ASV scan cost for our client
We currently provide PCI DSS consultancy services primarily for merchants falling under SAQ A, where ASV scanning is not required. Recently, we onboarded a client that falls under SAQ A-EP, so an ASV scan became necessary.
Since we are not an ASV ourselves, we approached a few ASV providers for a scan on a single domain. One provider mentioned that pricing is not based on the number of domains/IPs, but rather on the effort involved in generating and managing the report.
I wanted to understand from others in the industry:
- Is this the standard pricing model for ASV services?
- For a relatively straightforward single-domain requirement, what is the typical cost range businesses are paying?
- Are there ASV providers that support partner/third-party managed scanning models for consultants or MSPs?
The compliance side is already covered internally; we are mainly looking for a practical and scalable ASV scanning approach for occasional SAQ A-EP clients.