PCI DSS Penetration Testing

External, internal, and segmentation testing that satisfies PCI DSS v4.0 Requirement 11.4, with a report accepted by your QSA and acquiring bank

If your business processes, stores, or transmits payment card data, an e-commerce store, a payment gateway, a fintech app, or any system connected to a cardholder data environment (CDE), PCI DSS v4.0 requires you to run an annual penetration test, and again after any significant change to your infrastructure. We deliver the full scope of Requirement 11.4, with a report your finance and compliance team can read before your engineers need to, accepted as-is by your QSA and acquiring bank.

QSA-Accepted Report

A formal Validation Report built to satisfy PCI DSS auditors, acquiring banks, and cyber-insurance providers.

Full Requirement 11.4 Coverage

External, internal, and segmentation testing, everything PCI DSS v4.0 requires, from 11.4.1 through 11.4.5.

Globally Recognized Methodologies

OWASP Testing Guide, PTES, and NIST SP 800-115, with every finding scored using CVSS v3.1.

Free Retest Included

Once issues are remediated, we run a scoped retest and deliver a final validation report ready for your audit.

What Does PCI DSS v4.0 Actually Require?

The standard doesn't ask for a single "penetration test", it defines specific items under Requirement 11.4:

RequirementWhat's RequiredFrequency
11.4.1A documented penetration testing methodology approved by managementAnnually
11.4.2Internal penetration testing of the cardholder data environment (CDE)Annually + after any significant change
11.4.3External penetration testing of the network perimeter and exposed systemsAnnually + after any significant change
11.4.4Remediation of all identified vulnerabilities, with retesting to confirm closureWhenever issues are found
11.4.5Segmentation testing, if segmentation is used to reduce audit scopeEvery 6 months for service providers, annually for merchants

Important distinction: this is entirely separate from quarterly ASV scans (Requirement 11.3), which must be performed by a PCI SSC-certified Approved Scanning Vendor. We are not a certified ASV, our role is deep, manual penetration testing, and we're happy to coordinate with your existing ASV provider if you need one.

The Testing Scope We Cover

External CDE Testing

Simulating an external attacker against every internet-facing touchpoint connected to your cardholder data environment.

Internal Network Testing

Assessing whether an attacker or compromised employee could move laterally toward payment card data from inside the network.

Segmentation Testing

Verifying that the isolation between your cardholder data environment and the rest of the network actually holds.

Payment Flow & Checkout Testing

Deep application-layer testing of your checkout flow and any APIs connected to the payment gateway.

What You Get in the Report

  1. Executive Summary: one page written for finance and compliance leadership, not just engineers.
  2. Findings scored with CVSS v3.1: Critical / High / Medium / Low / Info, ranked by priority.
  3. Proof-of-Concept evidence: exploitation steps and screenshots for every critical finding.
  4. Risk Matrix and Remediation Roadmap: a practical timeline that balances priority against your audit deadline.
  5. Free retest and final validation report: a Validation Report accepted by your QSA and acquiring bank.

How We Work With You

  1. Free scoping call: together we define the boundaries of your cardholder data environment (CDE) and connected systems.
  2. Signed NDA and scope of work: an agreed testing window that won't disrupt your operations.
  3. Testing execution: external, internal, and segmentation testing per the agreed scope.
  4. Report delivery: Executive Summary and full technical report within days of test completion.
  5. Remediation support: we walk your engineering team through closing each finding, in priority order.
  6. Retest and final validation report: ready to hand to your auditor ahead of your deadline.

Frequently Asked Questions

Who specifically needs PCI DSS penetration testing?

Any organization that processes, stores, or transmits payment card data: e-commerce stores, payment gateways, fintech apps, collection agencies, and any system connected to a cardholder data environment (CDE), regardless of size, though the required depth scales with your payment volume (Merchant Level).

How often does PCI DSS v4.0 require penetration testing?

At minimum once a year (Requirements 11.4.2/11.4.3), and mandatorily after any significant change to infrastructure or applications connected to the CDE, a new payment gateway, a server migration, or a major network change. Segmentation testing (11.4.5) is required every 6 months for service providers, annually for merchants.

What's the difference between an ASV scan and a penetration test?

An ASV scan (Requirement 11.3) is a mandatory quarterly automated vulnerability scan, performed only by a PCI SSC-certified Approved Scanning Vendor. A penetration test (Requirement 11.4) is a deeper manual assessment performed annually. We perform the manual penetration testing, we are not a certified ASV.

What is segmentation testing, and when do I need it?

If you rely on network segmentation to isolate your cardholder data environment from the rest of the network in order to reduce audit scope, the standard requires you to actually verify that isolation holds and can't be bypassed, that's exactly what segmentation testing does.

Are you a certified QSA?

No. We are a specialized penetration testing provider, not a PCI SSC-certified Qualified Security Assessor (QSA). Our reports are built to fully satisfy Requirement 11.4 and are accepted by your QSA as part of your compliance file, but the full compliance assessment itself is a separate role performed by a formally certified QSA.

What happens if vulnerabilities are found close to my audit deadline?

We prioritize findings against the time available, focusing first on anything that could block your audit. Once your team remediates them, we run a fast, scoped retest limited to the identified issues and deliver the final validation report with enough lead time to hand to your auditor.

How long does this take, and what does it cost?

It depends on the size of your cardholder data environment and the number of connected systems. A mid-sized scope typically takes 1-3 weeks of execution. We provide an accurate quote after a free scoping call.

Get Ready for Your Next PCI DSS Audit

Free scoping call, accurate quote within 24 hours

+20 102 777 0444

Guides to help you decide

Get a FREE 30-Minute Consultation

With one of our expert specialists!

We discuss your needs and provide the best solutions for your project.

Consulting illustration