Glossary of Compliance

Compliance Glossary

Our list of curated compliance glossary offers everything you to know about compliance in one place.

Glossary » PCI DSS » PCI DSS Approved Scanning Vendor

PCI DSS Approved Scanning Vendor

An ASV is an organization that uses a set of security tools and services (called “ASV scan solution”) to perform external vulnerability scans. Their goal is to test the security posture of a business environment and identify vulnerabilities, misconfigurations, and other gaps in a security system that can be used to cause a security incident. 

This helps organizations improve their data security and meet PCI DSS requirements.

An ASV’s scan solution is rigorously tested and approved by the PCI SSC. Only then do they earn a spot on the PCI SSC’s List of Approved Scanning Vendors.

Key stages in PCI ASV scanning:

  • Determine the scope: The customer determines what parts of their internet-facing system, including components related to cardholder data, should be scanned.
  • Scan: The ASV conducts vulnerability scans using its scanning tools. Different sections of the Cardholder Data Environment (CDE) can be scanned separately.
  • Remediation: After scanning, the ASV shares interim results with the customer, who then takes necessary actions to fix any issues.
  • Resolution: If there are disagreements about scan results, the client and ASV work together to resolve them.
  • Rescan (if needed): Additional scans are performed until all conflicts and exceptions are resolved.
  • Final reporting: When no vulnerabilities remain, the ASV generates a report approved by PCI ASV and securely delivers it to the customer.

Additional reading

3 Reasons Your AI Governance Stack Needs to Be Always-On

You’ve built the governance program. You have selected and customized a framework, set up the controls, and assigned owners. Most GRC and TPRM teams have. In fact, 25% of organizations describe their AI Governance as advanced, and a majority have dedicated budgets for AI governance. If that sounds familiar, you’ve made good progress. But there…

Sprinto vs Drata vs Scrut: Choosing Your Compliance Automation Platform

If you’re weighing Sprinto, Drata, and Scrut, you’re likely at a real decision point: choosing your first platform or deciding which one fits better as your program grows. All three automate evidence collection, run continuous monitoring, and get you audit-ready across frameworks like SOC 2 and ISO 27001, so the basics aren’t where they separate. What sets them apart is how they work and who they fit. Sprinto leans into autonomous, always-on trust across compliance, risk, vendors, and AI governance, and tends to win when automation depth and multi-entity scale matter. Drata is a polished, engineering-friendly platform with a strong Trust Center. Scrut bundles hands-on service with the software and lands well with lean teams. Below, I’ve grounded the comparison in what businesses actually compare when they are switching.

Sprinto: Your growth superpower

Use Sprinto to centralize security compliance management – so nothing
gets in the way of your moving up and winning big.