A MegaplanIT security consultant will begin by identifying all external facing IPs that are in scope for vulnerability scanning.
APPROVED SCANNING VENDOR
Complimentary PCI ASV Scan & MegaPortal Access
Start your compliance journey with a complimentary PCI ASV scan and explore MegaPortal, our powerful platform designed to streamline your ASV process, reporting, and remediation. No commitment necessary. Just better security.
Service Overview
PCI SSC Approved Scanning Vendor (ASV)
In order to be PCI DSS compliant, your organization must adhere to requirement 11.2: “Run internal and external network vulnerability scans at least quarterly and after any significant change in the network. Quarterly external scans must be performed by an Approved Scanning Vendor (ASV).”
We use comprehensive network scans to identify vulnerabilities in your organization’s environment and provide remediation assistance and recommendations to help you achieve your quarterly Attestation of Scanning Compliance. With thousands of approved scans under our belts, nobody is better qualified to help your organization through all aspects of PCI DSS compliance.
Whether you are completing a Level 1 Assessment with a third-party auditor or completing a Self-Assessment Questionnaire with your internal compliance team, the MegaPortal will help you toward achieving your goal of PCI DSS compliance.
External Facing IPs
Scheduled Scans
Our consultant will coordinate with your team to schedule scanning activities. Your productivity is a priority, which is why we make sure our assessments never interfere with your organization’s workflow.
External ASV Scans
Once the external ASV scans are complete, the MegaplanIT consultant will review scan results internally to ensure accuracy. If any vulnerability exists, the MegaplanIT consultant will offer customized remediation consulting and perform retesting (if necessary).
Attestation of Scanning
Once your organization has passed the ASV scan, MegaplanIT will issue an Attestation of Scanning for submission to acquirers, processors, gateways, and other PCI stakeholders. We also provide detailed Technical Reports, including an Executive Summary, for your information and records.
HOW IT WORKS
The MegaPortal: Our PCI SSC Approved Scanning Service
We configure a custom PCI portal for your company to conduct ASV scans and generate your Self-Assessment Questionnaire (SAQ) report, if needed. Once the portal has been activated, a MegaplanIT security consultant will walk you through using the portal and provide you with recommendations for conducting and understanding the results of your first scan.
1. Create a Project
2. Add Targets
3. Schedule a Scan
4. Review Vulnerabilities
5. Create a Report
6. Request Attestation
1. Create a Project
1. Create a Project
Before scanning can begin, the first step is to create a project. By establishing a project, you organize and manage every asset in your PCI environment, ensuring no critical system is missed. In the event you have multiple business units having separate scopes, you may create additional projects to keep these organized.
2. Add Targets
2. Add Targets
Next, it’s time to add your targets. This involves entering all systems, IP addresses, or domains within your PCI scope. Be thorough, as every in-scope target must be included to ensure comprehensive scans that meet compliance requirements.
3. Schedule a Scan
3. Schedule a Scan
Once all in-scope targets have been added, it’s time to schedule your scan. The portal offers flexible customization options, allowing you to choose a one-time scan or a recurring schedule. Select the time and time zone that best fit your operations, ensuring scans align with both your needs and PCI standards.
4. Review Vulnerabilities
4. Review Vulnerabilities
Once a scan completes, the results will appear in your project. Here, you’ll be able to review any vulnerabilities, marked as either passing or failing. Promptly address failing findings by remediating issues or disputing false positives to ensure your environment meets PCI compliance standards.
5. Create a Report
5. Create a Report
Generate professional and meaningful reports with ease once your external PCI ASV scan is complete. In just a few clicks, the platform compiles scan results into a comprehensive, PCI-compliant report that highlights vulnerabilities by severity, maps findings to relevant PCI DSS requirements, and provides actionable remediation guidance. Reports can be exported in multiple formats, making it simple to share with auditors, stakeholders, or your internal security team. This streamlined process ensures clarity, saves time, and helps your organization maintain continuous compliance.
6. Request Attestation
6. Request Attestation
Request quarterly PCI attestations effortlessly with just a few clicks. The platform streamlines the attestation process, automatically generating the necessary documentation and ensuring it meets compliance standards. This simple, efficient workflow keeps your organization audit-ready, reduces administrative overhead, and helps maintain ongoing PCI compliance without the usual hassle.
Review Project Scope
Data Gathering, Review, and Analysis
Application Penetration Testing
Draft Report
MegaplanIT Quality Assurance
Report Delivery & Project Closure
Review Project Scope
Each assessment will start with the project scope and data collection. Your assessor will schedule a series of calls and collect documentation to obtain an overview of your payment solution architecture and development environment.
Data Gathering, Review, and Analysis
We then start data gathering, review, and analysis. The assigned assessor will process and evaluate supporting documentation against the applicable PCI standards. In addition, potential security control gaps will be escalated and monitored.
Application Penetration Testing
For SSF payment application assessments, MegaplanIT will access a mutually agreed upon lab environment to conduct hands-on operational and security testing that simulates real-world application use within a secure lab environment.
Draft Report
The assessor will review and finalize collected evidence, draft an initial report (ROV/AOV, ROC/AOC), and prepare the evidence and draft deliverables for internal QA submission.
MegaplanIT Quality Assurance
Your assessor will then submit the draft report and required documentation to MegapanIT’s internal Quality Assurance lead for objective and detailed review. MegaplanIT addresses QA recommendations before client draft delivery.
Report Delivery & Project Closure
MegaplanIT will deliver the draft reporting deliverables to you for client review and feedback. After completing additional updates and QA acceptance, the assessor will submit the final reports for validated payment applications and software lifecycles to PCI SSC AQM for review and approval. Relevant feedback and findings of interest are communicated to the client, as received from AQM.
Upon completing the AQM review and acceptance cycle, MegaplanIT will schedule a project closing meeting to review the overall project, receive feedback, conduct a Lessons Learned readout, and identify any further actions or next steps.
What Clients Say About the MegaPortal
See how organizations achieve PCI compliance faster and with confidence using MegaplanIT’s PCI ASV Scanning and MegaPortal’s real-time visibility:
Big shoutout to the support team for their amazing help, they made the ASV portal feel like second nature. It’s user-friendly, with scan results right there and easy to understand.
Laura K., Project Lead
I can’t say enough about the support team… they were kind, quick, and made everything make sense. The ASV portal is a everything we needed, finding what I need from scan results is straightforward
Michael P., Systems Analyst
Wow, what a great experience! The support folks were quick, friendly, and super helpful. Plus, the ASV portal is awesome, everything’s clear, easy to find, and laid out perfectly.
James T., IT Coordinator
The support team really knows their stuff. They made setting up on the ASV portal smooth and stress-free. The portal’s design is fantastic, so easy to use and see all our scan results at a glance.
Emily R., Business Owner
The support team was a lifesaver! They walked us through every step with patience and made using the ASV portal a breeze. The portal itself is so intuitive, finding scan results and navigating is effortless!
Sarah M., Operations Manager
Key Benefits
Why Choose MegaplanIT as Your PCI Approved Scanning Vendor
As a qualified ASV (approved by the PCI Security Standards Council), our goal is to assist merchants and service providers in becoming—and staying—PCI DSS compliant.
- Role-Based Access Control
- Unlimited Scanning
- Live Chat
- Next Day Meeting Scheduler
- Same-Day Attestation Reports
- Unlimited Reports
- Centralized Visibility
- Real-Time Notifications
- Trend Analysis & Reporting
- User-Friendly ASV Portal
Get a Free PCI ASV Scan and Trial of the MegaPortal
Take the first step toward simplified compliance. Get a free PCI ASV scan and experience the MegaPortal firsthand — giving you real-time visibility, streamlined reporting, and the tools you need to stay audit-ready.

