queue, and what the turnaround is when a false positive is blocking a passing scan at quarter end. That is the part of the deal that will actually cost you something, and it is cheapest to fix before signature. Second, if you genuinely want several modules, negotiate them as one conversation rather than sequentially, because a vendor competing for a platform decision has more to play with than one adding a line to an existing account. The corollary matters more: do not add modules to the scope for leverage you will pay for annually. Third, run a real competitive process on your actual external footprint. In a market with no published prices, an alternative quote is the only pressure that exists.
Separate the compliance requirement from the platform ambition in your own head before the first call. The PCI obligation is quarterly external scanning attested by an approved vendor. Everything else in the proposal is a choice you are making for other reasons, and it should survive being priced on its own.
For multi-year contracts, negotiate asset-count flexibility explicitly. Per-asset pricing models have tier-step jumps, and locking the asset-band pricing through the contract term is the most valuable cost-control clause. Do the same for the external target count on the ASV line, because that count grows quietly every time somebody stands up a new subdomain.
Check who actually attests your scan
The PCI SSC Approved Scanning Vendor directory is the authoritative list. Look up the entity named in your proposal before you sign.
Frequently asked
No. Rapid7 reaches PCI ASV scanning through a partner. In Rapid7's own words, on its retail industry page: "Rapid7 partners with MegaplanIT, a third-party ASV partner, which means we can help you achieve compliance with PCI DSS." The attestation on your quarterly external scan comes from MegaplanIT, the approved scanning vendor, not from Rapid7. This matters if you are buying InsightVM expecting an attested quarterly scan report to fall out of it. InsightVM is a capable vulnerability scanner and it will find the same classes of issue an ASV scan looks for, but finding them and attesting them are different jobs done by different entities. Check the PCI SSC Approved Scanning Vendor directory for whichever name is proposed to you, and get the attesting entity written into the contract.
Continue reading
Qualys PCI ASV cost
Per-IP standalone pricing read.
Tenable PCI cost
An ASV that has you run the scan, then attests it.
SecurityMetrics ASV cost
One published price, for one narrow bundle.
PCI scanning + pen test cost
The full ASV plus pen test market.
v4 vs v3 cost delta
Authenticated scanning is mandatory.
2026 outlook
What changes in PCI cost this year.