Requirement 11.4 asks for penetration testing by a qualified resource with
organisational independence. It does not ask for QSA accreditation. That applies to the
Report on Compliance, which is a different piece of work by a different firm.
Zero Harbor Security is not a QSA and not an ASV, does not produce
Reports on Compliance, and does not perform your quarterly approved scanning. It does
the 11.4 testing and the segmentation validation, and hands your assessor evidence with
a named practitioner behind it.