PCI DSS 4.0 Penetration Testing
Requirement 11.4 internal and external penetration testing, plus the segmentation validation you need if you rely on segmentation to reduce scope.
How testing supports PCI DSS 4.0
PCI DSS is unusually explicit: Requirement 11.4 mandates internal and external penetration testing at least annually and after any significant change, following a defined methodology. If you use network segmentation to keep systems out of the cardholder data environment, 11.4.5 requires you to test that the segmentation actually works. We scope directly to these requirements and produce a report your QSA can accept.
What a test evidences
A single engagement produces evidence across these areas of PCI DSS 4.0.
Requirement 11.4.3
External penetration testing of the cardholder data environment and its exposed services.
Requirement 11.4.2
Internal penetration testing from within your network toward the CDE.
Requirement 11.4.5
Segmentation testing to prove that out-of-scope networks cannot reach the CDE.
Defined methodology
Testing follows an industry methodology (NIST SP 800-115), as 11.4.1 requires.
Evidence for every framework at once
Most organizations answer to several frameworks, not one.
We scope a single penetration test so its findings and evidence serve PCI DSS 4.0 alongside the other standards your auditors, customers and insurers ask about — instead of running overlapping engagements for each.
| Finding | Severity | Maps to |
|---|---|---|
| Cross-tenant data access | Critical | PCI |
| Over-privileged access | High | PCI |
| Weak session handling | Medium | PCI |
PCI DSS 4.0 testing, answered
What counts as a significant change?
New systems in the CDE, changes to segmentation, network or application architecture changes, or infrastructure upgrades. Any of these triggers a retest under 11.4 independent of the annual cycle.
Do you test segmentation separately?
Yes. Segmentation testing under 11.4.5 is its own activity — proving that networks you have declared out of scope genuinely cannot reach the cardholder data environment.
Other frameworks we test against
SOC 2
Independent testing evidence for the Common Criteria and the vendor questionnaires that gate enterprise deals.
HIPAA
The technical half of a Security Rule risk analysis for providers, payers and digital health.
CMMC 2.0
NIST SP 800-171 and DFARS evidence for defense contractors handling controlled unclassified information.
Testing for PCI DSS 4.0?
Tell us the framework and the deadline. We scope to the evidence your assessor needs.