PCI DSS
PCI DSS penetration testing requirements
PCI DSS v4.0.1 is the current PCI DSS version published by the PCI Security Standards Council. Requirement 11.4 expects internal and external penetration testing to be regularly performed, with exploitable weaknesses corrected.
What needs to be in scope
The test should cover the cardholder data environment, connected systems that could affect its security, and any segmentation controls used to keep systems out of scope.
- External-facing payment applications and APIs
- Internal systems connected to payment workflows
- Cloud and network controls protecting payment data
- Segmentation controls that isolate the CDE
What evidence assessors look for
Useful evidence shows the methodology, dates, scope, tester independence, findings, impact, remediation and retest status. Scanner output alone should not be treated as a penetration test.
How recurring testing helps
PCI DSS expects testing after significant changes as well as on a regular cycle. A subscription model can make change-driven retesting easier to schedule and evidence.
FAQ
Common questions
Is PCI DSS penetration testing the same as vulnerability scanning?
No. Vulnerability scanning supports security assurance, but penetration testing manually validates whether weaknesses are exploitable and what impact they create.
Does PCI DSS require segmentation testing?
If segmentation is used to isolate the CDE from other networks, it should be tested to confirm the controls are effective.
Can one report support PCI DSS and other frameworks?
Often yes, if the scope, methodology, evidence and remediation status are written clearly enough for each audience.