Skip to content

PCI DSS v4.0 · Track A

Requirement 11.4 does not need a QSA. It needs someone who can test.

Requirement 11.4 asks for penetration testing by a qualified resource with organisational independence. It does not ask for QSA accreditation. That applies to the Report on Compliance, which is a different piece of work by a different firm.

Zero Harbor Security is not a QSA and not an ASV, does not produce Reports on Compliance, and does not perform your quarterly approved scanning. It does the 11.4 testing and the segmentation validation, and hands your assessor evidence with a named practitioner behind it.

Scope

The four sub-requirements this covers.

Requirement 11.4 is not one test. Segmentation is where cardholder data environment scope quietly expands between assessments, and it is the part most often discovered late.

  • 11.4.2 · Internal penetration testing

    At least every twelve months and after any significant change. Tested from inside the network boundary, against the cardholder data environment.

  • 11.4.3 · External penetration testing

    At least every twelve months and after any significant change, from outside the perimeter. Distinct from the quarterly ASV scan, which is a different requirement and a different provider.

  • 11.4.5 · Segmentation controls

    If you use segmentation to reduce scope, the controls must be tested at least every twelve months. This is where CDE scope quietly expands and an assessment goes sideways.

  • 11.4.6 · Service providers, every six months

    Service providers test segmentation twice a year rather than annually. If you are a PSP or a platform handling other people’s cardholder data, this is you.

“Simply running an automated tool does not satisfy the penetration testing requirement… The penetration tester must interpret the results of any automated tools and determine whether additional testing is needed.”
PCI Security Standards Council · Penetration Testing Guidance v1.1 · §4.1

The engagement

Fixed fee, published, with the boundary stated.

Your QSA keeps the assessment. This is the testing underneath it, which is why an assessor can refer the work without competing for it.

PCI DSS v4.0 segmentation and pentest

from $16,500

Cardholder data environment scoping, segmentation validation, and Requirement 11.4 testing.

  • CDE scope validation
  • Segmentation testing
  • Internal and external
  • Remediation retest

Typical duration · 7 days

Scope a PCI test

Questions

What people ask before they scope this.

Does a PCI DSS penetration test have to be done by a QSA?
No. PCI DSS Requirement 11.4 requires a penetration test performed by a qualified internal or external resource with organisational independence. It does not require QSA accreditation. The Report on Compliance itself does require a QSA, and that is separate work.
Is this the same as an ASV scan?
No, and they are not substitutes. Quarterly external vulnerability scanning under Requirement 11.3.2 must be performed by a PCI-approved scanning vendor. Zero Harbor Security is not an ASV and does not perform that scan. Requirement 11.4 penetration testing is a separate requirement that is not gated by accreditation.
Can Zero Harbor Security complete our Report on Compliance?
No. A Report on Compliance can only be produced by a Qualified Security Assessor company. This engagement produces the penetration test and segmentation validation evidence your QSA will ask for, and an attestation letter naming the practitioner who performed it.
How often do we need this?
Requirements 11.4.2 and 11.4.3 are at least every twelve months and after any significant change. Segmentation testing under 11.4.5 is at least every twelve months, and under 11.4.6 every six months for service providers.
What does a PCI DSS penetration test cost?
$16,500 as a fixed fee for 7 days, covering cardholder data environment scope validation, segmentation testing, internal and external testing, and one round of retesting. Published rather than quoted on request.
Does automated tooling satisfy Requirement 11.4?
No. PCI Security Standards Council guidance is explicit that simply running an automated tool does not satisfy the penetration testing requirement, and that the tester must interpret the results of any automated tools and determine whether additional testing is needed.