PCI DSS 4.0 Penetration Testing: What UK Retailers Must Change First

PCI DSS 4.0 Penetration Testing: What UK Retailers Must Change First

By EJN Labs · 23 Jul 2026 · 8 min read

PCI DSS 4.0 requires UK retailers that store, process or transmit cardholder data to run external and internal penetration tests at least every 12 months and after significant changes. The changes to tackle first are annual scope confirmation, authenticated internal vulnerability scans, payment page script controls and segmentation testing. A typical retail engagement takes 4 to 9 days at £1,200 to £1,400 per day.

What PCI DSS 4.0 changes for PCI DSS penetration testing

PCI DSS 4.0 demands more penetration testing, with more documentation, than version 3.2.1 ever did. Version 3.2.1 was retired on 31 March 2024, the final future-dated 4.0 requirements became mandatory on 31 March 2025, and the testing controls in Requirement 11 now apply in full.

Penetration testing did not start with version 4.0, but for UK retailers the grace period is over, and your acquirer can now hold you to the full set of 4.0 controls.

This article covers what changed and what to fix first. For the full requirement-by-requirement picture, our PCI DSS penetration testing service page is the authoritative reference; treat this post as the retail-specific change briefing that sits alongside it.

Why UK retailers feel this first

UK retailers feel this first because PCI DSS is enforced through the merchant agreement with your acquiring bank, not through UK law. Non-compliance triggers scheme fines passed through by your acquirer, higher transaction fees, and in serious cases the loss of your ability to take card payments.

PCI DSS is a contractual standard maintained by the PCI Security Standards Council, with the card schemes standing behind your acquirer. No regulator is involved, so the consequences arrive through the commercial relationship.

Retailers sit at the sharp end for three reasons. Card volume: merchants at Level 1 and Level 2 face annual validation with little room for interpretation. E-commerce skimming: attackers inject malicious JavaScript into checkout pages to harvest card data in the browser, and 4.0 added two requirements aimed squarely at that attack. And hybrid estates: tills, a payment gateway, a web shop, warehouse systems and a head office network, where every connection is a scoping question an assessor will ask about.

The five changes to tackle first

Version 4.0 introduced dozens of new requirements, but from a technical testing standpoint five of them dominate the work we see UK retailers needing to do.

  1. Annual scope confirmation (Requirement 12.5.2). You must document and confirm your PCI DSS scope at least every 12 months and after significant changes. Testing an estate whose scope has never been formally confirmed is the most common defect we find in first-time 4.0 assessments.
  2. Authenticated internal vulnerability scanning (Requirement 11.3.1.2). Internal scans must now run with credentials, not just unauthenticated network sweeps. Authenticated scans routinely surface three to five times more findings, so budget remediation time accordingly.
  3. Payment page script management (Requirement 6.4.3). Every script that loads on a payment page must be inventoried, authorised and integrity-checked. This is the direct answer to Magecart-style skimming and it applies to the scripts your marketing team added, not just the ones your developers wrote.
  4. Payment page tamper detection (Requirement 11.6.1). Under Requirement 11.6.1, a mechanism must detect and alert on unauthorised changes to the HTTP headers and content of payment pages as received by the consumer browser, checked at least weekly or at a frequency justified by a targeted risk analysis.
  5. A defined penetration testing methodology (Requirement 11.4.1). Your penetration testing must follow a documented methodology covering the entire cardholder data environment perimeter and critical systems, internal and external testing, application-layer and network-layer testing, and review of threats from the last 12 months. An ad hoc annual scan report no longer passes.

The core cadence remains: external and internal penetration testing at least every 12 months and after any significant infrastructure or application change (Requirements 11.4.2 and 11.4.3), plus segmentation testing to prove your cardholder data environment is genuinely isolated. If you want the baseline question answered in depth, see does PCI DSS require penetration testing.

How a PCI DSS engagement runs for a retailer

Segmentation comes first. When EJN Labs scopes a retail estate, the opening session maps where cardholder data enters, through tills, payment gateway, e-commerce checkout and phone payments, and which network segments can reach those paths. Proving or disproving that isolation is often the highest-value hour.

The flat network is the classic finding. We regularly see estates where the back-office Wi-Fi can route to the till VLAN, dragging the whole store network into scope.

A typical engagement then runs in four phases: scope confirmation against your documented cardholder data environment, so the test evidences Requirement 12.5.2 rather than contradicting it; external testing of the internet-facing perimeter, including the web shop, checkout, APIs and remote access; internal testing from a foothold inside the corporate network, attempting to reach the cardholder data environment across segmentation controls, which doubles as segmentation evidence for Requirement 11.4.5; and reporting mapped requirement by requirement, followed by retesting of fixed findings.

For online retailers, most exploitable findings live in the application layer: checkout logic, session handling, the payment gateway integration and the APIs connecting the storefront to stock and pricing systems. Our API penetration testing and external infrastructure penetration testing services cover both halves of that perimeter. If you are preparing internally first, our penetration testing checklist walks through what to have ready before a tester arrives.

What it costs and how scope drives the price

PCI DSS testing is priced by scope. UK day rates for CREST-accredited testing typically run £1,200 to £1,400, and the driver is how much estate sits inside your cardholder data environment: external IPs and applications, internal segments to test from, and whether segmentation testing is included.

Typical retail scopeEffortTypical UK cost
External perimeter plus segmentation test (card data outsourced to a gateway)4 to 6 days£4,800 to £8,400
External, internal and web application testing across a multi-site estate6 to 9 days£7,200 to £12,600

Reducing scope is the cheapest control you have: outsourcing payment capture to a validated provider and proving segmentation can roughly halve testing effort. For a broader view of pricing drivers, see our guide to penetration testing cost in the UK. Exact pricing for your estate comes from a short scoping call via the quote form.

How EJN Labs approaches PCI DSS 4.0 testing for retailers

EJN Labs is a CREST-accredited UK penetration testing firm, and we hold Cyber Essentials Plus and ISO 27001 ourselves, so the evidence discipline PCI DSS demands is one we apply to our own business. All testing is delivered by UK-based testers, which matters for retailers whose merchant agreements or insurers restrict where cardholder data environments may be accessed from.

We test against a documented methodology that satisfies Requirement 11.4.1, and we write reports for two audiences at once: engineers who need reproduction steps, and assessors who need each finding mapped to the requirement it affects. Where 4.0 introduced new controls, such as payment page script inventories under 6.4.3, we check them during the application test rather than leaving them as a paperwork exercise. Retest of remediated findings is included, because an unverified fix does not close a PCI DSS finding.

Frequently Asked Questions

Does PCI DSS 4.0 require penetration testing?

Yes. Requirement 11.4 explicitly requires external and internal penetration testing at least once every 12 months and after any significant infrastructure or application upgrade or change. The testing must follow a documented methodology, and vulnerability scanning alone does not satisfy the requirement.

Version 4.0 spells out what that methodology must cover: the cardholder data environment perimeter, critical systems, and attacks at both the application layer and the network layer.

What changed between PCI DSS 3.2.1 and 4.0 for testing?

Four headline changes: authenticated internal vulnerability scanning, formal annual scope confirmation, payment page script management and tamper detection, and a stricter documented penetration testing methodology. The annual external and internal testing cadence carried over unchanged, but the evidence bar rose.

Assessors now expect scope records, methodology documents and proof that findings were retested, not just a yearly report.

What does PCI DSS penetration testing cost for a UK retailer?

Expect £4,800 to £8,400 for an external perimeter test with segmentation testing, based on UK day rates of £1,200 to £1,400 for CREST-accredited testing. A wider engagement covering external, internal and web application testing across a multi-site estate typically comes to £7,200 to £12,600.

In day terms that is usually 4 to 6 days for the perimeter work and 6 to 9 days for the multi-site scope. Exact pricing depends on scope and comes from a short scoping call.

How often does segmentation testing have to run?

At least every 12 months for merchants, and after any change to segmentation controls. Service providers face a shorter cycle of at least every six months. If you use network segmentation to reduce PCI DSS scope, Requirement 11.4.5 makes you test that it actually isolates the cardholder data environment.

Most retailers combine segmentation testing with the annual internal penetration test to control cost.

Can our own IT team perform the penetration test?

Yes, PCI DSS permits internal testers provided they are organisationally independent of the teams that manage the systems under test and are suitably qualified. In practice most UK retailers cannot demonstrate that independence, so they use an external CREST-accredited firm instead.

Going external has a second benefit: acquirers and assessors receive a report from a recognised accreditation scheme.

Get your 4.0 testing scoped before your next assessment

If your next PCI DSS assessment is the first fully under version 4.0, the worst time to discover a segmentation gap or an unmanaged checkout script is during it. Tell us how you take payments and we will return a fixed scope and price. Request a CREST penetration testing quote and speak to UK-based testers who map every finding to the requirement it affects.

Leave a Reply

Your email address will not be published. Required fields are marked *