Please could I ask for some advice?
Under PCI DSS v3.2.1 I've been completing a Level 4 SAQ, which does not require an external compliance scan of my network because all card data is collected, processed and stored by a third party. Yesterday I discovered that under the new PCI DSS v4.0, external scanning will now be a requirement for Level 4 retailers - please correct me if I'm wrong, I'd like to be!
ClearAccept are introducing a mandatory, chargeable PCI compliance portal from 1st June (better late than never), but they are not providing a scanning service. I'm therefore looking for an Approved Scanning Vendor (ASV) that can provide a quarterly scan as cheaply as possible.
Does anybody already use an ASV that they can recommend?
I'd also like to understand what a scan actually entails, e.g. how it is initiated and how intrusive it is. Any wisdom would be appreciated!
Thank you,
John
EDIT 01/06/24: Actually, the ClearAccept portal (provided by Worldline Payment Guard) DOES include a scanning service - although ClearAccept's FAQs do a very good job of implying otherwise!
Under PCI DSS v3.2.1 I've been completing a Level 4 SAQ, which does not require an external compliance scan of my network because all card data is collected, processed and stored by a third party. Yesterday I discovered that under the new PCI DSS v4.0, external scanning will now be a requirement for Level 4 retailers - please correct me if I'm wrong, I'd like to be!
ClearAccept are introducing a mandatory, chargeable PCI compliance portal from 1st June (better late than never), but they are not providing a scanning service. I'm therefore looking for an Approved Scanning Vendor (ASV) that can provide a quarterly scan as cheaply as possible.
Does anybody already use an ASV that they can recommend?
I'd also like to understand what a scan actually entails, e.g. how it is initiated and how intrusive it is. Any wisdom would be appreciated!
Thank you,
John
EDIT 01/06/24: Actually, the ClearAccept portal (provided by Worldline Payment Guard) DOES include a scanning service - although ClearAccept's FAQs do a very good job of implying otherwise!
Comment