Skip to main content
    6 min read

    PCI DSS 4.0 Penetration Testing Requirements: A Plain-English Guide

    By StealthNet Team

    PCI DSS 4.0 requirement 11.4 mandates annual external and internal penetration testing, segmentation testing for service providers, and testing after significant change. Here is what each one means.

    PCI DSS 4.0 credit card breaking into blue data streams over a security shield

    Quote in 48 hours

    Scope your PCI DSS pentest

    QSA-ready reports for Req. 11.4. Fixed-fee quote in 24 hours.

    The short answer: PCI DSS 4.0 Requirement 11.4 requires annual external and internal penetration testing, application-layer penetration testing of in-scope custom code, segmentation testing every six months for service providers (annually for merchants), and a fresh test after any significant change to the cardholder data environment. Testers must be qualified, independent, and follow an industry-accepted methodology.

    PCI DSS 4.0 became mandatory on March 31, 2025. The penetration testing requirements (11.4.1 through 11.4.7) carry more specificity than the 3.2.1 version they replaced, and assessors have less room to interpret. This guide breaks each sub-requirement into plain English.

    What is PCI DSS Requirement 11.4?

    Requirement 11.4 is the section of PCI DSS 4.0 that mandates penetration testing of the Cardholder Data Environment (CDE) and any systems that connect to or could impact the CDE. It is split into seven sub-requirements, 11.4.1 through 11.4.7, each covering a specific aspect of methodology, scope, frequency, or remediation.

    PCI DSS 4.0 Requirement 11.4 network segmentation and testing flow diagram

    11.4.1: Documented penetration testing methodology

    You must have a documented methodology that includes industry-accepted approaches (NIST SP 800-115, PTES, OSSTMM, OWASP), coverage of the entire CDE perimeter and critical systems, internal and external testing, application-layer testing, network-layer testing, and review of threats and vulnerabilities from the last 12 months. Most failures here come from teams using a vendor's methodology without ever reading it.

    11.4.2: Internal penetration testing

    Internal pentests must run at least annually and after any significant change. Scope is every system in the CDE plus any system that could impact CDE security. The tester must be qualified (industry certifications or documented experience) and organizationally independent from the team that operates the systems being tested.

    11.4.3: External penetration testing

    External pentests run at least annually and after any significant change. Scope is the CDE perimeter and any external-facing component. Same qualifications and independence requirements as internal testing.

    11.4.4: Exploitable vulnerabilities and remediation

    Any exploitable vulnerability found during pentesting must be corrected and re-verified. This is the requirement that catches most teams. A pentest with five exploitable findings and no retest is non-compliant.

    11.4.5: Segmentation testing (annual for merchants)

    If you use network segmentation to reduce PCI scope, you must test the segmentation controls annually. The test must confirm that the segmentation is operational and effective, and must be performed by a qualified internal resource or external party. Service providers test every six months.

    11.4.6: Segmentation testing (semi-annual for service providers)

    Service providers (anyone storing, processing, or transmitting cardholder data on behalf of another entity) must test segmentation every six months. This is the requirement most often missed by SaaS payment processors and managed hosting providers.

    11.4.7: Multi-tenant service providers

    Multi-tenant service providers must support customer requests for pentest evidence and must isolate test environments to prevent cross-tenant impact. This was a clarification in 4.0 and is now explicitly enforced.

    What counts as a "significant change"?

    PCI does not give a precise list, but assessors consistently consider these significant: new hardware or software in the CDE, new network connections, new public-facing services, infrastructure migrations (cloud provider, datacenter), major application changes affecting authentication or payment flow, and acquisitions or divestitures affecting CDE scope.

    What does PCI DSS 4.0 pentest scope include?

    • Every system component in the CDE
    • Systems providing security services to the CDE (auth, logging, monitoring, key management)
    • Systems with connectivity to the CDE
    • Network segmentation controls used to limit CDE scope
    • All custom application code in the CDE (web, API, mobile)
    • External attack surface (DNS, load balancers, public IPs)

    How much does a PCI DSS 4.0 pentest cost?

    Annual pricing typically runs $10,000 to $25,000 for a single merchant CDE, and $20,000 to $50,000 for a service provider with semi-annual segmentation testing. Continuous PTaaS subscriptions can be more cost-effective for service providers. See our 2026 penetration test cost guide for full pricing detail.

    Qualifications PCI accepts for penetration testers

    PCI DSS 4.0 does not mandate specific certifications, but assessors look for at least one of: OSCP, OSWE, OSEP, OSCE, CREST CRT, CREST CCT, GPEN, GWAPT, or equivalent documented experience. The tester must also be organizationally independent from the team operating the tested systems.

    How to prepare for a PCI DSS 4.0 pentest

    1. Confirm your CDE scope diagram is current
    2. Inventory all in-scope systems, including security services and segmentation controls
    3. Gather evidence of any significant changes in the last 12 months
    4. Choose a tester with documented qualifications and independence
    5. Schedule retest capacity at the time of booking, not after
    6. Plan for segmentation testing on a separate cadence if you are a service provider

    How StealthNet AI delivers PCI DSS 4.0 pentests

    Our PCI DSS penetration testing service covers internal, external, segmentation, and application-layer testing in a single engagement. AI agents handle the breadth across the entire CDE while senior testers focus on segmentation validation and authenticated application flow. Reports include the control-mapping QSAs require, and we deliver semi-annual segmentation testing on a continuous schedule for service providers.

    Frequently asked questions

    When did PCI DSS 4.0 become mandatory?

    March 31, 2025. All assessments after that date must use 4.0.

    Do I need both internal and external pentesting under PCI 4.0?

    Yes. Requirement 11.4.2 mandates internal testing and 11.4.3 mandates external testing. They are separate requirements.

    How often does segmentation testing need to be performed?

    Annually for merchants under 11.4.5. Every six months for service providers under 11.4.6.

    Can the same person perform internal and external pentests?

    Yes, as long as they meet qualification and independence requirements for both. Most engagements bundle internal and external for cost efficiency.

    Does PCI 4.0 require application penetration testing?

    Yes. Any custom code in the CDE must be tested at the application layer. This includes web apps, APIs, and mobile back ends.

    What happens if my pentest finds exploitable vulnerabilities?

    Under 11.4.4, you must remediate and re-verify before your assessor can attest compliance. Retesting is mandatory, not optional.

    Does an AI-only pentest satisfy PCI DSS 4.0?

    Most QSAs accept hybrid AI plus human pentests. Pure AI without human attestation is rarely accepted today. Confirm with your QSA before scoping.


    Ready to find what attackers would find?

    AI-powered, hybrid, or fully manual penetration testing with audit-ready reports for SOC 2, PCI DSS, HIPAA, and CMMC. Most engagements can start within 24 hours.

    Share this article