Skip to content
Selva Ops

Compliance

PCI DSS 4.0 and Penetration Testing

Published

Selva Ops S.R.L.

PCI DSS is owned by the PCI Security Standards Council. Version 4.x tightens how entities define and run penetration testing under Requirement 11.4, starting with 11.4.1 — a documented, implemented methodology — not an ad-hoc annual exercise.

What Requirement 11.4.1 is asking for

At a high level, entities must define, document, and implement a penetration testing methodology that typically addresses:

  • Industry-accepted approaches
  • Coverage of the cardholder data environment (CDE) perimeter and critical systems
  • Testing from both inside and outside the network
  • Validation of segmentation / scope-reduction controls
  • Application-layer and network-layer penetration testing
  • Review of threats and vulnerabilities experienced in the last 12 months
  • A documented approach to assessing and remediating exploitable findings
  • Retention of testing and remediation results (commonly at least 12 months)

Primary documents live in the PCI SSC Document Library, including PCI DSS itself and the PCI SSC Penetration Testing Guidance information supplement.

Scope: CDE, connected-to, and segmentation

Mis-scoped tests fail assessments even when the report looks polished. Map the test to your current PCI scope diagram, including segmentation controls you rely on to shrink the CDE.

Cadence and triggering events

Report and remediation evidence QSAs expect

Cardholder data often flows through web applications and APIs. Align those surfaces with your documented 11.4 methodology before the QSA fieldwork starts.

Related services

FAQ

Is a vulnerability scan enough for PCI DSS 11.4?
No. ASV scanning and penetration testing are separate requirements. Requirement 11.4 expects industry-accepted penetration testing approaches, not scan output alone.
Does 11.4.1 cover application and network layers?
Yes. The defined methodology must include application-layer testing (at minimum covering vulnerabilities referenced in Requirement 6.2.4) and network-layer testing of components that support network functions and operating systems.

See what the deliverable looks like

Review a sanitized sample report before you talk to anyone — findings structure, severity model, and remediation detail.

Get the sample report