Scanning & testing

PCI ASV scanning and penetration testing cost

Two of the most-bought line items in any PCI programme. ASV scans run quarterly. Pen tests run annually. Both are required. Here is the rate card.

Updated April 2026

ASV vulnerability scanning

Quarterly external scans of every internet-facing IP, run by a vendor on the PCI SSC's Approved Scanning Vendor list. Pricing scales with IP count and support level.

ASV vendorPer quarterIP rangeNotes
SecurityMetrics$100-$3001-10 IPsMost popular for small merchants. Includes compliance portal.
Qualys$200-$8001-256 IPsEnterprise-grade. Scales well. Strong vulnerability management integration.
Tenable (Nessus)$250-$6001-128 IPsBest for organisations already using Nessus for internal scanning.
Trustwave$200-$5001-64 IPsAlso offers managed security services and pen testing.
Rapid7$300-$7001-128 IPsGood integration with InsightVM for internal scanning.
Intruder$150-$4001-20 IPsModern interface. Good for smaller environments.

Penetration testing

PCI DSS Requirement 11 mandates annual external and internal penetration tests, plus segmentation validation if you use network segmentation to reduce scope. Pricing scales with scope, methodology, and firm tier.

Test typeCost rangeFrequencyCost factors
External Network Penetration Test$5,000 - $30,000AnnualNumber of external IPs, services exposed, complexity
Internal Network Penetration Test$5,000 - $20,000AnnualNetwork size, number of VLANs, segmentation complexity
Web Application Penetration Test$5,000 - $15,000Annual + after significant changesApplication complexity, number of roles, APIs, authentication flows
Segmentation Validation Test$3,000 - $10,000Every 6 months (if segmentation used)Number of segments, network topology complexity
Wireless Penetration Test$3,000 - $8,000AnnualNumber of locations, wireless networks, physical security

For deeper figures, see our dedicated pen testing cost reference.

ASV scan vs pen test vs vulnerability scan

Three terms that get used interchangeably and are not the same. PCI DSS 4.0 requires all three, with different cadences and different evidence outputs.

ActivityWho runs itFrequencyTypical cost
External ASV scanPCI SSC Approved Scanning VendorQuarterly$100 - $800 / quarter
Internal vulnerability scanIn-house or third partyQuarterly (authenticated under 4.0)$2,000 - $15,000 / year
Penetration test (external)Pen test firmAnnual + after significant change$5,000 - $30,000
Penetration test (internal)Pen test firmAnnual$5,000 - $20,000
Segmentation validationPen test firmEvery 6 months (if segmentation used)$3,000 - $10,000

Need to start scanning today?

The PCI SSC publishes a public directory of every Approved Scanning Vendor with current PCI certification. Use it as your filter, not vendor sales pages.

Open the ASV directory

Frequently asked

Approved Scanning Vendor scans run $100 to $800 per quarter depending on the number of IPs and the vendor. Annual cost typically lands at $400 to $3,200. SecurityMetrics is the cheapest for small merchants. Qualys, Tenable, Rapid7, and Trustwave price higher and offer more detailed reporting. The PCI SSC maintains the official ASV directory.

Continue reading