Siam Thanat Hack Co., Ltd.

PCI DSS v4.0.1 and Penetration Testing

The security standard for entities that store, process, transmit, or can affect the security of payment card data.

Executive Summary and Mandate Overview
Target Audience Merchants, Payment Processors, Gateways, and E-commerce handling card data (CDE)
Mandatory Frequency Annually (Req 11.4). Every 6 months for CDE segmentation by service providers (Req 11.4.6)
Required Scope Cardholder Data Environment (CDE), Payment APIs, External and Internal Network
Non-Compliance Risk Monthly card brand fines ($5,000 to $100,000 per month) and loss of card processing privileges

Planning testing under PCI DSS v4.0.1

Start with the Cardholder Data Environment, or CDE, and systems that can affect its security rather than only the payment page.

Thai infographic explaining: Planning testing under PCI DSS v4.0.1
Visual summary: Planning testing under PCI DSS v4.0.1
  • Create data flows and an asset inventory to identify the CDE, connected-to systems, and security-impacting systems before planning tests.
  • Requirement 11.4 calls for internal and external testing at least every 12 months and after significant infrastructure or application changes.
  • Cover both network and application layers, including relevant threats and vulnerabilities from the prior 12 months.
  • Where network segmentation reduces scope, test its effectiveness under the standard's conditions, remediate exploitable findings, and retest before relying on the evidence.

PAYMENT CARD INDUSTRY DATA SECURITY STANDARD

The security standard for entities that store, process, transmit, or can affect the security of payment card data.

Penetration Testing requirements

  • PCI DSS is published by the PCI Security Standards Council and applies to merchants, acquirers, issuers, processors, and service providers within the Cardholder Data Environment (CDE).
  • Requirement 11.4 requires internal and external testing at least once every 12 months and after significant infrastructure or application upgrades or changes.
  • The methodology must address network and application layers, including vulnerabilities and threats experienced during the previous 12 months. Exploitable findings must be corrected and retested.
  • When network segmentation is used to reduce PCI DSS scope, its effectiveness must be tested at the frequency and under the conditions specified by the standard.
Before a compliance submission

Scope, frequency, tester qualification, and evidence depend on the entity and assessment method, such as SAQ or ROC. Confirm the current PCI DSS v4.0.1 text with your QSA or Compliance team.

Requirements and Testing Scope Matrix

Summary of the referenced clauses, the testing scope they cover, and the expected evaluation cycle.

Reference Mandate Title Scope Required Testing Cycle
Requirement 11.4 External and Internal Penetration Testing Entire Cardholder Data Environment (CDE) At least annually
Requirement 11.4.5 CDE Segmentation Isolation Verification Segmentation controls for any entity using segmentation At least annually and after segmentation changes
Requirement 11.4.6 CDE Segmentation Isolation Verification (Service Providers) Network Segmentation Controls (Service Providers) Every 6 months and after segmentation changes

Compliance Readiness Self-Assessment

Select items your organization has completed to evaluate your readiness score.

0%

Official source documents

Download the official PCI DSS document from the PCI SSC library.

Go to the official source