PCI DSS scanning

Pass your scans. Stay compliant all year.

We run the vulnerability scanning and testing PCI DSS requires, using Tenable and Horizon3.ai NodeZero, then help you fix what we find and hand your assessor clean evidence.

Powered by

TenableVulnerability and ASV scanning NodeZeroExploitability and pentest validation

PCI DSS Requirement 11

Every scan and test the standard calls for.

PCI DSS v4.0.1 Requirement 11 sets out regular security testing. We cover each part.

Requirement How often How we deliver it
Internal vulnerability scans Quarterly and after significant changes Tenable or Horizon3.ai NodeZero, run and reviewed by our team.
External ASV scans Quarterly, by a PCI SSC Approved Scanning Vendor Tenable PCI ASV scanning, with help disputing false positives and getting to a passing scan.
Internal & external penetration testing At least annually and after significant changes NodeZero autonomous testing plus expert-led testing where depth is needed.
Segmentation testing Validate that the cardholder data environment is isolated Testing that proves out-of-scope networks can't reach cardholder data.

Why it matters

A scan report isn't the same as being secure.

Scanners find thousands of vulnerabilities. Pairing Tenable with NodeZero shows which ones an attacker can actually exploit, so your team fixes what matters first.

Fewer false alarmsFindings are validated and prioritized by our analysts.
Proof of exploitabilitySee the real attack paths, not just a CVE list.
Help remediatingGuidance your IT team or MSP can act on.
Assessor-ready evidenceReports organized the way your QSA expects.

Common questions

Do we need both Tenable and NodeZero?

Not always. We recommend the right mix for your environment and assessor. Tenable covers vulnerability and ASV scanning; NodeZero proves which weaknesses are actually exploitable and supports penetration and segmentation testing.

What happens when a scan fails?

We help you prioritize and remediate the findings, document compensating controls or false positives, and rescan until you have a passing result.

Can you work with our QSA?

Yes. We provide the reports and evidence your Qualified Security Assessor needs and can join assessment meetings.

We only take card payments through a provider. Does this apply to us?

It depends on how payments touch your systems and which Self-Assessment Questionnaire applies. We can help you figure out what is actually required.

Get your PCI scanning handled.

Tell us about your cardholder data environment and we'll send a tailored quote.

Request a quote