Scanning & testing
PCI ASV scanning and penetration testing cost
Two of the most-bought line items in any PCI programme. ASV scans run quarterly. Pen tests run annually. Both are required. Here is the rate card.
Updated April 2026
ASV vulnerability scanning
Quarterly external scans of every internet-facing IP, run by a vendor on the PCI SSC's Approved Scanning Vendor list. Pricing scales with IP count and support level.
| ASV vendor | Per quarter | IP range | Notes |
|---|---|---|---|
| SecurityMetrics | $100-$300 | 1-10 IPs | Most popular for small merchants. Includes compliance portal. |
| Qualys | $200-$800 | 1-256 IPs | Enterprise-grade. Scales well. Strong vulnerability management integration. |
| Tenable (Nessus) | $250-$600 | 1-128 IPs | Best for organisations already using Nessus for internal scanning. |
| Trustwave | $200-$500 | 1-64 IPs | Also offers managed security services and pen testing. |
| Rapid7 | $300-$700 | 1-128 IPs | Good integration with InsightVM for internal scanning. |
| Intruder | $150-$400 | 1-20 IPs | Modern interface. Good for smaller environments. |
Penetration testing
PCI DSS Requirement 11 mandates annual external and internal penetration tests, plus segmentation validation if you use network segmentation to reduce scope. Pricing scales with scope, methodology, and firm tier.
| Test type | Cost range | Frequency | Cost factors |
|---|---|---|---|
| External Network Penetration Test | $5,000 - $30,000 | Annual | Number of external IPs, services exposed, complexity |
| Internal Network Penetration Test | $5,000 - $20,000 | Annual | Network size, number of VLANs, segmentation complexity |
| Web Application Penetration Test | $5,000 - $15,000 | Annual + after significant changes | Application complexity, number of roles, APIs, authentication flows |
| Segmentation Validation Test | $3,000 - $10,000 | Every 6 months (if segmentation used) | Number of segments, network topology complexity |
| Wireless Penetration Test | $3,000 - $8,000 | Annual | Number of locations, wireless networks, physical security |
For deeper figures, see our dedicated pen testing cost reference.
ASV scan vs pen test vs vulnerability scan
Three terms that get used interchangeably and are not the same. PCI DSS 4.0 requires all three, with different cadences and different evidence outputs.
| Activity | Who runs it | Frequency | Typical cost |
|---|---|---|---|
| External ASV scan | PCI SSC Approved Scanning Vendor | Quarterly | $100 - $800 / quarter |
| Internal vulnerability scan | In-house or third party | Quarterly (authenticated under 4.0) | $2,000 - $15,000 / year |
| Penetration test (external) | Pen test firm | Annual + after significant change | $5,000 - $30,000 |
| Penetration test (internal) | Pen test firm | Annual | $5,000 - $20,000 |
| Segmentation validation | Pen test firm | Every 6 months (if segmentation used) | $3,000 - $10,000 |
Need to start scanning today?
The PCI SSC publishes a public directory of every Approved Scanning Vendor with current PCI certification. Use it as your filter, not vendor sales pages.
Frequently asked
Approved Scanning Vendor scans run $100 to $800 per quarter depending on the number of IPs and the vendor. Annual cost typically lands at $400 to $3,200. SecurityMetrics is the cheapest for small merchants. Qualys, Tenable, Rapid7, and Trustwave price higher and offer more detailed reporting. The PCI SSC maintains the official ASV directory.
Continue reading