Knowledge base

Moving to PCI in Portal

Last updated: 2026-08-31


Purpose

What to do with your current scanning cycle and how to run your first scan in the new Portal.


Introduction

PCI compliance scanning is moving from the Classic UI to the Outpost24 Portal. The Portal version runs the same certified ASV cycle: you define a cardholder data environment, discover and review its assets, run the compliance scan, resolve or dispute failing findings, and close the cycle with a customer attestation and a final ASV report. The important thing to get right is timing. Do not switch tools in the middle of a scanning cycle unless you intend to start that cycle over.


Which Applies to You

Your situation

What to do

You are partway through a scanning cycle in the Classic UI.

Finish that cycle in the Classic UI. Complete your scan, resolve or dispute your findings, and submit your attestation and final report there. While you wait, set up your environment in the Portal so it is ready for your next cycle.

You are between cycles or preparing for your next scan.

Start in the Portal. Do not begin a new cycle in the Classic UI.

You are mid-cycle but would rather move now.

You can start the current cycle again from scratch in the Portal. Work already done in the Classic UI for this cycle does not carry across, so you begin with a fresh scope, a fresh scan, and fresh findings.

Why finishing in place is the default

A cycle is only useful once it is completed and attested. Abandoning a cycle partway means repeating the discovery, scanning, and dispute work you have already done, and your compliance deadline does not reset until a cycle is completed. Unless you have a reason to start over, finish where you started.


If you are Finishing your Current Cycle in the Classic UI

Complete the cycle as normal, then prepare for your next one in the Portal. You can do the preparation at any point, including while your Classic UI cycle is still running.

  1. Check your access. PCI scanning in the Portal is available on OUTSCAN only, not on HIAB, and the PCI section appears only for accounts with the PCI subscription enabled. If this is not visible to you, contact your Customer Success Manager or Sales Executive to have this enabled.

  2. Check your permissions. Your role needs the PCI resource set to View and Manage in order to create, confirm, scan, dispute, and complete.

  3. Create at least one schedule if you do not already have one. A schedule must exist before you can create an environment.

  4. Create your environment in the Portal, with its schedule and the customer contact details that will be printed on your ASV report.

  5. Gather your target list: the public IP addresses, hostnames, CIDR blocks, and ranges that make up your cardholder data environment.

Stop there. Do not create a scope in the Portal until your Classic UI cycle is complete, or you will have two cycles running at once.

Two things to expect in the Portal

Your compliance deadline starts empty. The Portal counts the 90-day window from the completion date of your last completed scope in the Portal, so the Deadline column shows a dash until you complete your first cycle there. Keep tracking your existing deadline until then. Your Classic UI history stays in the Classic UI for now. This will be migrated to the Portal UI before access to old Classic data is removed.


Getting your First Scan with PCI in Portal

Getting your first scan with PCI in the Portal: once you are ready to run a cycle in the Portal, this is the whole process.

  1. Go to PCI Environments in the Main Menu and open the environment you created.

  2. Click Create scope, enter your targets one per line, and click Create. Asset discovery starts immediately.

  3. When the status becomes READY FOR REVIEW, click the scope and use the In scope toggle to include or exclude each discovered asset. Everything publicly reachable in your cardholder data environment should be in scope.

  4. Click Confirm scope, then start the scan immediately or schedule it for a date within the next two weeks. Confirming locks your asset selection for that scope.

  5. If the result is NON COMPLIANT, remediate what you can and dispute what you cannot, then use Rescan & rediscover. Repeat until the scope is COMPLIANT.

  6. Select Create report. Generate a draft first if you want to review it internally, then choose Final submission, check the attestation box, and submit. The scope is completed, your report is stored, and your 90-day deadline restarts.

One thing to know before you confirm: confirming a scope locks which assets are in it, and a completed scope is locked permanently. A new scope cannot be created until the current one is completed, so take a moment over the asset review.


Where to Get Help