The PCI DSS Penetration Testing Requirement

The Payment Card Industry Data Security Standard (PCI DSS) is explicit and non-negotiable about penetration testing. Requirement 11.4, updated in PCI DSS 4.0 (which became fully mandatory in March 2024), requires all entities that store, process, or transmit cardholder data to conduct penetration testing at least once every 12 months and after any significant infrastructure or application upgrade or change.

Unlike some frameworks that treat penetration testing as implied, PCI DSS specifies exactly what testing must cover:

  • External penetration testing of the cardholder data environment (CDE) perimeter
  • Internal penetration testing of the CDE
  • Testing of segmentation controls — verifying that systems out of scope are actually isolated from the CDE
  • Application-layer testing (not just network-layer) for any web-facing systems in scope

PCI DSS 4.0 Changes That Affect Penetration Testing

PCI DSS 4.0 introduced several changes relevant to penetration testing. The renumbering moved penetration testing to Requirement 11.4 (from 11.3 in the prior version). More significantly, 4.0 added explicit requirements for penetration testing methodology documentation, increased focus on application-layer testing, and added requirements around the tester's qualifications — specifically that the tester must be organizationally independent from the entity being tested.

Who Can Conduct PCI DSS Penetration Testing?

PCI DSS requires the tester to be organizationally independent — meaning internal staff cannot test the systems they manage. The standard allows either a qualified internal resource from a different team or an external firm. In practice, most QSAs and their clients use external firms to avoid independence concerns and to bring a genuinely adversarial perspective. Grid32 qualifies as an independent external testing firm for PCI DSS purposes.

Segmentation Testing

One area where organizations frequently fall short is segmentation testing. PCI DSS requires that if you are using network segmentation to reduce the scope of your CDE, you must verify that the segmentation is actually effective through testing. This means specifically attempting to cross the segmentation boundary — something many organizations neglect or only superficially address.

What Your QSA Will Request

Your Qualified Security Assessor will typically request the penetration test report, the tester's qualifications, the methodology used, evidence that all required components were in scope, segmentation test results, and documentation of finding remediation. Grid32 provides all of this in a format designed to satisfy QSA review.

Satisfy your PCI DSS Requirement 11.4

Grid32 conducts PCI DSS-scoped penetration tests including segmentation validation. Our reports are formatted to satisfy QSA evidence requirements directly.

Get a Quote →