ClearPenTest

PCI Security Standards Council · PCI DSS v4.0.1 (Payment Card Industry Data Security Standard)

Does PCI DSS require a penetration test?

PCI DSS is the card brands' security standard for anyone who stores, processes or transmits cardholder data. It is the one framework on this list that requires penetration testing in so many words.

Required by nameRequirement 11.4

The short answer

Yes, explicitly. PCI DSS Requirement 11.4 mandates a defined penetration testing methodology, internal and external penetration testing at least once every 12 months and after any significant infrastructure or application change, correction of exploitable vulnerabilities, and retesting to verify the fix. Where segmentation is used to reduce scope, it must be tested too.

Who it applies to

Any organization handling payment card data, with the depth of validation set by transaction volume and how the data is handled.

In detail

PCI DSS is unusual among these frameworks because it is prescriptive. Requirement 11.4 does not ask for an evaluation that controls are functioning and leave the technique open. It names penetration testing, sets a frequency, and dictates what happens to the findings.

The sub-requirements matter as much as the headline. 11.4.1 requires a documented methodology based on an industry-accepted approach. 11.4.2 and 11.4.3 require internal and external testing respectively, at least every 12 months and after significant change. 11.4.4 requires exploitable vulnerabilities to be corrected and the testing repeated to verify the correction. 11.4.5 and 11.4.6 cover segmentation controls, with 11.4.6 applying to service providers at a six-month cadence.

Scope is where most of the money is won or lost. Effective network segmentation that keeps systems out of the cardholder data environment reduces what has to be tested, but segmentation only counts if it has been tested and shown to work, which is exactly what 11.4.5 is for.

What to have in scope

  • The full cardholder data environment, internal and external
  • Segmentation controls, tested to prove the reduced scope is real
  • Application and network layers, per the 11.4.1 methodology
  • Retesting after remediation, which 11.4.4 requires rather than suggests

Questions people ask

Does PCI DSS require a penetration test?

Yes. Requirement 11.4 requires internal and external penetration testing at least once every 12 months and after any significant infrastructure or application change, following a documented methodology, with exploitable vulnerabilities corrected and the testing repeated to verify the correction.

How often does PCI DSS require penetration testing?

At least once every 12 months, and additionally after any significant infrastructure or application change. Service providers using segmentation must test those segmentation controls at least every six months under 11.4.6.

What is the difference between a PCI scan and a PCI penetration test?

They are separate requirements. Requirement 11.3 covers vulnerability scanning, including quarterly external scans by an Approved Scanning Vendor. Requirement 11.4 covers penetration testing. Passing scans does not satisfy the penetration testing requirement.

This page describes published standards and regulations and is not legal advice. Where a rule is proposed rather than in force, it is labelled as such. Confirm obligations with your auditor or counsel.

Get a scoped price without a discovery call

Tell us what is in scope and what your audit needs. You get a fixed price and a date, not a quote after two meetings.