PCI DSS Penetration Testing for Requirement 11.4
PCI DSS v4.0 requirement 11.4 requires internal and external penetration testing at least every twelve months and after significant changes, plus segmentation testing where segmentation reduces scope. Scantra Security delivers PCI DSS penetration testing of your cardholder data environment with reports your QSA can rely on.
Last reviewed 2026-09-28 by the Scantra Security testing team
What requirement 11.4 asks for
- A documented penetration testing methodology based on industry standards
- External testing of the CDE perimeter and critical systems
- Internal testing from inside the network
- Application-layer testing of in-scope applications
- Segmentation testing, every six months for service providers
- Correction of exploitable vulnerabilities and retesting
Our PCI testing methodology
Our methodology follows PTES and NIST SP 800-115 and covers the network and application layers. We document it clearly so your QSA can confirm it meets 11.4.1.
Process
1. CDE scoping
Confirm cardholder data flows and segmentation boundaries.
2. External and internal testing
Network and application layer testing.
3. Segmentation testing
Prove out-of-scope networks cannot reach the CDE.
4. Free retest and certificate
We verify fixes at no extra cost and issue an updated report and certificate.
Merchants and service providers
Merchants and service providers have slightly different frequencies for segmentation testing. We plan your schedule accordingly.
Frequently asked questions
Is a vulnerability scan enough for PCI?
No. Requirement 11.3 covers scans, and 11.4 separately requires penetration testing.
Do you test segmentation?
Yes, segmentation testing is included when you rely on it to reduce scope.
Can you work with our QSA?
Yes, we can join calls with your QSA to explain methodology and results.
