PCI DSS

PCI DSS penetration testing requirements

PCI DSS v4.0.1 is the current PCI DSS version published by the PCI Security Standards Council. Requirement 11.4 expects internal and external penetration testing to be regularly performed, with exploitable weaknesses corrected.

What needs to be in scope

The test should cover the cardholder data environment, connected systems that could affect its security, and any segmentation controls used to keep systems out of scope.

  • External-facing payment applications and APIs
  • Internal systems connected to payment workflows
  • Cloud and network controls protecting payment data
  • Segmentation controls that isolate the CDE

What evidence assessors look for

Useful evidence shows the methodology, dates, scope, tester independence, findings, impact, remediation and retest status. Scanner output alone should not be treated as a penetration test.

How recurring testing helps

PCI DSS expects testing after significant changes as well as on a regular cycle. A subscription model can make change-driven retesting easier to schedule and evidence.

FAQ

Common questions

Is PCI DSS penetration testing the same as vulnerability scanning?

No. Vulnerability scanning supports security assurance, but penetration testing manually validates whether weaknesses are exploitable and what impact they create.

Does PCI DSS require segmentation testing?

If segmentation is used to isolate the CDE from other networks, it should be tested to confirm the controls are effective.

Can one report support PCI DSS and other frameworks?

Often yes, if the scope, methodology, evidence and remediation status are written clearly enough for each audience.

Choose when your next test starts.

Standard within 10 business days. Rapid as soon as the next business day.

Book a call