ASV pricing

Tenable PCI compliance cost 2026: you scan, Tenable attests

Tenable is the attesting vendor itself, “qualified as an Approved Scanning Vendor (ASV) to validate external vulnerability scans of internet facing environments” in its own words. The model is unusual: you run the scan with Tenable's PCI template, then submit it for attestation. Tenable publishes no price for it, and it attaches to Tenable Vulnerability Management rather than selling on its own.

Updated July 2026

Who attests

Tenable itself

Qualified ASV, no partner in the chain

Published ASV price

None

Attaches to Tenable Vulnerability Management

Scan model

You scan, then submit for attestation

The model: you run the scan, Tenable attests it

Most buyers picture an ASV as a service that points its scanners at your estate every quarter and posts you a certificate. Tenable does not work that way, and it is the most useful thing to know about the product. You configure and run the scan yourself using Tenable's PCI Quarterly External Scan template, then submit the resulting report to Tenable for attestation. Tenable is the approved scanning vendor in that exchange, so the attestation comes from the same company as the platform, with one contract and one dispute queue rather than two.

The consequences are worth being honest about, because they cut both ways. Your team owns the scan configuration and the schedule, which means a missed quarter is an operational failure of yours rather than a vendor's. You can iterate against the template before you submit anything, which is genuinely useful: you see what the report will say before it becomes a compliance artefact. And the work of getting to a clean report sits with you.

For a team already living in the platform every day, that control is a feature and the marginal effort is close to zero. For a merchant who wanted to hand the problem over and receive a document, it is work they did not expect to be doing. That distinction, not a price, is what should decide this.

Why there is no price here

Tenable publishes no price for Tenable PCI ASV. It attaches to Tenable Vulnerability Management rather than selling as a standalone product, which is much of the reason: the ASV line is rarely bought on its own, so it is rarely priced on its own. There is no rate card, no list price, nothing to cite. A figure invented for this page would land in your head as “Tenable ASV costs about that much” and travel with you into a negotiation as though it were a fact. It would not be one.

What is knowable is what the number is built from. Ask for it broken out this way and you can check the arithmetic yourself:

  • External targets in scope. The meter. Not your total asset count, the internet-facing subset in PCI scope.
  • Network targets versus web applications. Usually priced differently. Get the split before the total.
  • Rescans and disputes: included or metered. Requirement 11.3.2 needs four passing scans a year, not four attempts. Under a self-scan model you will iterate, so find out what iteration costs.
  • Scan frequency above the quarterly minimum. Monthly is a choice, not an obligation, and it is priced.
  • Bundled or standalone. Since ASV attaches to the platform subscription, establish what the line is worth inside the bundle and what happens to it if you drop the platform.

Three deployment shapes

ScenarioWhat the deployment actually contains
Small e-commerce, PCI-only, a handful of external targetsTenable Vulnerability Management entry tier plus the PCI ASV line, quarterly external scans run by your own team against the PCI template, then submitted for attestation. The platform exists here only to reach the attestation, and somebody in-house has to own the scan calendar.
Mid-market SaaS already on Tenable, roughly 60 assetsThe platform is already justified for internal vulnerability management and the team is already in the console. The PCI template is one more scan configuration alongside the ones they run anyway, and the self-scan model costs almost no extra effort. This is the shape Tenable fits best.
Enterprise fintech, platform plus internal scanningEnterprise-tier vulnerability management, authenticated internal scanning, container security, with PCI ASV as one capability inside it. The attestation is a rounding error in this decision and should not drive it. Judge the platform on the security operations case.

The useful comparison between these shapes is not fee against fee. It is whether the platform underneath is justified by something other than PCI, and whether you have a team who will happily own the scan calendar. Those two answers decide it.

When the Tenable platform investment pays back

The subscription pays back for buyers who need three or more of the following capabilities beyond PCI ASV: cloud-delivered internal vulnerability scanning across hybrid environments, cloud-native container and Kubernetes security scanning, web application security scanning, cloud security posture management (Tenable Cloud Security), and Tenable Lumin for executive-tier vulnerability reporting. Each of these is materially better delivered through the platform than through standalone point products.

For buyers who already use Nessus Professional for internal vulnerability management, the platform is the natural evolution rather than a new investment: centralised reporting, asset inventory, and the PCI ASV path that standalone Nessus does not provide. It also means the self-scan model lands on a team who already know the scanner, which is exactly the condition under which that model is a feature rather than a chore.

For buyers who need PCI ASV and have no broader platform ambition, Tenable is the wrong shape. Not because we can price the gap, which nobody can, but because of what you would be buying: a vulnerability management platform, with ASV attestation as one capability inside it, to satisfy a requirement that is quarterly scanning of your internet-facing footprint by an approved vendor. And you would still be running the scans yourself. Vendors who sell PCI ASV as a standalone product are built around exactly that requirement. If your use case is genuinely PCI-only, say so early and let the proposal be judged on it, rather than on a platform roadmap you have no intention of following.

When Tenable wins and when it does not

Tenable wins for buyers who already use Nessus Professional and want a natural upgrade path, for buyers who need integrated cloud-native vulnerability management across hybrid environments, and for buyers who want the attesting vendor and the scanning platform to be the same company: one contract, one dispute queue, one console. Teams who run the platform daily also get the self-scan model at close to zero marginal effort, which is the quiet advantage here.

Tenable does not win for buyers who only need PCI ASV, because the required platform subscription underneath it is the real purchase and the scanning work still lands on your team. It does not win for buyers already standardised on another vulnerability management platform, where forced migration is rarely justified by the PCI line alone. And it does not win for buyers who want a published retail rate card: Tenable prices through sales conversations rather than transparent product pages.

Negotiating with Tenable

Three tactics. First, if you are buying the platform anyway, negotiate the PCI ASV component inside that conversation rather than adding it afterwards. An add-on to a signed contract is a purchase with no alternative attached, which is the weakest position a buyer can negotiate from. Second, run a genuine competitive process on your real external target count, because in a market with no published prices a credible alternative quote is the only leverage there is. Third, get the asset-count definition in writing: what counts as an asset, what happens when the count grows mid-term, and whether decommissioned assets leave the count. That definition is the multiplier on everything else in the contract.

Ask the attestation questions too, because they are where the time goes: how disputes are raised, how long they take to resolve, and whether rescans and resubmissions are included or metered. Under a self-scan model you will be submitting more than once, and four passing scans a year is the obligation.

For multi-year terms, negotiate asset-band protection explicitly. Per-asset models have tier-step jumps, and locking the current band for the contract term protects against the cliff at threshold counts. Do the same for the external target count on the ASV line, because that count grows quietly every time somebody stands up a new subdomain.

Tenable on the PCI SSC ASV directory

Tenable is listed in the official PCI SSC Approved Scanning Vendor directory. Look up any vendor named in your proposal before you sign.

Verify on pcisecuritystandards.org

Frequently asked

Yes. In Tenable's own words, it is "qualified as an Approved Scanning Vendor (ASV) to validate external vulnerability scans of internet facing environments". Unlike vendors who reach ASV scanning through a partner, Tenable is the attesting entity itself, which means one contract and one dispute queue rather than two. The product is delivered through Tenable Vulnerability Management rather than through Nessus Professional, which surprises buyers who first met Tenable through Nessus.

Continue reading