The PCI DSS Penetration Testing Requirement

The Payment Card Industry Data Security Standard (PCI DSS) is explicit and non-negotiable about penetration testing. Requirement 11.4, updated in PCI DSS 4.0 (which became fully mandatory in March 2024), requires all entities that store, process, or transmit cardholder data to conduct penetration testing at least once every 12 months and after any significant infrastructure or application upgrade or change.

Unlike some frameworks that treat penetration testing as implied, PCI DSS specifies exactly what testing must cover:

  • External penetration testing of the cardholder data environment (CDE) perimeter
  • Internal penetration testing of the CDE
  • Testing of segmentation controls: verifying that systems out of scope are actually isolated from the CDE
  • Application-layer testing (not just network-layer) for any web-facing systems in scope

PCI DSS 4.0 Changes That Affect Penetration Testing

PCI DSS 4.0 introduced several changes relevant to penetration testing. The renumbering moved penetration testing to Requirement 11.4 (from 11.3 in the prior version). More significantly, 4.0 added explicit requirements for penetration testing methodology documentation, increased focus on application-layer testing, and added requirements around the tester's qualifications, specifically that the tester must be organizationally independent from the entity being tested.

Who Can Conduct PCI DSS Penetration Testing?

PCI DSS requires the tester to be organizationally independent, meaning internal staff cannot test the systems they manage. The standard allows either a qualified internal resource from a different team or an external firm. In practice, most QSAs and their clients use external firms to avoid independence concerns and to bring a genuinely adversarial perspective. Grid32 qualifies as an independent external testing firm for PCI DSS purposes.

Segmentation Testing

One area where organizations frequently fall short is segmentation testing. PCI DSS requires that if you are using network segmentation to reduce the scope of your CDE, you must verify that the segmentation is actually effective through testing. This means specifically attempting to cross the segmentation boundary, something many organizations neglect or only superficially address.

What Your QSA Will Request

Your Qualified Security Assessor will typically request the penetration test report, the tester's qualifications, the methodology used, evidence that all required components were in scope, segmentation test results, and documentation of finding remediation. Grid32 provides all of this in a format designed to satisfy QSA review.

PCI DSS Testing Requirements at a Glance

Requirement 11.4 breaks into several components. Segmentation testing frequency is the detail organizations most often get wrong: service providers must test every six months, merchants at least annually.

RequirementFrequencyReference
External penetration test of the CDEAnnually and after significant change11.4.3
Internal penetration test of the CDEAnnually and after significant change11.4.3
Segmentation testing (merchants)At least annually11.4.5
Segmentation testing (service providers)At least every 6 months11.4.6
Application-layer testing of in-scope systemsAnnually and after significant change11.4.3

How Scope Determines Your PCI Test

The size and cost of a PCI penetration test are driven almost entirely by the size of your cardholder data environment. Effective network segmentation that isolates the CDE from the rest of your network reduces what is in scope, which reduces both risk and testing effort. That is why the standard treats segmentation testing so seriously: if the boundary is not actually enforced, the entire connected network is in scope. Grid32 helps confirm your segmentation holds and scopes the external and internal testing to the environment that truly touches cardholder data. For how scope translates into price, see our pricing guide.

Frequently Asked Questions

What does PCI DSS require for penetration testing?

PCI DSS Requirement 11.4 requires external and internal penetration testing at least annually and after significant changes, plus segmentation testing where segmentation isolates the cardholder data environment. Testing must follow an industry-accepted methodology and be performed by a qualified tester.

What changed for penetration testing in PCI DSS 4.0?

PCI DSS 4.0 keeps the annual testing requirement and reinforces documented methodology, targeted risk analysis for certain activities, and more rigorous segmentation testing. Organizations should confirm their testing scope and cadence still meet the 4.0 language ahead of their next assessment.

Who can perform PCI DSS penetration testing?

PCI requires a qualified, organizationally independent tester. That can be an internal resource with proven independence and skills or a third party such as Grid32. Your QSA will request the tester's qualifications, scope, methodology, and the full report as evidence.

Satisfy your PCI DSS Requirement 11.4

Grid32 conducts PCI DSS-scoped penetration tests including segmentation validation. Our reports are formatted to satisfy QSA evidence requirements directly.

Get a Quote →