By EJN Labs · 7 Aug 2026 · 8 min read
If your hospitality business stores, processes or transmits cardholder data, PCI DSS Requirement 11.4 requires internal and external penetration testing at least annually and after significant changes, plus segmentation testing where you rely on network segmentation. Your QSA will ask for the report, the methodology and remediation evidence. Most UK hospitality engagements take 4 to 9 days, typically £4,400 to £12,600.
Why PCI DSS penetration testing matters for hospitality
PCI DSS penetration testing matters for hospitality because it is one of the few controls where the standard names the test types, the frequency and the evidence, and a Qualified Security Assessor (QSA) works through all three on audit day. Every payment channel a venue runs sits inside that scope.
Hotels, restaurant groups, pubs and venues take card payments through more channels than almost any other sector: front desk terminals, pay-at-table devices, booking engines, phone reservations, gift cards and self-service kiosks. Each channel puts you inside the scope of the PCI Data Security Standard, administered by the PCI Security Standards Council and enforced contractually by the card schemes and your acquirer.
Our PCI DSS penetration testing service page covers the standard’s requirements in depth. This article answers the narrower question hospitality operators ask us: what will the QSA look at, and how do you make sure your test passes inspection first time?
What your QSA checks on audit day
PCI DSS applies wherever cardholder data is stored, processed or transmitted, imposed through acquirer and card scheme agreements rather than by statute. Requirement 11.4 sets out explicit penetration testing obligations, and a QSA validating a Report on Compliance works through them line by line, checking five things:
- A documented methodology. The standard expects an industry-accepted approach covering the cardholder data environment (CDE) perimeter and critical systems, application-layer and network-layer testing, and consideration of threats seen in the previous 12 months.
- Internal and external tests within the last 12 months. Both are required at least annually and after any significant change, such as a new property management system, a POS refresh or a network redesign across sites.
- Segmentation testing. If you rely on segmentation to keep guest Wi-Fi, back-office systems or franchise networks out of scope, the segmentation controls must be tested at least annually for merchants, and every six months if you are assessed as a service provider.
- Tester independence and competence. PCI DSS Requirements 11.4.2 and 11.4.3 both call for the test to be carried out by a qualified internal resource or qualified external third party, with organisational independence of the tester, which the standard notes does not have to mean a QSA or ASV. Using a CREST-accredited firm is the simplest way to satisfy a QSA on competence.
- Remediation evidence. Exploitable vulnerabilities and security weaknesses must be corrected, and retesting must confirm the fix. A report with open critical findings and no retest is a common audit-day failure.
Penetration testing sits alongside, not instead of, the standard’s quarterly vulnerability scans, including external scans by an Approved Scanning Vendor. Presenting an ASV scan report as your penetration test is a classic audit-day failure: they are different controls, and the assessor treats them as such. For the underlying requirement unpacked, see our explainer on whether PCI DSS requires penetration testing.
What to test in a hospitality card estate
When EJN Labs scopes a hotel or restaurant group, we start from the card data flow rather than the network diagram: every route a card number can take, from tap to acquirer, and every system that touches it on the way. The systems that usually end up in scope are:
- Property management and reservation systems. The PMS often holds card details for no-show charges and incidentals, making it a core CDE system rather than a back-office tool.
- Point-of-sale and pay-at-table. POS servers, terminal estates and the VLANs they sit on, including how terminals authenticate and receive updates across sites.
- Online booking engines and APIs. Public booking journeys, payment pages and the integrations that pass reservations between channel managers, online travel agents and the PMS. These benefit from dedicated API penetration testing where integrations are complex.
- External infrastructure. Internet-facing services for head office and each property, remote access for IT suppliers, and franchise connectivity. Our external infrastructure penetration testing service maps directly to the external test the QSA expects.
- Segmentation between guest and payment networks. Guest Wi-Fi, staff Wi-Fi, CCTV, building management and till networks are frequently flat in older venues. Segmentation testing proves the guest network genuinely cannot reach the CDE.
Multi-site groups need to agree with their tester and QSA, before the engagement starts, whether every property is tested or a representative sample is defensible.
How an engagement runs for a hotel or restaurant group
An engagement starts with scoping: we ask for card-flow diagrams, segmentation design, a list of payment channels per property and your most recent attestation paperwork, so the test boundary matches the CDE boundary your QSA has agreed. Testing is then scheduled around your trading patterns.
That scheduling matters, because a busy Friday service is not the moment to probe a POS server, and venues commonly prefer internal work in quieter windows.
The test itself combines external and internal network-layer work, application-layer testing of booking and payment journeys, and segmentation checks launched from the out-of-scope networks a guest could realistically reach. Reporting maps each finding to the PCI DSS requirement it affects, with a severity rating and a practical fix, and a retest window is included as standard so corrected issues are verified. Our penetration testing checklist walks through the preparation steps in more detail if you are planning your first engagement.
What it costs and how scope drives the price
PCI DSS testing for hospitality is priced by effort, and effort is driven by the number of properties, payment channels and applications in scope. UK day rates for CREST-accredited testing typically run from £1,100 to £1,400, and typical hospitality engagements look like this:
| Engagement | Typical days | Typical UK cost |
|---|---|---|
| Segmentation test only (annual, or six-monthly for service providers) | 2 to 3 | £2,200 to £4,200 |
| External infrastructure plus booking engine test | 4 to 6 | £4,400 to £8,400 |
| Full internal and external CDE test across multiple sites | 6 to 9 | £6,600 to £12,600 |
These are typical UK ranges rather than fixed prices; a single restaurant with one POS system sits at the bottom, a multi-property hotel group with a PMS, spa and events business at the top. Our guide to penetration testing costs in the UK explains the pricing drivers across all engagement types, and the fastest way to an exact figure is our quote form.
How EJN Labs approaches hospitality PCI DSS testing
EJN Labs is a UK firm accredited by CREST and certified to ISO 27001 and Cyber Essentials Plus, with all testing delivered by UK-based testers. For hospitality clients we scope from the card data flow, test segmentation from the networks guests actually sit on, and write findings against the specific PCI DSS requirements a QSA will validate, so the report drops straight into your Report on Compliance or self-assessment evidence pack. Every engagement includes retesting of corrected findings, and where clients want us to, we answer the QSA’s follow-up questions about methodology and coverage directly, which shortens audit day.
Frequently Asked Questions
Does PCI DSS require penetration testing for hospitality businesses?
Yes, where PCI DSS applies to you. Requirement 11.4 mandates internal and external penetration testing at least annually and after significant changes, plus segmentation testing where segmentation keeps systems out of scope. A QSA or your acquirer will expect the evidence.
The obligation comes through your acquirer and card scheme agreements rather than UK law, and it applies regardless of whether you complete a Report on Compliance or a self-assessment questionnaire.
How much does PCI DSS penetration testing cost for a hospitality business?
Typically £4,400 to £12,600 overall, with most UK hospitality engagements taking 4 to 9 days at day rates of £1,100 to £1,400. Smaller scopes cost less, with a segmentation-only test usually taking 2 to 3 days, which comes to £2,200 to £4,200.
An external infrastructure and booking engine test runs 4 to 6 days (£4,400 to £8,400), and a full multi-site CDE test 6 to 9 days (£6,600 to £12,600). Request an exact price through our quote form.
How often must segmentation testing be carried out?
At least every 12 months for merchants, and at least every six months if you are assessed as a service provider, plus after any change to segmentation controls. For hospitality this cadence is what proves a guest device cannot reach the cardholder data environment.
The stakes are higher in hospitality because guest Wi-Fi, tills and back-office systems often share infrastructure. Without a current segmentation test, the whole network may fall into scope.
We complete a self-assessment questionnaire rather than a full audit. Do we still need a test?
It depends on which SAQ applies to your payment channels. Some SAQ types include the Requirement 11.4 penetration testing controls and some do not, so check the requirement list in your specific questionnaire and confirm the position with your acquirer. Many hospitality businesses run mixed channels, such as a booking engine plus card terminals, which can pull them into an SAQ type that does include testing.
What will a QSA reject in a penetration test report?
A QSA will reject a vulnerability scan presented as a penetration test, a test scope that does not match the agreed CDE boundary, missing segmentation testing, no evidence of an industry-accepted methodology, and exploitable findings left open with no retest.
A report written against the specific PCI DSS requirements, with a documented methodology and a retest confirming fixes, avoids all five problems.
Get audit-ready before your QSA arrives
If your PCI deadline is approaching, the cheapest time to fix scope problems is before the test, not after the audit. Tell us about your properties, payment channels and assessment type through our CREST penetration testing quote form and we will come back with a scoped proposal that your QSA will accept.




Leave a Reply