Payment Security Testing

PCI DSS Penetration Testing

PCI DSS 4.0–aligned penetration testing for merchants and service providers — internal, external, and segmentation testing under Requirement 11.4, with documentation built for your QSA or assessor.

The Requirement

PCI DSS Requirement 11.4, Explained

PCI DSS 4.0 Requirement 11.4 requires regular penetration testing of the cardholder data environment from both inside and outside the network, using a defined methodology — and testing of any segmentation controls you rely on to reduce scope.

Testing must be performed by a qualified resource who is organizationally independent of the systems under test, and exploitable vulnerabilities must be corrected and retested.

Requirement 11.4 at a glance

  • 11.4.1 — Documented, industry-accepted methodology
  • 11.4.2 — Internal testing every 12 months and after significant change
  • 11.4.3 — External testing every 12 months and after significant change
  • 11.4.4 — Exploitable vulnerabilities corrected and retested
  • 11.4.5 — Segmentation testing every 12 months and after changes
  • 11.4.6 — Service providers: segmentation testing every six months
What We Test

Testing the Cardholder Data Environment

Scope is built around your cardholder data environment (CDE) and every system that can affect its security.

CDE Perimeter

External and internal testing of the boundary around systems that store, process, or transmit card data.

Segmentation Controls

Verifying that out-of-scope networks truly cannot reach the CDE — the test that keeps your scope small.

Payment Applications

E-commerce checkout, payment pages, and custom payment applications at the application layer.

APIs and Integrations

Payment gateway integrations, tokenization services, and APIs connected to the payment flow.

Internal Network

What an attacker with an internal foothold could reach — privilege escalation and lateral movement toward the CDE.

Cloud-Hosted CDE

AWS and Azure environments in PCI scope. See Cloud Penetration Testing.

Deliverables

Documentation That Satisfies Your Assessor

  • Documented testing methodology aligned to 11.4.1
  • Scope definition referencing your CDE and data flows
  • Findings with severity ratings and evidence
  • Segmentation test results
  • Remediation guidance and retest evidence
  • Executive summary and attestation letter
Who It's For

Merchants, Processors, and Service Providers

  • Merchants at PCI Levels 1 through 4
  • Payment processors and gateways
  • Service providers that store, process, or transmit card data
  • SaaS platforms in the payment flow
  • Organizations using segmentation to reduce PCI scope
FAQ

PCI Penetration Testing FAQs

What are the PCI pen test requirements?

Requirement 11.4 calls for a documented, industry-accepted methodology; internal and external penetration testing; correction and retesting of exploitable vulnerabilities; and testing of any segmentation controls used to reduce PCI scope.

How often is PCI penetration testing required?

Internal and external testing at least once every 12 months and after any significant infrastructure or application change. Segmentation testing is required at least every 12 months for merchants and at least every six months for service providers, plus after changes to segmentation controls.

Is an ASV scan the same as a PCI pen test?

No. Quarterly ASV scans (Requirement 11.3.2) are automated external vulnerability scans. Penetration testing under 11.4 is a deeper, manual exercise that validates whether vulnerabilities can be exploited. Most environments need both.

Who can perform a PCI penetration test?

A qualified internal resource or a qualified external third party. The tester must be organizationally independent of the systems being tested — a common reason organizations choose a third-party provider.

Does my SAQ require penetration testing?

It depends on your SAQ type and how card data flows through your environment. SAQ D includes Requirement 11.4 in full. We'll confirm applicability during scoping.

Get Started

Get Ready for Your PCI Assessment

Share your CDE scope, segmentation approach, and assessment timeline. We'll plan internal, external, and segmentation testing around Requirement 11.4 and deliver documentation your assessor can review without back-and-forth.

Contact Us

Get Started with Privaxi Testing Services

Don’t wait for an attack to reveal the weaknesses in your defenses. Take a proactive approach by scheduling a comprehensive assessment ofyour systems. Our Testing and Assessment Services will help you understand your vulnerabilities and fortify your defenses.