PCI DSS

PCI DSS Penetration Testing for Requirement 11.4

PCI DSS v4.0 requirement 11.4 requires internal and external penetration testing at least every twelve months and after significant changes, plus segmentation testing where segmentation reduces scope. Scantra Security delivers PCI DSS penetration testing of your cardholder data environment with reports your QSA can rely on.

Last reviewed 2026-09-28 by the Scantra Security testing team

What requirement 11.4 asks for

  • A documented penetration testing methodology based on industry standards
  • External testing of the CDE perimeter and critical systems
  • Internal testing from inside the network
  • Application-layer testing of in-scope applications
  • Segmentation testing, every six months for service providers
  • Correction of exploitable vulnerabilities and retesting

Our PCI testing methodology

Our methodology follows PTES and NIST SP 800-115 and covers the network and application layers. We document it clearly so your QSA can confirm it meets 11.4.1.

Process

  1. 1. CDE scoping

    Confirm cardholder data flows and segmentation boundaries.

  2. 2. External and internal testing

    Network and application layer testing.

  3. 3. Segmentation testing

    Prove out-of-scope networks cannot reach the CDE.

  4. 4. Free retest and certificate

    We verify fixes at no extra cost and issue an updated report and certificate.

Merchants and service providers

Merchants and service providers have slightly different frequencies for segmentation testing. We plan your schedule accordingly.

Frequently asked questions

Is a vulnerability scan enough for PCI?

No. Requirement 11.3 covers scans, and 11.4 separately requires penetration testing.

Do you test segmentation?

Yes, segmentation testing is included when you rely on it to reduce scope.

Can you work with our QSA?

Yes, we can join calls with your QSA to explain methodology and results.

Related services

Get started

Ready to find what attackers will?

Talk to a senior pentester. Get a tailored scope, sample report and timeline within 24 hours.