By EJN Labs · 30 Jul 2026 · 3 min read
PCI DSS penetration testing cost depends on which of requirements 11.4.1 to 11.4.6 apply to you: EJN Labs prices every scope at a day rate of £1,100 to £1,400. The price is the day count times the rate, fixed before work starts.
What a PCI DSS pen test costs
A PCI DSS pen test is priced at £1,100 to £1,400 a day, and the day count depends on which of requirements 11.4.1 to 11.4.6 apply to you: three days of internal testing costs £3,300 to £4,200.
| Requirement | What it is | Published figures |
|---|---|---|
| External testing (11.4.3) | Internet-facing perimeter | Starting £3,500 · typical £6,500–£12,000 · 3–5 days |
| Internal testing (11.4.2) | Inside the CDE | £1,100 to £1,400 per day, scoped to your CDE size |
| Segmentation testing (11.4.5/11.4.6) | Controls isolating the CDE | £1,100 to £1,400 per day, scoped by segment count |
| Combined baseline (VAPT) | Vuln assessment + pen test | Starting £4,000 · typical £7,000–£12,000 · 3–5 days |
All figures are on our published price list; the VAPT row is listed for compliance baselines including PCI. Using the published external row, a 3 to 5 day external test typically lands between £6,500 and £12,000. The maths for every other service is in our penetration testing cost guide.
What requirements 11.4.1 to 11.4.6 require
PCI DSS v4.0.1 is specific: 11.4.1 requires a documented penetration testing methodology based on an industry-accepted approach (NIST SP 800-115, OWASP, OSSTMM, PTES). 11.4.2 requires internal penetration testing at least every 12 months and after significant infrastructure or application change. 11.4.3 requires the same externally. 11.4.4 requires exploitable findings to be corrected and testing repeated. 11.4.5 and 11.4.6 require segmentation testing: merchants at least every 12 months, service providers every 6 months. The source text is in the PCI SSC document library.
What drives the day count
CDE size sets the internal day count: more systems in scope means more days at the same rate. Each network segment adds segmentation-testing time, and running internal and external in one window keeps scoping overhead down. The 11.4.4 retest of fixed findings is free with us, so it never adds to the bill. If your segmentation is simple, say so when you ask for a quote: segment count is the single biggest lever on that line.
Merchant or service provider: why it changes the bill
Where segmentation is used to isolate the CDE, merchants test it at least every 12 months under 11.4.5. Service providers test it every 6 months under 11.4.6, so that line item lands twice a year: budget the segmentation day count twice.
Frequently asked questions
Can a vulnerability scan satisfy requirement 11.4?
No. Scans sit under requirement 11.3: authenticated internal vulnerability scans quarterly under 11.3.1 and external ASV scans quarterly under 11.3.2. Requirement 11.4 requires penetration testing, which is manual exploitation by testers, not a scanner. You need both, each on its own cadence: scans quarterly under 11.3, penetration tests on the 12-month or 6-month cycles under 11.4.
Get a PCI Pen Test Quote: Tell us your CDE size and segment count. Fixed quote from CREST-accredited UK testers within 24 hours. See the full service on PCI DSS penetration testing.




Leave a Reply