PCI DSS Penetration Testing

PCI DSS is unusually specific about penetration testing. Requirement 11.4 mandates internal and external penetration tests at least annually and after significant change, plus segmentation testing to prove your cardholder data environment is properly isolated.

RedSecLabs delivers PCI DSS penetration testing to the letter of Requirement 11.4, backed by the fact that we operate as a PCI Qualified Security Assessor (QSA). That means the test is scoped, executed and documented the way an assessor needs to see it, covering the network and application layers, the CDE boundary, and the segmentation controls your compliance depends on.

CREST Certified Pen Test Provider ISO Certified OSCP Certified Industry Certification

Get a Free Security Quote

Tell us what needs testing and we’ll return a fixed, scoped quote within one working day.

Scoped quote within one working day. NDA available on request. No mailing lists.

PCI QSA company · CREST-accredited testers · Covers Req 11.4.1–11.4.6 · Segmentation testing included · Assessor-ready report
Who this is for

This service fits if you’re..

1
Annual 11.4 testing
Merchants and service providers needing their mandatory annual internal and external penetration test.
2
Post-change testing
Organisations that have made significant changes to the CDE and must retest before their assessment.
3
Segmentation reliance
Anyone using network segmentation to reduce PCI scope, who must prove it works at least every 6 or 12 months.

PCI DSS Penetration Testing, Quick Facts

Last reviewed: 2026-07-21
Governing requirement
PCI DSS v4.0.1 Requirement 11.4, internal and external penetration testing plus segmentation testing
Mandatory
Yes, explicitly. Annual testing and testing after significant change are required, not optional
Segmentation testing
Required at least every 6 months for service providers and at least annually for merchants where segmentation isolates the CDE
Methodology
Must follow an industry-accepted approach and cover the CDE perimeter and critical systems, application and network layers
Who scopes it
We do, as a QSA company we scope to your CDE and the defined-in requirements of 11.4
Deliverable
A report evidencing 11.4.1–11.4.6, suitable for your QSA or SAQ evidence
11.4
The requirement it satisfies
v4.0.1
Current PCI DSS version
6–12 mo
Segmentation test cadence
QSA
Company accreditation held

What Requirement 11.4 actually demands

Requirement 11.4 is prescriptive. You need a documented penetration-testing methodology (11.4.1), external penetration testing at least annually and after significant change (11.4.3), internal penetration testing on the same cadence (11.4.2), correction and retesting of exploitable findings (11.4.4), and, if you use segmentation to reduce scope, segmentation penetration testing to prove those controls isolate the cardholder data environment (11.4.5 and 11.4.6). Service providers face the tighter six-month segmentation cadence.

We scope every engagement against your defined CDE and run all of it, network and application layers, external and internal perimeters, and the segmentation boundaries, then document the results against each sub-requirement. Because we are a QSA company, the report is written in the form your assessor expects to receive, which removes the usual round of clarifying questions.

What our PCI DSS penetration test covers:
External penetration testing of the CDE perimeter (11.4.3)
Internal penetration testing of critical systems (11.4.2)
Application-layer testing for the in-scope applications
Segmentation testing to prove CDE isolation (11.4.5 / 11.4.6)
Correction and free retesting of exploitable findings (11.4.4)
A report structured against each 11.4 sub-requirement for your QSA

The engagement is scoped and documented by a QSA company, so it produces compliance evidence, not just a technical report your assessor then has to interpret.

Why PCI tests fail the assessment

Most PCI penetration-testing problems are documentation and scope problems, not testing problems. An assessor will reject a test that misses the internal perimeter, omits segmentation testing where segmentation is claimed, uses the wrong cadence for a service provider, or lacks evidence that exploitable findings were corrected and retested. A scan mislabelled as a penetration test is the classic rejection.

Scoping the work as a QSA company from the outset removes these failure modes, because the test is built against the requirement, not adapted to it afterwards.

Common PCI DSS testing failures:
Vulnerability scan submitted where 11.4 requires a penetration test
Segmentation testing omitted while segmentation is used to reduce scope
Service provider using the annual cadence instead of six-monthly segmentation testing
Internal penetration test missing entirely, only external performed
No evidence exploitable findings were corrected and retested (11.4.4)
Report not mapped to sub-requirements, triggering assessor queries

Every one of these is avoidable by scoping to the requirement up front. As a QSA company, that is exactly how we build the engagement.

Need this scoped fast? Send your target list and we’ll return a fixed price within one working day.
Get a Fixed Quote

Requirement 11.4 at a glance

The penetration-testing sub-requirements under PCI DSS v4.0.1 and what each one means for your test scope.

Sub-requirementWhat it requiresHow we cover it
11.4.1A defined, documented, industry-accepted penetration testing methodologyWe provide the methodology and map the engagement to it
11.4.2Internal penetration testing at least annually and after significant changeInternal testing of critical systems inside the CDE
11.4.3External penetration testing at least annually and after significant changeExternal testing of the CDE perimeter and exposed services
11.4.4Correction of exploitable vulnerabilities and retestingRemediation guidance plus a free retest of fixed findings
11.4.5 / 11.4.6Segmentation controls tested to confirm CDE isolationSegmentation testing at your required cadence (6 or 12 months)

Based on PCI DSS v4.0.1 Requirement 11.4. Service providers must perform segmentation testing at least every six months; merchants at least annually.

PCI DSS Penetration Testing, Done by a QSA Company

Send your CDE scope or SAQ type and we’ll scope a Requirement 11.4 test that your assessor will accept, with a fixed quote within one working day.

Frequently Asked Questions

Yes, explicitly. Requirement 11.4 of PCI DSS v4.0.1 mandates internal and external penetration testing at least annually and after any significant change, plus segmentation testing where segmentation is used to reduce scope. Unlike some frameworks, PCI is prescriptive here, a vulnerability scan does not satisfy it.

They satisfy different requirements. ASV scanning (Requirement 11.3.2) is an automated quarterly external scan by an Approved Scanning Vendor. Penetration testing (11.4) is manual, deeper, covers internal and external perimeters and the application layer, and is performed at least annually. You need both. We provide both.

If you use network segmentation to isolate the cardholder data environment and reduce scope, service providers must test that segmentation at least every six months, and merchants at least annually. Testing must confirm the segmentation controls actually prevent access into the CDE.

Yes. Requirement 11.4 covers both network-layer and application-layer testing for systems in scope. For most environments that means external and internal network testing plus testing of the in-scope applications that handle or could reach cardholder data.

It changes how the engagement is scoped and documented. As a QSA company we know precisely what an assessor needs to see, so the test is scoped to your CDE against each 11.4 sub-requirement and the report is written as compliance evidence. That typically removes the clarification cycles that delay assessments.

Requirement 11.4.4 requires exploitable findings to be corrected and the testing repeated to verify the fix. We provide clear remediation guidance and include a retest of fixed findings, so your final report evidences that issues were closed rather than just identified.
📞 Call us Book a call