Skip to content

PCI DSS v4.0 penetration testing: requirement 11.4 compliance and application testing

A technical walkthrough of PCI DSS v4.0 Requirement 11.4 penetration testing mandates, segmentation validation, application testing frequencies, and Qualified Security Assessor expectations.

By BugSnaps Security Research · · 8 min read

The Payment Card Industry Data Security Standard (PCI DSS) v4.0 introduces stricter requirements for protecting cardholder data environments (CDE). Requirement 11.4 specifically dictates that internal and external penetration testing must be performed regularly, according to industry-accepted methodologies such as NIST SP 800-115.

Core testing mandates under PCI DSS 11.4

PCI DSS v4.0 leaves zero ambiguity regarding the expectations for penetration testing. Organizations handling payment card data must adhere to explicit timelines and verification standards:

  • Frequency: external and internal penetration testing must occur at least once every 12 months, and after any significant infrastructure or application change.
  • Application-layer testing: testing must cover both the network perimeter and the application layer, including all web applications and APIs interacting with cardholder data.
  • Segmentation verification (Req 11.4.5): service providers must perform segmentation tests at least once every six months to prove card data networks are isolated from general corporate systems.
  • Exploitation attempts: testers must attempt actual exploitation of vulnerabilities to confirm real-world exposure rather than relying on automated scanner scoring.

Documenting remediation and retesting

Requirement 11.4.4 mandates that all identified vulnerabilities must be remediated and retested until confirmed resolved. A test report that concludes with unresolved high or critical vulnerabilities is automatically rejected by your Qualified Security Assessor (QSA).

BugSnaps delivers PCI DSS compliant penetration test documentation complete with proof-of-concept evidence, CVSS vector strings, segmentation testing validation, and signed retest attestation certificates.

Run a real pentest on your app - free.

Sign in, prove you own the domain, and MyPentest maps and tests it. No credit card.