Requirement 11 · Test security of systems and networks regularly

11.3 Vulnerabilities are regularly identified, prioritised and addressed

SCOPEEVIDENCERISKEVIDENCETESTEVIDENCEREPORTEVIDENCEAUDIT TRAIL11.3 Audit PathPOLICY / CONTROL / EVIDENCE / REVIEW

How to meet it

Run internal scans and quarterly external ASV scans; remediate and rescan.

Defined requirements

The individual PCI DSS v4.0.1 requirements under 11.3, in plain English.

11.3.1Internal vulnerability scans run at least every three months, with high-risk/critical issues fixed and rescans done.
11.3.1.1Lower-risk vulnerabilities are addressed based on the targeted risk analysis with rescans as needed.
11.3.1.2Internal scans use authenticated scanning with sufficient privileges.
11.3.1.3Internal scans are performed after every significant change by qualified, independent personnel.
11.3.2External scans run at least every three months by a PCI SSC Approved Scanning Vendor, meeting passing-scan requirements.
11.3.2.1External scans are performed after significant changes, fixing CVSS 4.0+ vulnerabilities, by qualified independent personnel.

Policy templates for this control

Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.

Open the control-to-policy map
Back to Requirement 11, or see PCI DSS templates. To run PCI controls with automation, read how AI manages controls.