External Approved Scanning Vendor scans are usually quarterly for SAQ A-EP and SAQ D merchants, while a pure SAQ A redirect flow is often exempt but not always; the acquirer confirms which scans apply to the merchant.
Match scan expectations to the SAQ
For SAQ A, ask the acquirer whether an ASV scan is required. The guide describes many merchants using a genuine hosted redirect as exempt, but it does not make that an automatic exemption. For SAQ A-EP, commission quarterly ASV scans alongside script inventory, change and tamper detection, patching, and segmentation. For SAQ D, quarterly scans are part of a larger program and sit alongside an annual penetration test and segmentation testing.
Understand what an ASV scan is
An ASV performs external vulnerability scanning against the public-facing scope agreed for the merchant. It is not a review of every application control, a substitute for the SAQ, or a general approval of the business. Define the external addresses and services that belong in scope, follow the ASV's validation instructions, and document why any address is included or excluded. A scan report is evidence of the scan result, not a transfer of the merchant's obligations.
Commission, review, remediate
The merchant commissions the scan, reads the findings, fixes or mitigates issues, and keeps the report or attestation letter for each required quarter. Track the remediation and rescan result with the related patch or change record. Hosting can provide an environment that does not block the scanning vendor, but it does not commission the scan, choose the merchant's scope, or remediate the merchant's payment-page code.
- Confirm the required frequency with the acquirer.
- Keep the ASV scope list current after IP, domain, or application changes.
- Preserve reports, attestation letters, findings, exceptions, and retest evidence.
- Escalate unresolved findings to the acquirer or a qualified assessor rather than declaring yourself compliant.
Keep scanning in context
Internal vulnerability scanning and at least annual segmentation testing may also be expected, and SAQ D adds an annual penetration test. These are distinct from an external ASV scan. Read the PCI checklist for the evidence split and the SAQ guide for the decision path. For hosting-boundary questions, use the support ticket form; your acquirer has the final word.