PCI DSS · Requirement 11.3 Scanning

PCI scan-ready. Every quarter, done for you.

PCI DSS makes you scan for vulnerabilities every quarter, and again after any big change. We run those scans for you on Tenable Nessus, work out what would actually fail you, and hand back evidence your auditor will accept. Everything stays in South Africa, so you keep POPIA and GDPR residency.

11.3PCI requirement
Quarterly+ after each change
Nessusscan engine
ntinga-scan · engine: nessus · api.acme.co SCANNING
$ ntinga-scan --target api.acme.co --engine nessus --deep
0Critical
0High
0Medium
0Low

Built for teams under PCI DSS · fintech · e-commerce · SaaS

PCI DSS 11.3 POPIA GDPR SOC 2 aligned Scans by Nessus Scans run in africa-south1
// PCI DSS coverage

Every scan PCI DSS asks you to run, in one place

PCI DSS 11.3 requires internal and external vulnerability scans, quarterly and after every significant change. Ntinga runs each one on Nessus, ranks the results, and tells you exactly what to remediate before your assessment.

External Scans · Req 11.3.2

Every quarter we scan the internet-facing side of your cardholder environment for exposed services, expired certs and assets you'd forgotten you had, then re-test until it's clean and ready for your ASV to sign off.

EXTERNAL · PCI 11.3.2

Internal Scans · Req 11.3.1

Credentialed Nessus scans across the servers, workstations and appliances inside your CDE, catching missing patches and weak configs every quarter and after each change. No ASV needed for these.

INTERNAL · PCI 11.3.1

Web App & API Testing

OWASP Top 10, business-logic checks and API fuzzing on your public-facing payment apps, mapped to PCI Req 6.4. A person looks at every high-severity finding before it reaches you.

WEB · PCI 6.4 · OWASP

Cloud & Segmentation

Posture scanning for GCP, AWS and Azure: public buckets, over-broad IAM, unencrypted disks, and the segmentation controls that keep your PCI scope small.

CLOUD · SCOPE · CSPM

Secure-Config Audits · Req 2.2

Nessus CIS audit policies tuned to your own OS, cloud and app stack. It's the documented secure-configuration evidence PCI Req 2.2 wants, not a generic template.

CIS · PCI 2.2 · HARDENING

Rescan After Every Change

PCI makes you rescan after any significant change. New CVE or new deploy overnight? We re-test automatically and alert you the moment your exposure changes.

ON-CHANGE · PCI 11.3
// Managed pipeline

From your selection to auditor-ready evidence, we run every scan

You never wait on a quote or a consultant, and you never touch the scanner. Choose your scope, we verify the assets are yours, and Ntinga runs the scan on your behalf and delivers the PCI evidence. The numbers are the exact order it runs in.

01

Select

Drop in the IPs and domains in scope. The price updates live as you drag; you can watch it in the calculator below.

02

Verify

We confirm the assets are yours with a DNS TXT or file token before anything runs. Company email required, no free inboxes.

03

Confirm

We send an invoice for the scope you picked, in ZAR. The moment it settles, your scan is scheduled. No back-and-forth.

04

We scan

Ntinga runs the scan for you on Tenable Nessus: external, plus any extra depth and your CIS benchmark if you've turned it on. You never touch the engine.

05

Report

We deliver a ranked report plus your PCI 11.3 evidence to a read-only portal. You get the results, not scanner access. Quarterly plans re-scan on schedule.

// Reporting

Reports your QSA will actually accept

We run the scanner and hand you the results: a ranked, read-only report with the scope, cadence and remediation evidence a PCI assessment asks for. You never get direct access to the scan engine, and you never need it.

  • Scored by real risk

    Every finding gets a score that weighs how exploitable it is, how exposed you are and what it would cost you, so your team fixes what matters first.

  • Auditor-ready PCI evidence

    Every report carries scan scope, quarterly dates and remediation status mapped to PCI DSS 11.3. It's the evidence pack your QSA signs off, not a raw CVE dump. Want an analyst to check every critical by hand? That's one toggle away.

  • Data stays in-region

    Scans, evidence and reports are processed and stored in africa-south1. Your data never leaves the jurisdiction you're regulated in.

acme.co · PCI quarterly scan #412715 Jul 2026 · 03:12 SAST
72

Risk score: High

Down 14 points since the last scan. 3 criticals still open, and PCI wants those cleared before your next quarterly attestation.

Critical
3
High
11
Medium
27
Low
9
// Pricing

Price your PCI scanning. Pay only for what you scan.

Drag the slider to the number of IPs and domains in your PCI scope. Pick your depth and cadence (quarterly is the PCI minimum) and the price updates live, with volume discounts already built in. Send it to us with your company email and we'll confirm the scope and invoice you in ZAR. Clear per-asset pricing, and no "contact sales" wall.

1500+
Custom CIS Benchmark

Tailored CIS hardening audit mapped to your environment

Analyst-validated criticals

Every critical & high triaged by hand before it reaches you

$242 / month
≈ $9.69 per asset / month
Scoping call
Free

A 30-minute call to size your PCI 11.3 scope: which IPs and domains are in the cardholder data environment, and what your quarterly scan will cost.

Book a scoping call
Pay-as-you-scan
From $6.46 / asset / mo

Everything above, priced live and invoiced in ZAR, with the scans run by Ntinga. The per-asset rate keeps dropping the more you scan.

Use the calculator
Enterprise / MSP
Custom

500+ assets, private scanner, QSA-ready PCI / POPIA / ISO evidence packs, ASV coordination and a named analyst. Annual billing available.

Talk to us

Prices are indicative and invoiced in ZAR. Need 500+ assets or a private scanner? Talk to our team →

// Get started

Get your PCI 11.3 scanning scoped

Drop in the domain in your cardholder data environment and your work email. We'll come back with the scope, a fixed price in ZAR, and the ownership check we run before any scan touches your assets.

Data processed in africa-south1 · POPIA compliant · we never sell your results

// Refunds & Cancellations

Refunds and cancellations

Ntinga Information Systems provides PCI DSS 11.3 vulnerability scanning as a subscription service. This policy explains how to cancel, when refunds apply, and how we handle disputes.

Scan subscriptions

Scans are delivered at the frequency each client requires — daily, weekly, monthly, quarterly or annually — and billed for the subscription term selected at checkout. You can cancel at any time by emailing sales@ntingasec.com. Cancellation stops future billing and takes effect at the end of your current paid term; scanning continues until that term ends, and the current term is not refunded. If no scan has been run and no report has been issued under your current term, we will refund that term's payment in full if you request it within 14 days of the charge.

Managed and analyst-reviewed plans

Plans that include a named analyst, a private scanner or ASV coordination may be cancelled with 30 days' written notice. Fees for the current billing period are not refundable, and service continues to the end of that period. Any scanning phase, analyst review or evidence pack already delivered is non-refundable.

Disputes

If you are dissatisfied with a report or deliverable, contact sales@ntingasec.com within 14 days of delivery. We will review it and, where the deliverable falls short of the scope you paid for, either remediate at no cost or issue a partial refund. Unresolved matters are escalated to the Founder, Sakhumzi Louw, and, failing resolution, handled under the dispute clause of your service agreement.

How refunds are processed

Approved refunds are returned to the account the invoice was settled from, within 10 business days of approval.

Questions about this policy? Email sales@ntingasec.com · Ntinga Information Systems · Johannesburg, ZA