What Requirement 11.4 covers
- A defined, documented and industry-accepted penetration testing methodology, applied consistently.
- Internal penetration testing at least every 12 months and after significant change.
- External penetration testing at least every 12 months and after significant change.
- Correction of exploitable vulnerabilities and security weaknesses found, followed by a repeat test to verify the correction.
- Segmentation testing to confirm that segmentation controls isolating the CDE are operational and effective — at least annually for merchants, at least every six months for service providers.
- Multi-tenant service providers must support their customers in performing testing of their own environments.
Scanning does not satisfy 11.4
PCI DSS requires quarterly vulnerability scanning separately under Requirement 11.3, including ASV scans for external. These are distinct requirements because they are distinct activities — scan output submitted in place of a penetration test will not close 11.4.
What counts as a "significant change"
This trips up more assessments than the annual cadence does, because organisations schedule the annual test and then ship a major change three months later without retesting.
The standard leaves the definition to you, but it must be documented and defensible. In practice assessors expect changes such as a new or substantially modified application in the CDE, new infrastructure or a migration, changes to network topology or firewall rules affecting the CDE, an upgrade or replacement of a payment platform, or a change in how cardholder data is stored, processed or transmitted.
Write your definition down before your assessment, apply it consistently, and keep the evidence that you tested when it triggered.
Who is allowed to perform the test
PCI DSS does not require a QSA to perform penetration testing, and it does not mandate a specific certification. What it requires is a qualified internal resource or a qualified third party, with organisational independence from the team that manages the systems being tested. Internal staff may perform it if that independence exists.
Assessors will ask for evidence of qualification — relevant certifications, experience, and a documented methodology. Most organisations use a third party because independence is easier to demonstrate than to argue.
Scoping the CDE correctly
Scope is the whole game in PCI. The test must cover the CDE perimeter and any critical systems connected to it, from both outside and inside. If you rely on segmentation to reduce scope, that segmentation must itself be tested — proving that systems out of scope genuinely cannot reach the CDE.
- The CDE itself — systems that store, process or transmit cardholder data.
- Connected-to and security-impacting systems that could affect CDE security.
- The external perimeter of the CDE from an internet perspective.
- The internal perimeter — testing from within your network toward the CDE.
- All segmentation controls claimed as scope-reducing, tested from every out-of-scope network segment.
- Both the network layer and the application layer, including payment applications.
Want a number before you talk to anyone?
Our instant estimator prices your actual environment using the same model our quoting process uses. No email required to see the figure.