What does PCI DSS require for penetration testing?

Unlike SOC 2 or ISO 27001, PCI DSS flatly requires a penetration test. Requirement 11.4 mandates internal and external tests every 12 months and after significant changes, a retest to verify fixes, and segmentation tests every 6 months for service providers. What it does not require is a QSA, an ASV, or an outside firm.

Infographic: PCI DSS Requirement 11.4 requires internal and external testing every 12 months, after significant changes, and a retest to verify fixes

On this page: what 11.4 says · the mandatory retest · who may test · service providers · scans are separate · what it costs · why teams fail it

What Requirement 11.4 actually says

Most pages about PCI penetration testing paraphrase a paraphrase. The requirement itself is short and unambiguous, and you can download the standard from the PCI SSC document library to read it in full. Here is the structure:

Timeline of one year of PCI DSS testing obligations for a service provider, showing two penetration tests, segmentation tests every six months, quarterly ASV scans and a mandatory retest

RequirementWhat it obligesCadence
11.4.1a defined, documented penetration testing methodology using industry-accepted approachesmaintained
11.4.2internal penetration testing per that methodologyevery 12 months + after significant change
11.4.3external penetration testing per that methodologyevery 12 months + after significant change
11.4.4exploitable findings corrected, and testing repeated to verifyafter every remediation
11.4.5segmentation controls tested, if segmentation isolates the CDEevery 12 months
11.4.6the same segmentation testing, for service providersevery 6 months
11.4.7multi-tenant providers support customers’ external testingon request

Two things in that table surprise people. The cadence is not simply annual: “after any significant infrastructure or application upgrade or change” means a re-architecture in March obliges a test in March, not next January. And 11.4.4 makes the retest part of the requirement, not an upsell.

What counts as a significant change

The standard leaves this to you, which teams read as permission to ignore it. Your QSA will not. In practice, treat a new external service, a change to authentication or authorization, a move between cloud accounts or regions, a new component inside the cardholder data environment, or a change to segmentation as significant, and write that definition into the 11.4.1 methodology document before an assessor writes it for you. Deciding after the fact looks like a decision made to avoid a test.

The retest is mandatory, and usually unpriced

Requirement 11.4.4 is the clause that quietly doubles engagements. CompliancePoint, a QSA, quotes it as:

Exploitable vulnerabilities and security weaknesses found during penetration testing are corrected as follows…

with corrections risk-ranked through your Requirement 6.3.1 process, and testing repeated to verify them. Schellman, another QSA, is blunt about what that means in practice: after fixing, “you’ll of course need to have another pen test performed, also called a retest.” A remediation with no documented retest does not satisfy 11.4.4.

Most firms bill that retest separately at 10 to 25 percent of the original fee, so the honest annual number is higher than the quote you were given. The full cost breakdown is here. Continuous testing sidesteps the issue structurally: if the test never stops, the fix gets re-attacked as a matter of course rather than as a change order.

Who is actually allowed to test

This is where most vendor content overstates the requirement, and where a QSA-literate CTO will catch you.

Comparison of who may perform each PCI test, showing penetration testing needs organizational independence but no certification while quarterly external scanning requires an Approved Scanning Vendor

PCI DSS asks for a tester who is “qualified by experience or training” and who has organizational independence from the systems being tested. It does not ask for a certification. The parenthetical:

(not required to be a QSA or ASV)

appears repeatedly through Requirement 11.4 and the SAQs. Testing may be performed by a qualified internal resource or a qualified external third party.

Why independence still pushes the test outside

Organizational independence is the real constraint, and it is stricter than it sounds: the tester cannot assess systems they build, run, or maintain. At seed and Series A, with one platform team, there is no internal resource who clears that bar, so the test goes outside for structural reasons rather than regulatory ones. That is a more honest argument than claiming PCI demands a third party, and it survives contact with someone who has read the standard.

What your QSA will actually read

The methodology document from 11.4.1, and the evidence. Reviewers look for scope coverage of the whole cardholder data environment perimeter, testing from inside and outside, application-layer and network-layer work, findings that are validated as genuinely exploitable, and the retest. That is the same bar described in our methodology pages, and it is why an unvalidated scanner dump fails review no matter who ran it.

Service providers owe roughly double

If you sell software that sits inside someone else’s cardholder data environment, three things change:

  • 11.4.6 puts segmentation testing on a 6-month clock instead of the annual cadence merchants get.
  • 11.4.7 obliges multi-tenant providers to support their customers’ external testing. You inherit an obligation to enable testing you do not control or schedule.
  • Level 1 starts at 300,000 transactions a year, roughly 822 a day, counted across all your customers combined rather than per customer. A Series A fintech crosses into full QSA-assessed territory earlier than founders expect.

Counted honestly, a segmented service provider owes at least four penetration tests a year (internal, external, and two segmentation tests), plus every retest, plus four quarterly ASV scans.

ASV scans are a different obligation

Requirement 11.3.2 requires external vulnerability scans every 90 days by a PCI SSC Approved Scanning Vendor, and unlike almost everything else in v4.x it cannot be met through the customized approach. This is the one place PCI truly does mandate a certified outside party.

It is also the most common confusion in the market: a passing quarterly ASV scan is not evidence for 11.4. Scans enumerate known vulnerabilities; a penetration test exploits them and chains them. The difference in what each one finds is the whole reason the standard has both, and the customized approach objective for 11.4.1 is framed around resisting a competent manual attacker rather than a tool.

What this costs in practice

For a typical segmented environment, budget $8,000 to $30,000 a year across the internal test, the external test, segmentation testing, and retests, with ASV scanning billed separately. Our own numbers are public and the full market bands are here:

WhoPentest, per monthWhat it covers
Startups: teams of 10 or fewer (no funding or age limit)$299, AI-ledcontinuous testing on one product, plus SOC 2 controls
Every other company$2,999, human in the loopthe same, with a hacker validating exploitability

Where the money actually goes

The cost driver you actually control is scope. Every system that can affect the security of the cardholder data environment is in scope, so segmenting aggressively and keeping card data out of your own systems shrinks the testable surface and the bill with it. That work pays for itself in the first assessment.

Why this is the requirement teams fail

Requirement 11 has been the worst-performing requirement in PCI for years. Reporting on Verizon’s Payment Security Report, SecurityWeek summarised it plainly:

Requirement 11 continues to lag at the back of the pack when it comes to full compliance

with the widest control gap of any requirement. The same body of research produced the line worth keeping in mind before treating this as paperwork:

At the time of a breach, no organization was compliant across all 12 PCI DSS requirements.

The pattern behind the failures is consistent: teams test once a year, re-architect in month four, and never test again, which fails the significant-change clause. Or they remediate and never document a retest, which fails 11.4.4. Both are cadence problems, not capability problems, which is the argument for testing continuously rather than annually. It is also why we publish our benchmark results rather than asking anyone to take the cadence claim on faith.

The short version

  • PCI DSS genuinely requires penetration testing, unlike SOC 2: internal and external, every 12 months and after significant change.
  • The tester needs organizational independence and competence, not a QSA or ASV badge.
  • The retest in 11.4.4 is mandatory. Check whether it is in your quote.
  • Service providers owe segmentation tests every 6 months and must support their customers’ testing.
  • Quarterly ASV scanning under 11.3.2 is a separate obligation and does need a certified vendor.
  • Budget $8,000 to $30,000 a year for a segmented environment, or start from $299 a month on continuous testing.

Frequently asked questions

Does PCI DSS require a third-party penetration test?

No. PCI DSS requires organizational independence, not an outside company. The standard says testing may be performed by a qualified internal resource or a qualified external third party, and the phrase not required to be a QSA or ASV appears repeatedly in Requirement 11.4. The practical catch is that independence means the tester cannot assess systems they build, run, or maintain, and most small teams have nobody who qualifies.

How often does PCI DSS require penetration testing?

Internal and external tests at least once every 12 months, and after any significant infrastructure or application upgrade or change. If you use segmentation to isolate the cardholder data environment, segmentation controls get tested every 12 months for merchants and every 6 months for service providers.

Is the retest actually mandatory under PCI DSS?

Yes. Requirement 11.4.4 says exploitable vulnerabilities and security weaknesses found during penetration testing are corrected, and that testing is repeated to verify the corrections. A remediation with no documented retest does not satisfy the requirement, which is why every PCI engagement is structurally two phases. Ask whether the retest is in the quoted price.

Do quarterly ASV scans count as a penetration test?

No, they are a separate obligation. Requirement 11.3.2 makes external vulnerability scans a quarterly job for a PCI SSC Approved Scanning Vendor, and it cannot use the customized approach. Requirement 11.4 is manual attack work on top of that. You owe both, and passing scans does not evidence 11.4.

How much does a PCI penetration test cost?

Plan on 8,000 to 30,000 dollars a year for a typical segmented environment once you count the internal test, the external test, segmentation testing, and the retest, with ASV scanning billed separately. The number moves with the size of your cardholder data environment, which is why scope reduction pays for itself.

Will a QSA accept an AI-led penetration test?

QSAs assess the methodology and the evidence, not the brand of tool. Requirement 11.4.1 wants a documented, industry-accepted methodology, and the customized approach for it is framed around resisting a competent manual attacker, so unvalidated scanner output does not qualify. Continuous AI testing with human-validated, reproducible findings and a documented retest does meet that bar, and it makes the every-significant-change clause survivable.