Holm Security's PCI ASV Solution is an Approved Scanning Vendor (ASV) service for organizations to meet Payment Card Industry Data Security Standard (PCI DSS) requirements. The platform performs external vulnerability scanning on internet-facing systems connected to payment cards to identify common vulnerabilities and exposures (CVEs), misconfigurations, and outdated software. Following automated scans, certified experts manually verify that identified findings are exploitable to eliminate false positives.
The solution facilitates the PCI DSS compliance lifecycle by supporting mandatory quarterly scans, post-significant change scans, and remediation rescanning. Its function is to validate that systems pass compliance criteria, which requires having no vulnerabilities with a Common Vulnerability Scoring System (CVSS) score of 4.0 or higher. To document this process for audits by a Qualified Security Assessor (QSA), the service generates official PCI-compliant scan reports that include a final sign-off for submission or archiving.