top of page
Logo.jpg

ASV Scans for Mobile Applications

  • Jul 30, 2025
  • 2 min read

Updated: May 27

ASV scanning (PCI DSS Requirement 11.3.2) is also needed for mobile application environments that include publicly accessible backend systems or APIs connected to the payment flow: “All publicly accessible applications — including backend systems that mobile apps communicate with — must undergo ASV scans.”

Mobile application connected to APIs and server infrastructure for PCI DSS ASV scan scope

Why ASV scanning is required


  1. Requirement 11.3.2 (PCI DSS v4.0.1) mandates:

External vulnerability scans are to be performed at least once every three months … on all externally accessible (Internet-facing) system components that are part of the cardholder data environment (CDE), or that provide a path to the CDE.

Even if the mobile app doesn’t process PAN directly, its backend APIs are Internet-facing and mediate the payment flow, making them in-scope.


  1. According to the PCI SSC ASV Program Guide:


“ASV scan requirements in SAQ A apply … to e‑commerce merchant systems that host the webpage or embedded payment page/form … The intent is … scanning for vulnerabilities that could potentially expose their link to the TPSP’s payment page.(blog.pcisecuritystandards.org).

For mobile applications, the same principle applies to backend APIs: if they are Internet-facing and tied to payment, they require scanning.


  1. The PCI Approved Scanning Vendor Program Guide (v4.0r2) defines

    “Internet-facing system components” as all hosts that can be reached externally and are part of or provide a path to the CDE.

That includes backend servers and APIs used by the mobile application — they are scannable assets under the ASV Program.

 

PCI DSS ASV scan dashboard showing vulnerability checks for internet-facing systems

See further information in the Resource Guidance about Application Servers, DNS Servers, Web Applications and Web Servers.


For organisations that need external scan support, nabu provides PCI DSS ASV scanning for internet-facing systems connected to payment environments.


Need to confirm which mobile application systems require ASV scanning? Contact nabu before your next PCI DSS scan.

bottom of page