Compliance

PCI DSS Penetration Testing

Requirement 11.4 penetration testing of your cardholder data environment — external, internal, and segmentation testing — scoped precisely to your CDE and delivered on your QSA's timeline.

See pricing

What's included

  • External CDE penetration testing
  • Internal CDE penetration testing
  • Network segmentation validation (11.4.5)
  • Application-layer testing where card data flows
  • Re-test after remediation

Deliverables

  • Executive summary for leadership
  • QSA-mappable technical report
  • CVSS-rated findings with evidence
  • Segmentation test results
  • Remediation roadmap

Timeline

5–10 business days, depending on CDE size and whether segmentation testing is in scope.

Requirement 11.4, precisely

PCI DSS Requirement 11.4 calls for penetration testing of the cardholder data environment at least annually and after any significant infrastructure or application change — covering both the network layer and, where applicable, the application layer. If you rely on network segmentation to keep systems out of PCI scope, 11.4.5 additionally requires testing that the segmentation controls actually hold under attack, not just that they're configured as documented.

11.4 penetration testing vs. ASV scanning — the distinction that matters

These get conflated often enough that it's worth stating plainly: Requirement 11.3.2 requires quarterly external vulnerability scans by a PCI SSC-Approved Scanning Vendor (ASV) — an automated, certified-vendor scan with its own accreditation requirement. Requirement 11.4 penetration testing is a separate, deeper, manual requirement that PCI DSS explicitly allows to be performed by "a qualified internal resource or qualified external third party" — no ASV certification required. This service is 11.4 penetration testing. If you still need quarterly ASV scans, that's a different, separately-accredited service you'll need from an ASV-listed vendor.

What's typically in scope

Systems that store, process, or transmit cardholder data, and anything connected to them: payment application components, the network segments routing to the CDE, and any systems your segmentation is meant to isolate. Scope is defined against your actual network diagram and CDE boundary during the scoping call — precise scope matters here both for compliance validity and for cost.

Questions about PCI DSS testing

Requirement 11.4 requires penetration testing of the cardholder data environment (CDE) at least annually and after significant changes — both external and internal, plus testing to validate that any network segmentation isolating the CDE actually holds. That's the requirement this engagement is built for.

No, and this is worth being precise about. PCI DSS Requirement 11.3.2 requires quarterly external vulnerability scans by a PCI SSC-Approved Scanning Vendor (ASV) — that's a separate, automated-scan requirement with its own certification. Requirement 11.4 penetration testing is different: deeper, manual, and can be performed by "a qualified internal resource or qualified external third party" without ASV accreditation. This service covers 11.4 penetration testing, not ASV scanning — if you need ASV scans too, that's a separate vendor.

Yes — segmentation testing is explicitly required under 11.4.5 if you're relying on network segmentation to reduce PCI scope. Testing confirms whether the CDE is actually isolated from the rest of your network, or whether a path exists that would pull other systems into scope.

The cardholder data environment and any systems connected to it: payment processing components, the networks that route to them, and — if applicable — the web application handling card data or tokens. Scope is defined precisely during the call against your actual CDE diagram, not assumed.

5 to 10 business days depending on CDE size and whether segmentation testing is in scope. If you're working against a QSA deadline, say so during scoping.

From $500 for a focused application-layer test, from $1,500 where network segmentation and infrastructure testing are included. See the pricing page for details.

Get your Requirement 11.4 evidence sorted

Free scoping call, fixed-price proposal within 24 hours.

See pricing