PCI DSS penetration testing: the one framework that names it directly

Unlike SOC 2, ISO 27001, or NIS2, PCI DSS does not imply a pentest - it requires one by name. Requirement 11.4 mandates a documented testing methodology plus internal and external penetration testing at least once every 12 months. The nuance is who is allowed to run it, not whether it is required.

Does PCI DSS require a penetration test?

Yes, literally. PCI DSS v4.0.1 Requirement 11.4 requires entities to define, document, and implement a penetration testing methodology, and to perform internal and external penetration testing at least once every 12 months and after any significant change to the network or applications. This is the one framework in this hub where "requires a pentest" is accurate rather than a marketing stretch.

PCI DSS is the exception among the frameworks on this site: it names penetration testing directly, with a fixed cadence and explicit tester expectations, instead of implying it through a general risk-management or effectiveness-review obligation.

The nuance that still matters is not whether a pentest is required, but who is allowed to perform it and what else Requirement 11 expects alongside it - a documented methodology, segmentation testing where relevant, and separate, more frequent vulnerability scanning under Requirement 11.3.

Requirement 11.4 explained

Requirement 11.4.1 requires the penetration testing methodology itself to be defined, documented, and implemented, based on an industry-accepted approach, covering the entire cardholder data environment (CDE) perimeter and critical systems, testing from both inside and outside the network, and validating segmentation controls. It also requires application-layer and network-layer testing, review of threats and vulnerabilities from the prior 12 months, a documented approach to risk-ranking what is found, and retention of results for at least 12 months.

Requirement 11.4.2 requires internal penetration testing at least once every 12 months and after any significant change. Requirement 11.4.3 requires the same cadence for external penetration testing. Requirement 11.4.4 requires that exploitable vulnerabilities and security weaknesses found during testing are corrected, with the test repeated to verify the fix.

Internal, external, and segmentation testing

Internal (11.4.2) and external (11.4.3) penetration tests cover different vantage points on the same cardholder data environment - from inside the network and from the outside looking in. Where an entity uses network segmentation to reduce PCI DSS scope, Requirement 11.4.5 requires a separate penetration test of those segmentation controls at least once every 12 months for all entities, tightening to every 6 months for service providers under Requirement 11.4.6.

Requirement 11.3 is a distinct, more frequent obligation and is not a substitute for penetration testing: internal vulnerability scans are required at least once every 3 months and must be authenticated scans (11.3.1, 11.3.1.2), while external vulnerability scans are required at least once every 3 months and must be performed by a PCI SSC Approved Scanning Vendor (ASV) under Requirement 11.3.2. Scanning is automated and vulnerability-focused; penetration testing is exploit-driven, less frequent, and goes deeper.

Tester qualification and independence

Requirements 11.4.2 and 11.4.3 require the penetration test to be performed by a qualified internal resource or qualified external third party, with organizational independence of the tester (not required to be a QSA or ASV) - an internal team can run the test if it is independent of the group that built and manages the environment and holds verifiable qualifications. That tester does not need to be a Qualified Security Assessor (QSA); QSA status is a separate credential for signing your PCI DSS assessment, not a requirement for the pentest itself.

That qualified, organizationally-independent tester expectation is the honest limit on automation here: an AI-only or fully automated test, by itself, does not satisfy Requirement 11.4 without a qualified human tester defining the methodology, directing the engagement, and standing behind the findings. Requirement 11.3.2 has its own separate, non-negotiable gate - the external vulnerability scan must be run by a vendor on the PCI SSC's list of Approved Scanning Vendors. No amount of tester qualification substitutes for ASV status on that specific requirement.

How Intrudify fits

Intrudify's engagements are human-validated by OSCE3-certified testers, not run on automated output alone, which is why Intrudify engages as an external testing provider intended to meet the qualified, organizationally-independent tester expectation in Requirements 11.4.2 and 11.4.3. Your QSA or assessor confirms tester qualification for your assessment, with reproducible proof-of-exploit and developer-ready remediation mapped to Requirement 11.4.

Intrudify is not a QSA and does not issue your PCI DSS attestation, and Intrudify is not a PCI SSC Approved Scanning Vendor: it does not perform the ASV scans that Requirement 11.3.2 specifically requires. If you need external vulnerability scans for Requirement 11.3.2, you still need a separately listed ASV for that requirement - Intrudify supports the Requirement 11.4 penetration testing and 11.4.5/11.4.6 segmentation testing obligations, not the ASV scanning obligation.

  • Findings mapped to Requirement 11.4 methodology elements, with segmentation testing support for 11.4.5/11.4.6
  • Human-validated by OSCE3-certified testers - the qualified, organizationally independent tester Requirements 11.4.2 and 11.4.3 require
  • Reproducible proof-of-exploit for high and critical findings, developer-ready remediation, and a re-test window supporting 11.4.4
  • Does not replace ASV scanning under Requirement 11.3.2 - use a PCI SSC-listed Approved Scanning Vendor for that specific obligation

How a pentest maps to controls

Control What a pentest evidences
Req 11.4 Penetration testing methodology defined, documented, and implemented; internal and external penetration testing performed at least once every 12 months and after any significant change (11.4.1-11.4.4).
Req 11.4.5-11.4.6 Penetration testing of segmentation controls used to isolate the CDE - at least every 12 months for all entities (11.4.5), or every 6 months for service providers (11.4.6).
Req 11.3 Internal vulnerability scans at least once every 3 months using authenticated scanning (11.3.1, 11.3.1.2); external vulnerability scans at least once every 3 months, performed by a PCI SSC Approved Scanning Vendor (11.3.2).

Need audit-ready evidence for PCI DSS?

Book a scoping call

Frequently asked questions

Does PCI DSS require a penetration test?

Yes. Requirement 11.4 requires a documented penetration testing methodology plus internal and external penetration testing at least once every 12 months and after any significant change - PCI DSS is the one major framework that names a pentest directly rather than implying one.

Who is allowed to perform a PCI DSS penetration test?

A qualified internal resource or a qualified external third party, provided the tester has organizational independence from the systems under test (Requirements 11.4.2 and 11.4.3). The tester does not need to be a QSA or an ASV - those are separate credentials for signing your assessment and running quarterly scans.

Can an AI-only or fully automated test satisfy PCI DSS Requirement 11.4?

Not by itself. Requirements 11.4.2 and 11.4.3 require a qualified, organizationally independent tester defining the methodology and standing behind the findings, so an automated or AI-only test needs a qualified human tester in the loop to satisfy Requirement 11.4.

What is the difference between a PCI DSS pentest and an ASV scan?

A pentest (Req 11.4) is exploit-driven, runs at least annually, and can be performed by a qualified independent tester. An ASV scan (Req 11.3.2) is an automated external vulnerability scan required quarterly and must be run by a PCI SSC Approved Scanning Vendor specifically.

Is Intrudify a PCI Approved Scanning Vendor (ASV)?

No. Intrudify is not an ASV and does not perform the quarterly external vulnerability scans Requirement 11.3.2 requires. You need a separately PCI SSC-listed ASV for that requirement; Intrudify supports the Requirement 11.4 penetration testing obligation instead.

How often must segmentation be tested under PCI DSS?

At least once every 12 months for all entities that use segmentation to reduce PCI DSS scope (Requirement 11.4.5), tightening to at least every 6 months for service providers (Requirement 11.4.6), and again after any change to the segmentation controls.

What happens if a PCI DSS pentest finds exploitable vulnerabilities?

Requirement 11.4.4 requires that exploitable vulnerabilities and security weaknesses found during testing be corrected, and the test repeated to verify the fix actually closes the gap before the engagement is considered complete.

Sources
Related frameworks
SOC 2 Not named in the criteria, but auditors expect an annual pentest as evidence. DORA General testing (incl. penetration testing) is required under Art. 24-25; a separate, human-led TLPT is required only for entities identified under Art. 26-27, and no automated test substitutes for it.
All compliance frameworks