The Payment Card Industry Data Security Standard (PCI DSS) v4.0 introduces stricter requirements for protecting cardholder data environments (CDE). Requirement 11.4 specifically dictates that internal and external penetration testing must be performed regularly, according to industry-accepted methodologies such as NIST SP 800-115.
Core testing mandates under PCI DSS 11.4
PCI DSS v4.0 leaves zero ambiguity regarding the expectations for penetration testing. Organizations handling payment card data must adhere to explicit timelines and verification standards:
- Frequency: external and internal penetration testing must occur at least once every 12 months, and after any significant infrastructure or application change.
- Application-layer testing: testing must cover both the network perimeter and the application layer, including all web applications and APIs interacting with cardholder data.
- Segmentation verification (Req 11.4.5): service providers must perform segmentation tests at least once every six months to prove card data networks are isolated from general corporate systems.
- Exploitation attempts: testers must attempt actual exploitation of vulnerabilities to confirm real-world exposure rather than relying on automated scanner scoring.
Documenting remediation and retesting
Requirement 11.4.4 mandates that all identified vulnerabilities must be remediated and retested until confirmed resolved. A test report that concludes with unresolved high or critical vulnerabilities is automatically rejected by your Qualified Security Assessor (QSA).
BugSnaps delivers PCI DSS compliant penetration test documentation complete with proof-of-concept evidence, CVSS vector strings, segmentation testing validation, and signed retest attestation certificates.