Dunicot A cybersecurity consultancy and advisory firm.

Framework · PCI DSS

PCI DSS penetration testing

PCI DSS is the one framework in this list that names penetration testing outright, states how often, and specifies what the methodology must cover. That makes it the least ambiguous and the least forgiving.

Overview

Internal, external and segmentation testing under requirement 11.4, documented the way a QSA expects to receive it.

Framework reference

Standard
PCI DSS v4.0, requirement 11.4
Frequency
At least annually, and after any significant infrastructure or application change
Scope
External and internal testing of the cardholder data environment and connected systems
Segmentation
Where segmentation reduces scope, it must be tested, every six months for service providers
Methodology
Must be documented and industry-accepted; reports reference PTES, OWASP WSTG and NIST SP 800-115
Retest
Exploitable vulnerabilities must be corrected and testing repeated to verify the correction

What the framework requires

Requirement 11.4.2 covers internal testing and 11.4.3 external testing, both annually and after significant change. Requirement 11.4.1 requires the methodology itself to be defined, documented and industry-accepted.

Requirement 11.4.5 requires segmentation testing where segmentation isolates the cardholder data environment from other networks: at least annually, and every six months for service providers.

Requirement 11.4.4 requires that exploitable vulnerabilities and security weaknesses found are corrected and that testing is repeated to verify the corrections. The retest is not optional, and the evidence has to show it happened.

What the engagement delivers

01

Full 11.4 coverage

Internal, external and segmentation testing delivered as one engagement, mapped requirement by requirement.

02

Documented methodology

The written methodology required by 11.4.1, referencing PTES, OWASP WSTG and NIST SP 800-115, provided as an engagement artefact.

03

Segmentation evidence

Every expected-blocked path between the cardholder data environment and other networks actively attempted, with the result recorded per path.

04

Scope validation

Where cardholder data really flows, including logs, backups, error reporting and analytics, versus where the documented scope says it does.

05

Correction and repeat testing

The retest cycle required by 11.4.4, with evidence tying each correction to a verified re-test.

06

QSA-ready packaging

Scope, dates, methodology, tester qualification, findings, corrections and verification in the structure your assessor expects.

Questions

How often does PCI DSS require penetration testing?

At least annually for both internal and external testing, and after any significant infrastructure or application change. Segmentation testing is at least annual for merchants and at least every six months for service providers.

What is segmentation testing?

Active verification that the controls isolating your cardholder data environment do block traffic. Every expected-blocked path is attempted from the out-of-scope side and the result recorded, which turns the network diagram into evidence.

Who is qualified to perform PCI penetration testing?

PCI DSS requires an appropriately qualified internal resource or a qualified external third party with organisational independence. Testing is performed by an OSCP, LPT Master and CPENT certified tester, with certification details included in the report for your assessor.

Can you reduce our PCI scope?

Scope reduction is an architecture exercise, but testing informs it directly: the engagement identifies where cardholder data reaches, which frequently differs from the documented flow. Once segmentation is in place, its effectiveness is what gets tested.

How much does PCI DSS penetration testing cost?

Cost follows the cardholder data environment rather than the whole estate: in-scope hosts, the number of segmentation zone pairs, and whether application testing is included. Reducing scope before testing usually reduces cost more than negotiating the rate.

Does PCI DSS 4.0 change the testing requirements?

The testing requirement itself is broadly consistent, but 4.0 tightens the surrounding expectations: scope must be documented and confirmed at least annually, and the targeted risk analysis behind any frequency decision must be written down. Testing evidence is now read alongside that documentation.

What counts as segmentation testing?

Attempting every expected-blocked path between every pair of in-scope zones and recording the result, rather than reviewing the firewall rules. A rule that exists and a path that is blocked are different claims, and only the second one is evidence.

Do you provide the ASV scan as well?

No. Approved Scanning Vendor scans are a separate requirement performed by an ASV-listed provider, and we do not claim that listing. Penetration testing is the deeper, manual requirement alongside it, and we will say plainly which of the two you are buying.

Testing for your PCI DSS deadline

Tell us the audit date and the scope. Engagements are scheduled backwards from your deadline so remediation and retest both land inside it.