PCI DSS
Annually and after significant changePayment Card Industry Data Security Standard v4.0.1
Annual external and internal penetration testing of the cardholder data environment, plus segmentation testing.
Recommended services
What it requires
Requirement 11.4 calls for external and internal penetration testing at least once every 12 months and after significant changes, following a documented methodology, with exploitable findings corrected and retested. Where segmentation isolates the cardholder data environment, segmentation controls must be tested at least every 12 months, or every six months for service providers.
PCI DSS v4.0.1, Requirements 11.4.1 to 11.4.7
Evidence we provide
- Report following a documented, industry-accepted methodology
- Segmentation testing results with proof of isolation
- Retest confirmation of corrected findings
- Attestation letter for your QSA or SAQ