PCI DSS Penetration Test
Do you process credit card payments? Then you need to comply with the Payment Card Industry Data Security Standard (PCI DSS). Requirement 11.4 mandates that you carry out a penetration test on your cardholder data environment (CDE) at least annually.
What does PCI DSS require for pentesting?
PCI DSS v4.0 requirement 11.4 specifically mandates:
- Annual external penetration test on internet-facing systems
- Annual internal penetration test on systems in or connected to the CDE
- Segmentation testing if you use network segmentation to isolate the CDE
- Remediation testing after resolving critical findings
Who is a PCI DSS pentest relevant for?
- Webshops that process or store payment data themselves
- Payment service providers (PSPs)
- Fintech companies with payment infrastructure
- Hotels, hospitality and retail with POS systems
- SaaS platforms with subscription management and billing
Our approach
MonkeysICT uses the PTES (Penetration Testing Execution Standard) and OWASP methodology as a foundation, supplemented with PCI DSS-specific test scenarios. We deliver a report that meets the requirements of your Qualified Security Assessor (QSA).
FAQ
How often do I need to run a PCI DSS pentest?
At least annually, and after every significant change to the infrastructure or application. If segmentation is used, a segmentation test is also required every six months.
Does the pentester need to be PCI DSS certified?
PCI DSS requires that the pentester be organisationally independent from the environment being tested and have demonstrable penetration testing experience. A specific PCI certificate is not legally mandatory, but practical experience and methodological documentation are.
What’s the difference between a PCI ASV scan and a pentest?
An ASV scan (Approved Scanning Vendor) is an automated external vulnerability scan — requirement 11.3. A penetration test goes further: an ethical hacker actively attempts to breach the CDE — requirement 11.4. Both are mandatory.
Also see: API pentest | web application pentest | request a quote
