Requirement 11.4 is prescriptive. You need a documented penetration-testing methodology (11.4.1), external penetration testing at least annually and after significant change (11.4.3), internal penetration testing on the same cadence (11.4.2), correction and retesting of exploitable findings (11.4.4), and, if you use segmentation to reduce scope, segmentation penetration testing to prove those controls isolate the cardholder data environment (11.4.5 and 11.4.6). Service providers face the tighter six-month segmentation cadence.
We scope every engagement against your defined CDE and run all of it, network and application layers, external and internal perimeters, and the segmentation boundaries, then document the results against each sub-requirement. Because we are a QSA company, the report is written in the form your assessor expects to receive, which removes the usual round of clarifying questions.
The engagement is scoped and documented by a QSA company, so it produces compliance evidence, not just a technical report your assessor then has to interpret.
Most PCI penetration-testing problems are documentation and scope problems, not testing problems. An assessor will reject a test that misses the internal perimeter, omits segmentation testing where segmentation is claimed, uses the wrong cadence for a service provider, or lacks evidence that exploitable findings were corrected and retested. A scan mislabelled as a penetration test is the classic rejection.
Scoping the work as a QSA company from the outset removes these failure modes, because the test is built against the requirement, not adapted to it afterwards.
Every one of these is avoidable by scoping to the requirement up front. As a QSA company, that is exactly how we build the engagement.
The penetration-testing sub-requirements under PCI DSS v4.0.1 and what each one means for your test scope.
| Sub-requirement | What it requires | How we cover it |
|---|---|---|
| 11.4.1 | A defined, documented, industry-accepted penetration testing methodology | We provide the methodology and map the engagement to it |
| 11.4.2 | Internal penetration testing at least annually and after significant change | Internal testing of critical systems inside the CDE |
| 11.4.3 | External penetration testing at least annually and after significant change | External testing of the CDE perimeter and exposed services |
| 11.4.4 | Correction of exploitable vulnerabilities and retesting | Remediation guidance plus a free retest of fixed findings |
| 11.4.5 / 11.4.6 | Segmentation controls tested to confirm CDE isolation | Segmentation testing at your required cadence (6 or 12 months) |
Based on PCI DSS v4.0.1 Requirement 11.4. Service providers must perform segmentation testing at least every six months; merchants at least annually.
Send your CDE scope or SAQ type and we’ll scope a Requirement 11.4 test that your assessor will accept, with a fixed quote within one working day.