Back to Blog
Compliance9 min read

PCI DSS Penetration Testing Requirements: Requirement 11.4 Explained (2026)

P

Pentestas Team

Security Analyst

7/2/2026
PCI DSS Penetration Testing Requirements: Requirement 11.4 Explained (2026)
PCI DSS penetration testing requirements — Requirement 11.4 guide

💫 PCI DSS penetration testing requirements — the short version

  • Requirement 11.4 mandates internal and external penetration testing at least every 12 months and after every significant change.
  • Segmentation controls must be tested every 12 months (merchants) or every 6 months (service providers).
  • Exploitable findings must be fixed and re-tested (11.4.4).
  • Since v4.0.1 became mandatory on 31 March 2025, a missing or mis-scoped test means a failed assessment, blocked card processing, and monthly fines.
  • An AI penetration testing system can run 11.4-aligned tests continuously — for a fraction of a once-a-year manual engagement.

Here is the position every payment company is in right now. Your QSA will not sign your Report on Compliance (ROC) or Attestation of Compliance (AOC) until you hand them a current Requirement 11.4 penetration test — internal and external, scoped to your entire cardholder data environment. Miss it, or scope it wrong, and the consequences are not theoretical: a failed assessment, an acquiring bank that throttles or blocks your ability to process cards, and monthly non-compliance fees that dwarf the cost of the test itself.

And since PCI DSS v4.0.1 became mandatory on 31 March 2025, the clock does not just reset once a year — it resets after every significant infrastructure or application change. Ship a new checkout flow, migrate a database, add a service inside the CDE, and you have created a new testing obligation.

Most teams answer this the expensive way: they buy a single, five-figure, point-in-time manual pentest, sweat through three weeks of scheduling and back-and-forth, then hope nothing changes for the next twelve months. It always changes. This guide breaks down exactly what the PCI DSS penetration testing requirements demand, what a QSA actually needs to see, and how to stay continuously in-scope — without a five-figure invoice every time your environment moves.

📋

The requirement

What PCI DSS Requirement 11.4 actually says

Requirement 11.4 is the section of PCI DSS v4.0.1 that mandates penetration testing. It is not a vague “test your security” clause — it is six specific, auditable sub-requirements:

11.4.1 — a defined, documented penetration-testing methodology covering the external and internal layers, the application and network layers, and segmentation. 11.4.2internal penetration testing. 11.4.3external penetration testing. Both 11.4.2 and 11.4.3 must be performed at least once every 12 months and after any significant upgrade or change. 11.4.4 — any exploitable vulnerability found must be corrected and the test repeated to verify the fix. 11.4.5 and 11.4.6 — the controls that isolate your cardholder data environment must themselves be penetration-tested.

Requirement 11.4 — sub-requirements

11.4.1Documented methodology11.4.2Internal pentest11.4.3External pentest11.4.4Re-test fixed flaws11.4.5 / 11.4.6Segmentation controlsAll at leastevery 12 months+ after every change
PCI DSS v4.0.1 Requirement 11.4: the six sub-requirements every QSA checks.
🎯

The scope

What “in scope” means for your test

The scope is the cardholder data environment (CDE): every system that stores, processes, or transmits cardholder data, plus anything that can affect its security. Your test has to hit it from two directions — the external internet-facing surface and the internal surface reachable from inside your network — and at two layers: the network layer and the application layer.

This is where most first attempts fail their QSA: the pentest covered the public website but never exercised the internal APIs, the admin panels, or the segmentation controls that are supposed to keep the CDE small. If a segmentation control fails, everything on the other side of it just entered your PCI scope.

What must be in scope

Cardholder Data Environment (CDE)Application layerNetwork layerExternal surfaceinternet-facingInternal surfacefrom inside CDE+ segmentation controls isolating the CDE from out-of-scope networks
Scope: external + internal, application + network layer, plus the segmentation that keeps the CDE small.

The cadence

How often — merchants vs. service providers

The headline cadence is at least every 12 months for internal and external penetration testing, plus after every significant change. Segmentation testing is where merchants and service providers diverge: merchants test segmentation controls every 12 months; service providers must test them every 6 months. If you are a processor, gateway, or hosting provider, you are on the twice-a-year clock.

The “after every significant change” clause is the one that quietly breaks annual-only programs. A point-in-time report is a snapshot; the moment you deploy a meaningful change, that snapshot no longer reflects reality — and your compliance obligation has already re-triggered.

Cadence — merchants vs service providers

MerchantService providerPentest: every 12 monthsPentest: every 12 monthsSegmentation: every 12 monthsSegmentation: every 6 monthsstricter…and after ANY significant infrastructure or application change.
Cadence differs: service providers must pentest segmentation controls twice as often as merchants.
💰

The offer

Why annual-only pentesting is the expensive option

A traditional manual PCI penetration test runs roughly $10,000–$30,000 and lands as a PDF that is accurate for about a day. Then your environment changes and you are out of coverage until the next annual cycle — or you pay again for a re-test. That is a lot of money for a snapshot, and it leaves you blind for 361 days out of 365.

Pentestas is pentesting as a service: an AI penetration testing system that runs 11.4-aligned internal and external tests on your cardholder data environment continuously — automatically, after every deploy — starting at $79/month. It is penetration testing with AI at the core, orchestrated by frontier models (we run penetration testing with Claude for deep reasoning and cost-controlled penetration testing with DeepSeek for high-volume passes), delivered as a B2B SaaS pentest platform that maps findings straight to the PCI requirement they satisfy.

The cost of staying compliant

Manual pentest (annual)$10k–$30k+once / year · stale in a dayAI platform (continuous)from $79/more-runs after every change
Point-in-time manual testing vs. continuous AI-driven coverage — an order-of-magnitude cost difference.

The mapping

How Pentestas covers Requirement 11.4

The platform exercises the external surface from the internet and the internal surface through a lightweight agent deployed inside your network, so a single engagement covers both 11.4.2 and 11.4.3. It tests the application and network layers, checks the segmentation controls that keep the CDE isolated, and — critically for 11.4.4 — re-tests every exploitable finding after you fix it, capturing the before-and-after evidence your QSA wants. Because it re-runs after every change, the “significant change” obligation is handled automatically instead of becoming a fire drill.

Every finding ships with real exploit evidence, a severity rating, and remediation steps — the audit-ready artifacts that make a QSA conversation short instead of painful.

Point-in-time vs. continuous coverage

testtesttesttesttestAnnual pentest = 4 confident days out of 365Continuous coverage closes the 361-day blind spotevery deploy re-tests the CDE — the change that breaks compliance is caught the day it ships
A once-a-year test is accurate for about a day. Continuous testing keeps you in-scope between audits.

A straight answer on manual vs. AI

A manual penetration test performed by senior human testers is still the highest-value assessment you can buy — a skilled human will chain business-logic flaws and reason about your specific threat model in ways no tool fully matches. It also typically costs 20–30× more than an AI-driven platform. Both have a place. Use continuous, AI-driven pentesting to stay in scope after every change and catch the large majority of issues that are findable programmatically; commission a manual pentest for the deep, creative, high-assurance milestone. The strongest PCI programs run both: AI for coverage and cadence, humans for depth — and the AI platform keeps you compliant every single day in between.

Bottom line: PCI DSS Requirement 11.4 is not satisfied by one lucky PDF a year. It rewards continuous coverage of the whole cardholder data environment, internal and external, re-tested after every change. That is exactly the shape of the problem an AI penetration testing system is built to solve — and it costs a fraction of what you are paying to be compliant for one day out of the year.

FAQ

PCI DSS penetration testing, quick answers

How often does PCI DSS require penetration testing?

At least once every 12 months and after any significant infrastructure or application change (Requirement 11.4.2/11.4.3). Segmentation controls are tested every 12 months for merchants and every 6 months for service providers (11.4.5/11.4.6).

Is a vulnerability scan the same as a PCI penetration test?

No. Requirement 11.3 covers vulnerability scanning (including quarterly ASV scans); Requirement 11.4 covers penetration testing, where a tester actively exploits weaknesses across the application and network layers. You need both — a scan is not a substitute for a pentest.

Who can perform a PCI DSS penetration test?

A qualified internal or external tester who is organizationally independent of the systems being tested. It does not have to be your QSA, but your QSA must be satisfied the methodology and scope meet Requirement 11.4 before signing your ROC/AOC.

How much does a PCI penetration test cost?

A manual annual engagement typically runs $10,000–$30,000+. A continuous, AI-driven platform that keeps you in-scope after every change starts at $79/month — which is why most teams now pair the two.

Get PCI 11.4 coverage that keeps up with your deploys

Continuous internal + external penetration testing mapped to PCI DSS, from $79/month.

See plans & pricing
Alexander Sverdlov

Alexander Sverdlov

Founder of Pentestas. Author of 2 information security books, cybersecurity speaker at the largest cybersecurity conferences in Asia and a United Nations conference panelist. Former Microsoft security consulting team member, external cybersecurity consultant at the Emirates Nuclear Energy Corporation.