Penetration Testing for PCI DSS Compliance

Penetration testing is a mandatory requirement for most organisations pursuing PCI DSS compliance. Under Requirement 11.4, PCI DSS v4.0.1 mandates that both internal and external penetration testing be performed regularly to assess the security of the cardholder data environment (CDE). While the precise obligations depend on your environment and scope, penetration testing plays a central role in validating the effectiveness of your security controls.

What is a Penetration Test?

A penetration test (or pentest) is an authorised, simulated cyberattack designed to identify and exploit security weaknesses in your systems. Unlike automated vulnerability scans, penetration tests rely on skilled human testers who mimic real-world attack techniques to evaluate the true risk posed by vulnerabilities.

Pentests simulate how an attacker might breach your defences, providing a practical measure of your environment’s resilience. They help organisations:

  • Identify security gaps
  • Prioritise remediation efforts
  • Validate segmentation and architecture
  • Meet compliance and regulatory requirements

Real-World Impact of Penetration Testing

For example, a mid-sized retailer undergoing a PCI DSS assessment engaged a penetration tester who discovered that a forgotten admin interface for an old web application was still exposed to the internet. Although protected by a weak password, it allowed access to a backend system containing cardholder data. Because the risk was discovered and remediated pre-assessment, the business avoided a potential breach and the costly consequences that could follow.

Why Penetration Testing Matters for PCI DSS

PCI DSS explicitly requires penetration testing under Requirement 11.4: Annual and post-change testing for all systems in the CDE, covering both network and application layers, including segmentation controls.

Penetration testing supports a proactive approach by:

  • Identifying exploitable vulnerabilities
  • Validating defences before attackers do
  • Providing evidence of control effectiveness for assessors

Key Changes in PCI DSS v4.0 Related to Pentesting

PCI DSS v4.0 introduces several updates to penetration testing expectations:

  • Stronger linkage to risk-based testing: Organisations using the Customised Approach can tailor testing frequency based on a targeted risk analysis, allowing more flexibility if justified.
  • More emphasis on change detection: Requirement 11.4.7 focuses on detecting and responding to failures in penetration testing processes or remediation efforts.
  • Greater clarity on segmentation testing: Requirements now stress not only validating segmentation but doing so in a manner representative of actual access attempts.
  • Alignment with continuous testing models: PCI DSS v4.0 encourages more frequent, risk-driven testing over rigid calendar-based scheduling.

These changes aim to ensure that pentesting isn’t just a tick-box activity, but part of a broader, ongoing security assurance strategy.

What’s Involved in a PCI Penetration Test?

A PCI-compliant pentest typically includes:

  1. Scoping – Define systems, IPs, applications in-scope (entire CDE and connected systems).
  2. Reconnaissance – Identify potential attack surfaces using passive and active techniques.
  3. Vulnerability Identification – Use tools and manual analysis to uncover exploitable issues.
  4. Exploitation – Safely exploit vulnerabilities to demonstrate business impact.
  5. Reporting – Provide detailed findings, proof of exploit, risk ratings, and remediation guidance.
  6. Retesting – Confirm that remediations were effective and controls are now operating as intended.

How QSAs Evaluate Penetration Tests

Qualified Security Assessors will review your pentest as part of your PCI Scope. You should ensure:

  • Clear documentation of scope, methodology, and testing date
  • Evidence that all high-risk findings were remediated
  • Retest results to verify fixes
  • Inclusion of segmentation testing, if applicable

Who Can Perform PCI DSS Penetration Testing?

PCI DSS requires penetration testing to be performed by individuals who are:

  • Qualified and experienced in penetration testing
  • Organisationally independent from those managing tested systems
  • Familiar with PCI DSS and industry methodologies

Using an external provider (like Securious) ensures objectivity and access to specialist expertise.

Preparing for a PCI DSS Pentest

Define Scope Thoroughly Work with your testing provider to accurately define the systems, applications, and environments in scope — including the entire CDE, connected systems, APIs, and any third parties.

Notify Key Stakeholders Inform internal teams about the test to prevent disruptions or unnecessary incident responses.

Resolve Past Issues Address previous pentest findings to avoid recurrence and demonstrate a maturing security posture.

Validate Segmentation Ensure segmentation controls (if used) are documented and up-to-date. These must be tested explicitly.

Recognised Testing Methodologies

A high-quality pentest should follow standards such as:

  • OWASP Testing Guide (for web apps)
  • NIST SP 800-115
  • Penetration Testing Execution Standard (PTES)
  • CREST or CHECK frameworks (where certification applies)

Always confirm your provider uses recognised methodologies and has PCI DSS experience.

Penetration Testing in Cloud Environments

Even when hosted in AWS, Azure, or Google Cloud, PCI DSS still applies. Remember:

  • Cloud customers are responsible for testing their systems (shared responsibility model)
  • Common risks include IAM misconfigurations, insecure storage, and exposed services
  • Testing permissions may be needed from cloud providers

Securious regularly performs PCI pentests in cloud and hybrid environments, ensuring all risks are covered.

Cost and Duration Considerations

The cost and timeline for a PCI penetration test vary based on:

  • Size and complexity of the environment
  • Number of systems or IPs in scope
  • Depth of application testing
  • Cloud vs. on-premise architecture

Most tests take between 3–10 days and pricing is typically scoped during initial consultation.

Retesting and Continuous Improvement

Under PCI DSS, retesting is not optional. Once vulnerabilities are remediated, your provider must:

  • Reassess the same systems to ensure fixes are effective
  • Confirm no new vulnerabilities have been introduced
  • Verify that all controls now function as expected

This approach supports ongoing improvement rather than treating each test as a standalone activity.

Common Questions and Misconceptions

Do I need a penetration test if I use a payment processor? Possibly. Even if you outsource card processing, if you have systems in-scope — such as web servers handling card data before redirection — you may still be required to perform pentesting.

Can vulnerability scans replace a penetration test? No. Vulnerability scans are automated and identify known issues, while penetration tests involve manual exploitation and assess actual risk. Both are required under PCI DSS, but they serve different purposes.

Can my IT team perform the pentest? Only if they are qualified, experienced, and organisationally independent. That typically means someone not responsible for maintaining or managing the tested systems.

What happens if I fail a pentest? There’s no pass/fail — but any high-risk vulnerabilities must be addressed and retested before your PCI DSS compliance can be validated.

Do I need to test every system? You must test all systems within your CDE and any connected or in-scope systems that could impact its security. Accurate scoping is essential.

Best Practices

To get the most value from your PCI DSS penetration testing programme:

Integrate testing into your Software Development Life Cycle (SDLC) – Don’t limit it to annual compliance; test early and throughout development.

Test regularly, not reactively – Adopt continuous security testing, especially in dynamic environments.

Prioritise remediation by risk – Focus first on high-impact vulnerabilities rather than just severity scores.

Document everything – Maintain detailed records of scope, methodologies, results, and fixes.

Use experienced partners – Work with a testing provider who understands PCI DSS and your specific environment.

How Securious Can Help

As a UK-based Qualified Security Assessor Company (QSAC), Securious provides:

  • PCI-focused penetration testing for CDE systems
  • External vulnerability scanning with ASV attestation
  • Scope validation aligned to your environment
  • Support for segmentation validation
  • Testing in cloud, hybrid, or traditional environments

Our expert team adheres to NCSC guidelines and OWASP Top 10 principles. We deliver actionable reports, clear remediation advice, and follow-up retesting to help you achieve and maintain compliance.

To discuss your requirements:

Useful resources