By EJN Labs · 9 Jul 2026 · 6 min read
Yes. If your organisation stores, processes or transmits cardholder data, PCI DSS Requirement 11.4 requires penetration testing. It is not a recommendation or a nice-to-have. Requirement 11.4 of PCI DSS v4.0.1 sets out a specific, auditable obligation: internal and external penetration tests, carried out at least once every 12 months and again after any significant change, with every exploitable weakness fixed and re-tested.
The detail is where most teams get caught out. A vulnerability scan is not a penetration test. An annual test is not always enough. And the person who runs it has to meet an independence bar. This guide breaks down exactly what Requirement 11.4 asks for, so you can scope the test that satisfies your assessor the first time.
Where penetration testing sits in PCI DSS
PCI DSS v4.0 has been mandatory since 31 March 2025, and v4.0.1 is the current version. Testing obligations live in Requirement 11, “Test security of systems and networks regularly”. Two of them are easy to confuse:
- Requirement 11.3 covers vulnerability scanning, including quarterly external scans by an Approved Scanning Vendor (ASV).
- Requirement 11.4 covers penetration testing, which is a separate obligation. Scanning is automated and broad. A penetration test is a manual, goal-driven exercise that a scanner cannot replace.
You need both. Passing your ASV scans does not discharge your Requirement 11.4 duty, and vice versa.
What Requirement 11.4 actually mandates
Requirement 11.4 breaks into a set of sub-requirements. In plain terms:
- 11.4.1 A documented methodology. Your penetration testing must follow a defined, industry-accepted approach (for example NIST SP 800-115). It must cover the entire cardholder data environment (CDE) perimeter and critical systems, test from both inside and outside the network, and include application-layer and network-layer testing.
- 11.4.2 Internal penetration testing. Performed at least once every 12 months and after any significant change to infrastructure or applications.
- 11.4.3 External penetration testing. Performed at least once every 12 months and after any significant change.
- 11.4.4 Remediate and re-test. Exploitable vulnerabilities and security weaknesses found during testing must be corrected, and the testing repeated to verify the corrections.
- 11.4.5 Segmentation testing. If you use segmentation to isolate the CDE from other networks, those segmentation controls must be penetration tested at least once every 12 months.
- 11.4.6 Segmentation testing for service providers. If you are a service provider, that segmentation testing rises to at least once every six months, and after any change to segmentation controls.
- 11.4.7 Multi-tenant service providers. Must support their customers with external penetration testing.
How often do you need to test?
Test at least once every 12 months, covering both internal and external testing, and again after any significant change to your environment. The annual baseline is only half the requirement, and it is the second trigger, testing after change, that most often catches people out.
Significant change includes new infrastructure or software, a change to network topology, a firewall rule change that affects the CDE, or new components added to the environment. If you rebuilt a payment application in March, an annual test run in January will not cover it.
Service providers that rely on segmentation carry the heaviest cadence: segmentation testing every six months under Requirement 11.4.6.
Who is allowed to perform a PCI DSS penetration test?
PCI DSS Requirement 11.4.1 requires the tester to be qualified and organisationally independent of the team that manages the systems being tested. The tester can be an internal resource, provided they are genuinely independent, or an external third party.
PCI DSS does not name a specific accreditation such as CREST. It sets a competence and independence bar rather than a scheme. In practice, assessors treat a CREST-accredited provider as strong, ready-made evidence that the independence and qualification requirements are met, which removes a common audit question before it is asked. EJN Labs is CREST-accredited and organisationally independent of your operations, so our reports satisfy this element cleanly.
What the test has to cover
Scope is where an underspecified test fails an audit. A Requirement 11.4 penetration test needs to reach:
- the full CDE perimeter and the critical systems that support it;
- both external-facing and internal attack surfaces;
- the application layer and the network layer;
- segmentation controls, where segmentation is used to reduce scope.
A test that only looks at the public-facing web application, and skips the internal network or the segmentation controls, leaves a gap your assessor will find.
What happens when the test finds something
Finding vulnerabilities is expected. Requirement 11.4.4 is explicit that exploitable findings must be remediated and the testing repeated to confirm the fix held. This is why a single point-in-time test is rarely the end of the engagement. A retest is part of compliance, not an optional extra.
This is worth building into your budget and timeline from the start. At EJN Labs, retests of the fixes we identify are included, so verifying remediation for 11.4.4 does not become a second invoice.
How EJN Labs delivers PCI DSS penetration testing
We scope the engagement against Requirement 11.4 directly, so the deliverable maps to the sub-requirements your assessor checks. You get a fixed price, a realistic timeline, a CREST-accredited UK-based tester, and a report structured for a QSA to accept as evidence. Findings are triaged by exploitability, remediation guidance is practical, and retesting to satisfy 11.4.4 is included.
If you want to see the format an assessor receives before you commit, request a sample report, or get a fixed quote for your PCI DSS scope in 24 hours.
See our PCI DSS penetration testing service or get a fixed-price PCI DSS quote in 24 hours.
Frequently asked questions
Does PCI DSS require a penetration test?
Yes. PCI DSS v4.0.1 Requirement 11.4 requires both internal and external penetration testing, at least once every 12 months and after any significant change to the environment.
How often is PCI DSS penetration testing required?
At least once every 12 months for internal and external testing, plus after any significant change. Service providers that use segmentation must test their segmentation controls at least once every six months under Requirement 11.4.6.
What is the difference between a vulnerability scan and a penetration test under PCI DSS?
They are separate obligations. Vulnerability scanning sits under Requirement 11.3, including quarterly external ASV scans, and is largely automated. Penetration testing sits under Requirement 11.4 and is a manual, goal-driven exercise. You need both, and passing one does not satisfy the other.
Who can perform a PCI DSS penetration test?
A tester who is qualified and organisationally independent of the team that manages the systems in scope. PCI DSS does not mandate a specific scheme such as CREST, but assessors widely accept CREST accreditation as evidence that the qualification and independence bar is met.
What does a PCI DSS penetration test need to cover?
The full cardholder data environment perimeter and critical systems, tested from both outside and inside the network, across the application and network layers, and including segmentation controls where segmentation is used to reduce scope.
What happens if the penetration test finds vulnerabilities?
Requirement 11.4.4 requires you to remediate exploitable findings and repeat the testing to verify the corrections. A retest to confirm the fixes is part of achieving compliance.




Leave a Reply