PCI DSS 4.0 and Penetration Testing
PCI DSS is owned by the PCI Security Standards Council. Version 4.x tightens how entities define and run penetration testing under Requirement 11.4, starting with 11.4.1 — a documented, implemented methodology — not an ad-hoc annual exercise.
What Requirement 11.4.1 is asking for
At a high level, entities must define, document, and implement a penetration testing methodology that typically addresses:
- Industry-accepted approaches
- Coverage of the cardholder data environment (CDE) perimeter and critical systems
- Testing from both inside and outside the network
- Validation of segmentation / scope-reduction controls
- Application-layer and network-layer penetration testing
- Review of threats and vulnerabilities experienced in the last 12 months
- A documented approach to assessing and remediating exploitable findings
- Retention of testing and remediation results (commonly at least 12 months)
Primary documents live in the PCI SSC Document Library, including PCI DSS itself and the PCI SSC Penetration Testing Guidance information supplement.
Scope: CDE, connected-to, and segmentation
Mis-scoped tests fail assessments even when the report looks polished. Map the test to your current PCI scope diagram, including segmentation controls you rely on to shrink the CDE.
Cadence and triggering events
Report and remediation evidence QSAs expect
Related testing surfaces
Cardholder data often flows through web applications and APIs. Align those surfaces with your documented 11.4 methodology before the QSA fieldwork starts.
Related services
FAQ
- Is a vulnerability scan enough for PCI DSS 11.4?
- No. ASV scanning and penetration testing are separate requirements. Requirement 11.4 expects industry-accepted penetration testing approaches, not scan output alone.
- Does 11.4.1 cover application and network layers?
- Yes. The defined methodology must include application-layer testing (at minimum covering vulnerabilities referenced in Requirement 6.2.4) and network-layer testing of components that support network functions and operating systems.