Payments

PCI DSS 4.0 Penetration Testing

Requirement 11.4 internal and external penetration testing, plus the segmentation validation you need if you rely on segmentation to reduce scope.

Overview

How testing supports PCI DSS 4.0

PCI DSS is unusually explicit: Requirement 11.4 mandates internal and external penetration testing at least annually and after any significant change, following a defined methodology. If you use network segmentation to keep systems out of the cardholder data environment, 11.4.5 requires you to test that the segmentation actually works. We scope directly to these requirements and produce a report your QSA can accept.

Where it maps

What a test evidences

A single engagement produces evidence across these areas of PCI DSS 4.0.

Requirement 11.4.3

External penetration testing of the cardholder data environment and its exposed services.

Requirement 11.4.2

Internal penetration testing from within your network toward the CDE.

Requirement 11.4.5

Segmentation testing to prove that out-of-scope networks cannot reach the CDE.

Defined methodology

Testing follows an industry methodology (NIST SP 800-115), as 11.4.1 requires.

One engagement

Evidence for every framework at once

Most organizations answer to several frameworks, not one.

We scope a single penetration test so its findings and evidence serve PCI DSS 4.0 alongside the other standards your auditors, customers and insurers ask about — instead of running overlapping engagements for each.

pci-dss-evidence.pdf
FindingSeverityMaps to
Cross-tenant data accessCriticalPCI
Over-privileged accessHighPCI
Weak session handlingMediumPCI
Questions

PCI DSS 4.0 testing, answered

What counts as a significant change?

New systems in the CDE, changes to segmentation, network or application architecture changes, or infrastructure upgrades. Any of these triggers a retest under 11.4 independent of the annual cycle.

Do you test segmentation separately?

Yes. Segmentation testing under 11.4.5 is its own activity — proving that networks you have declared out of scope genuinely cannot reach the cardholder data environment.

Testing for PCI DSS 4.0?

Tell us the framework and the deadline. We scope to the evidence your assessor needs.