PCI DSS makes you scan for vulnerabilities every quarter, and again after any big change. We run those scans for you on Tenable Nessus, work out what would actually fail you, and hand back evidence your auditor will accept. Everything stays in South Africa, so you keep POPIA and GDPR residency.
Built for teams under PCI DSS · fintech · e-commerce · SaaS
PCI DSS 11.3 requires internal and external vulnerability scans, quarterly and after every significant change. Ntinga runs each one on Nessus, ranks the results, and tells you exactly what to remediate before your assessment.
Every quarter we scan the internet-facing side of your cardholder environment for exposed services, expired certs and assets you'd forgotten you had, then re-test until it's clean and ready for your ASV to sign off.
EXTERNAL · PCI 11.3.2Credentialed Nessus scans across the servers, workstations and appliances inside your CDE, catching missing patches and weak configs every quarter and after each change. No ASV needed for these.
INTERNAL · PCI 11.3.1OWASP Top 10, business-logic checks and API fuzzing on your public-facing payment apps, mapped to PCI Req 6.4. A person looks at every high-severity finding before it reaches you.
WEB · PCI 6.4 · OWASPPosture scanning for GCP, AWS and Azure: public buckets, over-broad IAM, unencrypted disks, and the segmentation controls that keep your PCI scope small.
CLOUD · SCOPE · CSPMNessus CIS audit policies tuned to your own OS, cloud and app stack. It's the documented secure-configuration evidence PCI Req 2.2 wants, not a generic template.
CIS · PCI 2.2 · HARDENINGPCI makes you rescan after any significant change. New CVE or new deploy overnight? We re-test automatically and alert you the moment your exposure changes.
ON-CHANGE · PCI 11.3You never wait on a quote or a consultant, and you never touch the scanner. Choose your scope, we verify the assets are yours, and Ntinga runs the scan on your behalf and delivers the PCI evidence. The numbers are the exact order it runs in.
Drop in the IPs and domains in scope. The price updates live as you drag; you can watch it in the calculator below.
We confirm the assets are yours with a DNS TXT or file token before anything runs. Company email required, no free inboxes.
We send an invoice for the scope you picked, in ZAR. The moment it settles, your scan is scheduled. No back-and-forth.
Ntinga runs the scan for you on Tenable Nessus: external, plus any extra depth and your CIS benchmark if you've turned it on. You never touch the engine.
We deliver a ranked report plus your PCI 11.3 evidence to a read-only portal. You get the results, not scanner access. Quarterly plans re-scan on schedule.
We run the scanner and hand you the results: a ranked, read-only report with the scope, cadence and remediation evidence a PCI assessment asks for. You never get direct access to the scan engine, and you never need it.
Every finding gets a score that weighs how exploitable it is, how exposed you are and what it would cost you, so your team fixes what matters first.
Every report carries scan scope, quarterly dates and remediation status mapped to PCI DSS 11.3. It's the evidence pack your QSA signs off, not a raw CVE dump. Want an analyst to check every critical by hand? That's one toggle away.
Scans, evidence and reports are processed and stored in africa-south1. Your data never leaves the jurisdiction you're regulated in.
Down 14 points since the last scan. 3 criticals still open, and PCI wants those cleared before your next quarterly attestation.
Drag the slider to the number of IPs and domains in your PCI scope. Pick your depth and cadence (quarterly is the PCI minimum) and the price updates live, with volume discounts already built in. Send it to us with your company email and we'll confirm the scope and invoice you in ZAR. Clear per-asset pricing, and no "contact sales" wall.
Tailored CIS hardening audit mapped to your environment
Every critical & high triaged by hand before it reaches you
A 30-minute call to size your PCI 11.3 scope: which IPs and domains are in the cardholder data environment, and what your quarterly scan will cost.
Book a scoping callEverything above, priced live and invoiced in ZAR, with the scans run by Ntinga. The per-asset rate keeps dropping the more you scan.
Use the calculator500+ assets, private scanner, QSA-ready PCI / POPIA / ISO evidence packs, ASV coordination and a named analyst. Annual billing available.
Talk to usPrices are indicative and invoiced in ZAR. Need 500+ assets or a private scanner? Talk to our team →
Drop in the domain in your cardholder data environment and your work email. We'll come back with the scope, a fixed price in ZAR, and the ownership check we run before any scan touches your assets.
Data processed in africa-south1 · POPIA compliant · we never sell your results
Ntinga Information Systems provides PCI DSS 11.3 vulnerability scanning as a subscription service. This policy explains how to cancel, when refunds apply, and how we handle disputes.
Scans are delivered at the frequency each client requires — daily, weekly, monthly, quarterly or annually — and billed for the subscription term selected at checkout. You can cancel at any time by emailing sales@ntingasec.com. Cancellation stops future billing and takes effect at the end of your current paid term; scanning continues until that term ends, and the current term is not refunded. If no scan has been run and no report has been issued under your current term, we will refund that term's payment in full if you request it within 14 days of the charge.
Plans that include a named analyst, a private scanner or ASV coordination may be cancelled with 30 days' written notice. Fees for the current billing period are not refundable, and service continues to the end of that period. Any scanning phase, analyst review or evidence pack already delivered is non-refundable.
If you are dissatisfied with a report or deliverable, contact sales@ntingasec.com within 14 days of delivery. We will review it and, where the deliverable falls short of the scope you paid for, either remediate at no cost or issue a partial refund. Unresolved matters are escalated to the Founder, Sakhumzi Louw, and, failing resolution, handled under the dispute clause of your service agreement.
Approved refunds are returned to the account the invoice was settled from, within 10 business days of approval.
Questions about this policy? Email sales@ntingasec.com · Ntinga Information Systems · Johannesburg, ZA