Skip to content

PCI DSS v4.0 penetration testing requirements

Explicitly required by namePCI Security Standards Council

Yes. PCI DSS is the one framework on this page that names penetration testing outright and tells you how often to do it. Requirement 11.4 mandates internal and external penetration testing at least annually and after any significant infrastructure or application change, against a defined and documented methodology.

How often

At least every 12 months and after every significant change. Segmentation controls every 12 months, or every 6 months if you are a service provider.

What is in scope

The entire cardholder data environment perimeter and any critical systems, tested from both outside and inside the network, at the network layer and the application layer.

The actual text

Clause by clause.

What the standard says, rather than what a vendor says it says. Quote these references directly when you are asked to justify a testing programme internally.

ReferenceRequirement
11.4.1
A defined methodology
A documented penetration testing methodology must exist, covering industry-accepted approaches, coverage of the entire cardholder data environment perimeter and critical systems, testing from inside and outside the network, application-layer and network-layer testing, and retention of results.
11.4.2
Internal testing
Internal penetration testing performed at least once every 12 months and after any significant infrastructure or application upgrade or change, by a qualified internal resource or qualified third party with organisational independence.
11.4.3
External testing
External penetration testing performed at least once every 12 months and after any significant infrastructure or application upgrade or change, under the same independence condition.
11.4.4
Correct and retest
Exploitable vulnerabilities and security weaknesses found during penetration testing must be corrected in line with the entity’s risk assessment, and testing must be repeated to verify the corrections. A finding is not closed because a change was made; it is closed when the retest fails to reproduce it.
11.4.5
Segmentation controls
Where segmentation is used to isolate the cardholder data environment, penetration testing of those segmentation controls at least every 12 months and after any change to segmentation controls or methods.
11.4.6
Segmentation, service providers
For service providers, segmentation control testing at least every six months rather than annually, and after any change to segmentation controls or methods.
11.4.7
Multi-tenant providers
Multi-tenant service providers must support their customers’ external penetration testing, either by providing evidence or by permitting the customer to test.
Evidence

What the assessor wants to see.

Work through it here. Progress is kept in your browser, and copy or print drops it straight into an audit folder.

evidence checklist
6 items to evidence

Tick what you already hold. Progress is saved in this browser only — nothing is sent anywhere — and copy or print puts it into your audit folder.

Failure modes

Where people lose the point

  • Submitting a vulnerability scan as a penetration test. Requirement 11.3 covers scanning; 11.4 is separate and is not satisfied by scan output.
  • Testing annually but not after significant changes, which is a second and independent trigger.
  • Producing findings with no retest evidence, leaving 11.4.4 unsatisfied.
  • Service providers applying the 12-month segmentation cadence instead of the 6-month one in 11.4.6.
  • Scoping the test to the application only, when 11.4.1 requires the whole CDE perimeter and critical systems.
Questions

PCI DSS and penetration testing

Does PCI DSS require a third-party penetration test?
No. PCI DSS requires organisational independence, not an external company. A qualified internal resource may perform the test provided they are organisationally independent of the systems being tested — typically meaning they are not the people who built or administer them. Many QSAs prefer a third party because independence is easier to evidence, but it is not the letter of the requirement.
What counts as a significant change under 11.4.2 and 11.4.3?
PCI DSS does not enumerate them, which is deliberate; the entity defines and documents what significant means for its environment. In practice assessors expect new or modified infrastructure in the CDE, upgrades to operating systems or components, new sub-networks or servers, and material application changes. Whatever definition you adopt, write it down before the assessment, because an undocumented definition looks retrofitted.
How long do penetration test reports need to be retained?
Requirement 11.4.1 requires retention of penetration testing results and remediation activities for at least 12 months. In practice keep longer, because an assessor will often want to see the trajectory across cycles rather than a single point.

For the longer narrative treatment — worked examples, cost and timing — read PCI DSS 4.0 pentesting requirements: the full guide.

Testing that produces evidence, not just findings.

Reports mapped to the control they satisfy, with a replayable record behind every finding — which is what an assessor asks for when they push back.