pa.taxFind help
Browse by specialty

PCI Approved Scanning Vendors

Approved Scanning Vendors listed by the PCI Security Standards Council to run external vulnerability scans required by PCI DSS.

81 firms listed · October 2026 snapshot

FedRAMP 3PAOGovRAMP 3PAOPCI QSAPCI ASVCMMC C3PAOHITRUST assessorSOC 2 services sourced

ControlCase

Fairfax, VA

View profile
FedRAMP 3PAOGovRAMP 3PAOPCI QSAPCI ASVCMMC C3PAOHITRUST assessorSOC 2 services sourced

RSM US, LLP

Chicago, IL

View profile

Frequently asked questions

How is this list sourced?

PCI SSC Approved Scanning Vendors is the official list, read October 3, 2026. An ASV runs external vulnerability scans, not a full PCI DSS assessment. The PCI Security Standards Council does not endorse or recommend any ASV, and vendors in remediation are not listed here. Check the live registry for changes.

Are these listings endorsements?

No. Compare the firm's services and confirm current status before engaging an auditor.

Firms are listed from official registries, each with its own as-of date. Locations are shown only where the registry or the firm's own site provides them. A listing records registry status, not an endorsement, and directory information may change. SOC 2 is a CPA attestation report, not a certificate. pa.tax is independent: listed firms pay nothing for inclusion, ranking or referrals, and firms are listed alphabetically.

Confirm current status and scope directly with the PCI SSC Approved Scanning Vendors, as of October 3, 2026.