PCI DSS Penetration Testing
PCI DSS 4.0–aligned penetration testing for merchants and service providers — internal, external, and segmentation testing under Requirement 11.4, with documentation built for your QSA or assessor.

PCI DSS Requirement 11.4, Explained
PCI DSS 4.0 Requirement 11.4 requires regular penetration testing of the cardholder data environment from both inside and outside the network, using a defined methodology — and testing of any segmentation controls you rely on to reduce scope.
Testing must be performed by a qualified resource who is organizationally independent of the systems under test, and exploitable vulnerabilities must be corrected and retested.
Requirement 11.4 at a glance
- 11.4.1 — Documented, industry-accepted methodology
- 11.4.2 — Internal testing every 12 months and after significant change
- 11.4.3 — External testing every 12 months and after significant change
- 11.4.4 — Exploitable vulnerabilities corrected and retested
- 11.4.5 — Segmentation testing every 12 months and after changes
- 11.4.6 — Service providers: segmentation testing every six months
Testing the Cardholder Data Environment
Scope is built around your cardholder data environment (CDE) and every system that can affect its security.
CDE Perimeter
External and internal testing of the boundary around systems that store, process, or transmit card data.
Segmentation Controls
Verifying that out-of-scope networks truly cannot reach the CDE — the test that keeps your scope small.
Payment Applications
E-commerce checkout, payment pages, and custom payment applications at the application layer.
APIs and Integrations
Payment gateway integrations, tokenization services, and APIs connected to the payment flow.
Internal Network
What an attacker with an internal foothold could reach — privilege escalation and lateral movement toward the CDE.
Documentation That Satisfies Your Assessor
- Documented testing methodology aligned to 11.4.1
- Scope definition referencing your CDE and data flows
- Findings with severity ratings and evidence
- Segmentation test results
- Remediation guidance and retest evidence
- Executive summary and attestation letter
Merchants, Processors, and Service Providers
- Merchants at PCI Levels 1 through 4
- Payment processors and gateways
- Service providers that store, process, or transmit card data
- SaaS platforms in the payment flow
- Organizations using segmentation to reduce PCI scope
PCI Penetration Testing FAQs
What are the PCI pen test requirements?
Requirement 11.4 calls for a documented, industry-accepted methodology; internal and external penetration testing; correction and retesting of exploitable vulnerabilities; and testing of any segmentation controls used to reduce PCI scope.
How often is PCI penetration testing required?
Internal and external testing at least once every 12 months and after any significant infrastructure or application change. Segmentation testing is required at least every 12 months for merchants and at least every six months for service providers, plus after changes to segmentation controls.
Is an ASV scan the same as a PCI pen test?
No. Quarterly ASV scans (Requirement 11.3.2) are automated external vulnerability scans. Penetration testing under 11.4 is a deeper, manual exercise that validates whether vulnerabilities can be exploited. Most environments need both.
Who can perform a PCI penetration test?
A qualified internal resource or a qualified external third party. The tester must be organizationally independent of the systems being tested — a common reason organizations choose a third-party provider.
Does my SAQ require penetration testing?
It depends on your SAQ type and how card data flows through your environment. SAQ D includes Requirement 11.4 in full. We'll confirm applicability during scoping.

Get Ready for Your PCI Assessment
Share your CDE scope, segmentation approach, and assessment timeline. We'll plan internal, external, and segmentation testing around Requirement 11.4 and deliver documentation your assessor can review without back-and-forth.
Get Started with Privaxi Testing Services
Don’t wait for an attack to reveal the weaknesses in your defenses. Take a proactive approach by scheduling a comprehensive assessment ofyour systems. Our Testing and Assessment Services will help you understand your vulnerabilities and fortify your defenses.
