PCI DSS Penetration Testing
Internal, external, application-layer, and segmentation testing that maps cleanly to PCI DSS Requirement 11.4, with a report your QSA can work from and retests to close the loop.
The Requirement
What PCI DSS actually asks for
Unlike most frameworks, PCI DSS is explicit. Requirement 11.4 mandates penetration testing on a defined methodology and schedule, and your assessor will check the details: internal and external testing, network and application layers, segmentation validation, and remediation of exploitable findings.
It also draws a line that trips up a lot of teams: the quarterly ASV scans in Requirement 11.3 are vulnerability scans, not penetration tests. A scan enumerates potential weaknesses; a penetration test exploits and chains them the way an attacker would. You need both, and they are not interchangeable.
Internal and external testing
Requirement 11.4 calls for penetration testing from outside the network and from inside it, covering the cardholder data environment and the systems that could affect it.
Network-layer and application-layer
Both layers are in scope: network services and segmentation on one side, and the applications that store, process, or transmit cardholder data on the other, including the vulnerability classes in Requirement 6.2.4.
Segmentation validation
If you use segmentation to reduce PCI scope, testing must prove the segmentation actually isolates the CDE. Annually for merchants, and at least every six months for service providers.
Annually and after significant changes
Penetration testing is required at least once every 12 months and after significant infrastructure or application changes, using a documented, industry-accepted methodology.
How We Deliver
Built for the QSA conversation
Every engagement is scoped against your cardholder data environment and documented on an industry-accepted methodology, so the mapping from finding to requirement is explicit. Findings land in our platform in real time with severity, evidence, and reproduction steps; your team remediates and requests retests from the portal; and the final report plus retest records give your QSA a traceable remediation story instead of a stack of emails.
Scoping tip: segmentation testing is where PCI pentests most often go sideways. If your scope reduction depends on network segmentation, we validate isolation explicitly and document the evidence, because that is the first thing a thorough assessor pulls on. Read about our full testing services or how PTaaS delivery works.
FAQ
PCI penetration testing questions
How often does PCI DSS require penetration testing?
At least once every 12 months and after any significant infrastructure or application change. If you rely on segmentation to reduce scope, segmentation testing is required at least annually for merchants and at least every six months for service providers.
Is an ASV scan the same as a penetration test?
No. The quarterly external scans from an Approved Scanning Vendor satisfy Requirement 11.3.2 and are automated vulnerability scans. Requirement 11.4 penetration testing is a separate, manual exercise where testers exploit and chain weaknesses the way an attacker would. PCI DSS requires both, and one cannot substitute for the other.
What has to be in scope?
The cardholder data environment perimeter and any systems that could impact its security, tested from both outside and inside the network, at the network layer and the application layer. If segmentation is used for scope reduction, the segmentation controls themselves must be tested and shown to isolate the CDE.
What happens if you find exploitable vulnerabilities?
PCI DSS requires that exploitable vulnerabilities and security weaknesses found during testing are corrected and the testing repeated to verify the fix. Retests are built into our engagements: your team remediates, requests a retest from the portal, and the verification is documented in the same record.
Do QSAs accept your reports?
Yes. Reports document scope, the industry-accepted methodology used, tester qualifications, findings with evidence, and remediation results, which is the specific documentation Requirement 11.4.1 expects an assessor to review.
Scope your PCI pentest correctly the first time
Bring us your CDE diagram and your assessment date. We'll map the testing to Requirement 11.4 and get it done with room to remediate.