PCI DSS v4.0

ShipShape and PCI DSS

Useful for one requirement. We are explicitly NOT an Approved Scanning Vendor.

The control we speak to

Requirement 11.3.2

External vulnerability scans are performed by an Approved Scanning Vendor (ASV) at least once every three months and after any significant change.

What we produce for it

  • External scanning of your public application on a monthly cadence, with a dated record per scan.
  • Evidence for 6.2.4-style checks on common web application attacks — injection and access control among them.
  • A clear statement, on every record, of what was and was not tested.

What we do NOT do

  • WE ARE NOT AN ASV. Requirement 11.3.2 specifically requires a PCI-approved scanning vendor, and a ShipShape scan does NOT satisfy it. You still need an ASV.
  • We do not scan network infrastructure, and we do not assess cardholder data environment segmentation.
  • If you handle card data, treat our output as supporting evidence alongside a proper ASV scan, never as a replacement for one.
Run a scan