Summary
Features
PCI program solutions for acquirers and ISOs
SecurityMetrics PCI programs are merchant-friendly, keeping them and you happy.
Feature
Basic
Plus
Pro
Advisor
Online Portal
Merchant PCI SAQ
SAQ Pre-Population
ASV scans (1/merch)
PCI Policy Template
24/7 Help Desk
24/7 Scan & SAQ Support
Partner+ Portal
Custom Email Campaigns
Assigned CSM
ASV scans (5/merch)
$100,000 Merchant Premium Service Warranty
Card Data Discovery
Mobile Device Scan
AI-Powered PCI Compliance (Spectre AI)
Anti-Malware Software
Get started on your PCI program, request a quote now.
Request a QuoteLite
Basic
Advanced
PCI for small businesses starting at
Price discounts available depending on merchant processor
- External Vulnerability Scan (1 IP)
- Online PCI Self Assessment Questionnaire (SAQ)
- Online compliance reporting portal
- Non-compliance notification
- Compliance reporting to merchant processor
- Compliance certificate
- PANscan® (Card discovery software for 1 machine)
- Service warranty (Up to $100,000 reimbursement in case of a breach)
- Security Awareness Training (1 seat)
*We discount our services for most merchants because of our relationship with their merchant processor.
Looking for Acquirer or PCI program pricing? Click here.
Which vulnerability scan is right for you?
Basic
- Online Portal Access (Software to help you work towards HIPAA compliance)
- Security Fundamentals Checklist
- $100,000 Service Guarantee
- Monthly Perimeter Scans: 1 IPs
- Risk Analysis
- Risk Management Plan
- Monthly HIPAA Newsletter
- HIPAA Policies & Procedures (including Breach Notification Policy and Business Associate Agreement Template
- HIPAA Training: 3 seats
- 5 Hour Technical Support (inbound tech support only)
Plus
- Online Portal Access (Software to help you work towards HIPAA compliance)
- Security Fundamentals Checklist
- $100,000 Service Guarantee
- Monthly Perimeter Scans: 3 IPs
- Risk Analysis
- Risk Management Plan
- Monthly HIPAA Newsletter
- HIPAA Policies & Procedures (including Breach Notification Policy and Business Associate Agreement Template
- HIPAA Training: 15 seats
- Unlimited Support (specialized HIPAA support agents available for guidance on all HIPAA tools)
Pro
- Online Portal Access (Software to help you work towards HIPAA compliance)
- Security Fundamentals Checklist
- $100,000 Service Guarantee
- Monthly Perimeter Scans: 5 IPs
- Risk Analysis
- Risk Management Plan
- Monthly HIPAA Newsletter
- HIPAA Policies & Procedures (including Breach Notification Policy and Business Associate Agreement Template
- HIPAA Training: 25 seats
- Unlimited Support (specialized HIPAA support agents available for guidance on all HIPAA tools)
Basic
- Portal access
- 1 payment path supported
- User-initiated scanning process
- Fulfills req’s. 6.4.3 & 11.6.1
- Add-on consultation credits available
- Partner discounts available
Plus
- Portal access
- 1 payment path supported (option to add on)
- Automated scanning process
- Fulfills req's. 6.4.3 & 11.6.1
- Add-on consultation credits available
- Partner discounts available
Pro
- Portal access
- 3 payment paths supported (option to add on)
- Automated scanning process
- Fulfills req's. 6.4.3 & 11.6.1
- Forensic annual baseline assessment
- 12 annual consultation credits included
- Partner discounts available
Frequently Asked Questions
What is an ASV Scan?
ASV stands for “Approved Scanning Vendor.” The Payment Card Industry Data Security Standard (PCI DSS) requirement 11.2.2 calls for regular vulnerability scanning from an ASV.
These are vendors with scanning solutions that have been tested, approved, and added to a list of approved solutions that can help fulfill this PCI compliance requirement. Learn about what qualities to look for in an ASV.
What does a vulnerability scan do?
An external vulnerability scan is performed outside of your network (e.g., at your network perimeter), identifying known exploitable weaknesses in a network.
When am I required to scan?
The PCI SSC requires a vulnerability scan to be performed minimally every three months or after any significant network change (i.e., add/remove network device, updates to segmentation rules).
What IP addresses or domains need to be scanned?
Any Internet-facing connection that processes, stores, or transmits cardholder data. This includes IP addresses that are used in the event of a failover or backup.
My vendor said my hardware was PCI compliant. Do I still need to validate compliance?
Yes, you will still need to validate compliance. There is more to PCI compliance than just the hardware you use. Using tested and secure hardware for credit card processing, viewing, and storing are important aspects of PCI Compliance, but those are only a few.
Credit card information is often compromised through the lack of secure connections and other misconfigured connections to that secure hardware. Scanning will help identify vulnerabilities to be fixed.
Resources
The following are related resources that we have prepared for you. Find more answers to your questions in our Learning Center.


























































