PCI DSS v4.0.1 and Penetration Testing
The security standard for entities that store, process, transmit, or can affect the security of payment card data.
Planning testing under PCI DSS v4.0.1
Start with the Cardholder Data Environment, or CDE, and systems that can affect its security rather than only the payment page.

- Create data flows and an asset inventory to identify the CDE, connected-to systems, and security-impacting systems before planning tests.
- Requirement 11.4 calls for internal and external testing at least every 12 months and after significant infrastructure or application changes.
- Cover both network and application layers, including relevant threats and vulnerabilities from the prior 12 months.
- Where network segmentation reduces scope, test its effectiveness under the standard's conditions, remediate exploitable findings, and retest before relying on the evidence.
PAYMENT CARD INDUSTRY DATA SECURITY STANDARD
The security standard for entities that store, process, transmit, or can affect the security of payment card data.
Penetration Testing requirements
- PCI DSS is published by the PCI Security Standards Council and applies to merchants, acquirers, issuers, processors, and service providers within the Cardholder Data Environment (CDE).
- Requirement 11.4 requires internal and external testing at least once every 12 months and after significant infrastructure or application upgrades or changes.
- The methodology must address network and application layers, including vulnerabilities and threats experienced during the previous 12 months. Exploitable findings must be corrected and retested.
- When network segmentation is used to reduce PCI DSS scope, its effectiveness must be tested at the frequency and under the conditions specified by the standard.
Scope, frequency, tester qualification, and evidence depend on the entity and assessment method, such as SAQ or ROC. Confirm the current PCI DSS v4.0.1 text with your QSA or Compliance team.
Requirements and Testing Scope Matrix
Summary of the referenced clauses, the testing scope they cover, and the expected evaluation cycle.
| Reference | Mandate Title | Scope Required | Testing Cycle |
|---|---|---|---|
| Requirement 11.4 | External and Internal Penetration Testing | Entire Cardholder Data Environment (CDE) | At least annually |
| Requirement 11.4.5 | CDE Segmentation Isolation Verification | Segmentation controls for any entity using segmentation | At least annually and after segmentation changes |
| Requirement 11.4.6 | CDE Segmentation Isolation Verification (Service Providers) | Network Segmentation Controls (Service Providers) | Every 6 months and after segmentation changes |
Compliance Readiness Self-Assessment
Select items your organization has completed to evaluate your readiness score.
