PCI DSS scanning — from 91,90 € a year
Quarterly external scans for card compliance: the scan, the report and a re-scan after you fix what it found
Order a scan for 91,90 €
If your site takes card payments, the acquiring bank asks for quarterly external scanning and a report on it. HackerGuardian checks your public addresses for known vulnerabilities, exposed services and weak TLS settings, then produces a report in PCI DSS format. Anything found gets fixed and re-scanned until the report comes back as «passing». Price — from €91.90 a year: the basic plan covers one set of addresses, the enterprise one covers more hosts and more frequent checks. This is about the external check and the paperwork for the acquirer, not about bringing the whole infrastructure into compliance.
HackerGuardian plans
Two levels: basic scanning and an enterprise set of addresses
| Certificate | Validation and issuance | What it secures | Warranty | Price | |
|---|---|---|---|---|---|
| HackerGuardian PCI Scan Control Center Sectigo |
— | One domain and its www | — |
€91.90
per year | Order |
| HackerGuardian PCI Scanning Enterprise Sectigo |
— | One domain and its www | — |
€256.90
per year | Order |
Plans differ in the number of addresses checked and the number of scans.
What you get
The three things people order it for
Vulnerability scan
Public addresses are checked for known vulnerabilities, unnecessary exposed services and weak encryption settings.
Report for the acquirer
Results come as a report in PCI DSS format — that is what goes to the bank.
Re-scans
After fixes the scan runs again, until the report comes back as «passing».
How it works
From order to a passing report
List of addresses
You name the public addresses and domains that fall into the scope of the check.
Scanning
The service probes the perimeter from outside — nothing is installed on your servers.
Going through the findings
The report shows exactly what to close: a software version, an extra service, an outdated cipher.
Re-scan and report
After the fixes you run the scan again and get the report your acquirer accepts.
Frequently asked questions
Scope, timing and what to do with findings
Anyone taking card payments who has to report to an acquiring bank under PCI DSS. The check is required quarterly.
No. The scan covers the external check requirement and gives the acquirer a report, but compliance also means processes, access control and how card data is stored.
No, the check runs from outside against your public addresses.
The report says what to close. After the fixes you run a re-scan, which is included in the plan.
It depends on the plan: the basic one covers a small set of addresses, the enterprise one covers more hosts.
At least quarterly as the standard requires, plus after noticeable infrastructure changes.
On servers hosted with us — yes, we will tell you what to close and how. For other platforms you pass the report to your own administrator.
Yes. The external address of the machine is checked, and we help close what is found on our side.