PCI-DSS Penetration Testing: Requirements, Scope & Timing (2026)
Short answer: yes. Of the major compliance frameworks, PCI-DSS is the one that explicitly requires penetration testing. Requirement 11.4 of PCI-DSS v4.0 calls for external and internal penetration tests at least once every 12 months and after any significant change to the cardholder data environment. If you store, process, or transmit card data, a pen test is not optional — it is written into the standard.
Here is what that requirement actually covers, how the scope works, how often you have to test, and what an assessor expects to see.
What PCI-DSS Requirement 11.4 requires
Requirement 11.4 sets out penetration testing for the cardholder data environment (CDE). In plain terms, it asks for:
- A defined penetration-testing methodology based on an industry-accepted approach (such as NIST SP 800-115)
- External penetration testing — from outside your network, against your internet-facing systems
- Internal penetration testing — from inside, simulating an attacker who is already past the perimeter
- Testing at least once every 12 months and after any significant change to the environment
- Remediation of exploitable findings, followed by a retest to confirm they are closed
Segmentation testing — the part teams forget
If you use network segmentation to reduce your PCI scope — keeping the cardholder data environment isolated from the rest of your network — PCI-DSS requires you to test that the segmentation actually holds. That segmentation testing is required at least every 12 months for most merchants, and more frequently for service providers. Skipping it is one of the most common ways an otherwise-compliant environment fails an assessment.
How often do you need to test?
The baseline is every 12 months, plus after any significant change — a new payment application, a network re-architecture, a migration, or a major infrastructure update. "Significant change" is judged against your environment, so if you are not sure whether a change qualifies, the safe assumption is that it does. Service providers face tighter cadences on segmentation testing than merchants.
Who is allowed to perform it?
PCI-DSS requires the tester to be organizationally independent and qualified — it does not have to be a QSA, but it cannot be the person who configured the systems being tested. In practice that means a qualified third-party firm, or an internal team with demonstrable independence from the environment under test. Most organizations use an external firm because independence is easier to prove and the report carries more weight with the assessor.
What the report needs to include
An assessor-ready PCI penetration test report generally contains:
- The methodology used and the scope tested (CDE boundaries, external and internal)
- Segmentation test results, if segmentation is used to reduce scope
- Each finding with severity, evidence, and business impact
- Remediation guidance and retest evidence for exploitable findings
- Dates that prove the test falls inside your assessment window
How PCI compares to SOC 2 and HIPAA
This is where PCI is different. SOC 2 and HIPAA do not name penetration testing — a pen test is the practical way to satisfy their vulnerability and risk requirements, but the standards leave it implicit. PCI-DSS removes the ambiguity: it tells you to test, how (external and internal), and how often (annually and after significant change). If you are subject to more than one framework, a well-scoped test can produce evidence for all of them at once.
Does a vulnerability scan satisfy PCI penetration testing?
No. PCI requires both quarterly vulnerability scanning and penetration testing — they are separate requirements. A scan is not a substitute for a test.
What counts as a "significant change"?
New systems in the CDE, changes to network topology or firewall rules, upgrades to payment applications, or new components that handle card data. When in doubt, treat it as significant and test.
Do small merchants still need a pen test?
It depends on your SAQ type and how you handle card data. Some self-assessment paths reduce the requirement, but any environment that stores or processes card data internally should assume penetration testing applies. Confirm against your specific SAQ.
Have a compliance deadline? Get a fixed price before any work starts.
Book a 20-minute scoping call