Create an Attestation

Required User Role: Administrator and Custom Role

After you submit a Tenable PCI ASV scan, you must create an attestation request draft.

Note: When you create an attestation request draft for a scan, you do not also submit the scan for ASV attestation. You must dispute all remaining failures and address all out of scope assets before you submit the attestation for ASV approval.

Caution: You cannot create an attestation for scans that are more than 90 days old.

To create an attestation request:

  1. Access the Tenable PCI ASV Workbench.

  2. In the scans table, in the New Scan Results tab, select the check box next to the scan or scans for which you want to create an attestation.

  3. In the action bar, click Start Attestation.

    The Attestation Detail page appears.

    Note: You cannot start an attestation for Tenable Web App Scanning unless you include a PCI Quarterly External scan as well. For more information, see the KB article: How To Combine multiple PCI ASV Scans.

  4. In the Name box, type the name of the attestation as you want it to appear on the attestation request.

    Note: Tenable recommends that you type a name you can easily identify. After you submit the attestation request, you cannot change the name on the attestation.

  5. (Optional) To assign the attestation to a different user, in the Owner drop-down box, select the user to whom you want to assign the attestation.
  6. Do one of the following:

    • Click Save.

      Tenable PCI ASV saves the attestation draft in the In Remediation tab of the Tenable PCI ASV table.

      Note: You can return to a saved, unsubmitted attestation and configure the options until you submit the attestation for review.

    • Click Submit to ASV Review. For more information, see Submit an Attestation for ASV Review.

What to do next: