FREE RETEST INCLUDED

PCI DSS Penetration Testing.
QSA-Ready in 5 Days.

OSCP-certified testers. Manual CDE penetration testing that satisfies Requirements 11.4.1 through 11.4.5. QSA-ready reports with segmentation validation — starting at $2,000.

Meet With A Team Member ↗
500+
Apps Tested
5 Day
Report Turnaround
<24hr
Quote Response
Free
Retest Included
ACCEPTED FORPCI DSS v4.0SOC 2ISO 27001NIST

Everything Your QSA Needs.
Nothing They Don’t.

External CDE Penetration Testing

We attack every internet-facing system in scope of your cardholder data environment — web apps, APIs, payment gateways, admin portals — from an attacker’s perspective. Satisfies 11.4.2.

Internal CDE Penetration Testing

We simulate a breached endpoint inside your CDE and test lateral movement, privilege escalation, and segmentation controls. Requirements 11.4.2 and 11.4.3 both satisfied in one engagement.

Segmentation Testing

We validate that your out-of-scope networks can’t reach the CDE. Required annually for merchants, every six months for service providers under Requirement 11.4.5.

QSA-Ready Report in 5 Days

Findings mapped to specific 11.4 sub-requirements. CVSS scores, reproduction steps, and remediation guidance formatted exactly how your Qualified Security Assessor expects. Free retest included.

Fixed Price from $2,000

No hourly billing. No surprise scope changes. Fixed quote within 24 hours of your scoping call. The price you’re quoted is the price you pay.

OSCP-Certified Testers

Every tester holds OSCP or equivalent (CREST, CEH). Credentials your QSA will recognize on sight. We document our methodology to satisfy Requirement 11.4.1.

PCI DSS v4.0

Requirement 11.4 — Fully Satisfied

Every sub-requirement covered in a single engagement. Your QSA gets everything they need.

11.4.1
Methodology
11.4.2
External
11.4.3
Internal
11.4.4
Remediation
11.4.5
Segmentation

What We Actually Test

Manual testing of every attack surface your QSA will evaluate under Requirements 11.4.2 and 11.4.3.

CARDHOLDER DATA ENVIRONMENT

Inside the CDE

We test every system that stores, processes, or transmits cardholder data — and every system connected to one. Payment flows, tokenization endpoints, admin interfaces, and the network segments between them.

  • Payment flow tampering & tokenization testing
  • Card data discovery & exposure
  • Encryption validation
  • Admin portal attack surface
  • SQL & NoSQL injection in payment paths
Best for:Level 1 Merchants · Service Providers · SAQ-D

NETWORK SEGMENTATION

Scope Reduction Validation

Requirement 11.4.5 requires you to prove your out-of-scope networks can’t reach the CDE. We test from both sides and produce evidence your QSA can validate without additional testing.

  • VLAN hop testing
  • Firewall rule validation
  • ACL bypass attempts
  • Lateral movement mapping
  • Scope reduction strategy validation
Best for:Service Providers · Level 1 Merchants · SAQ-A-EP

READY FOR YOUR PCI DSS PENTEST?

Scope your pentest in 60 seconds.

Tell us about your CDE and audit timeline. Get a fixed scope and quote from a certified pentester — not a sales rep — within 1 business day.

Meet With A Team Member ↗
Satisfies all 11.4 sub-requirements.
QSA-ready report in 5 days.
Segmentation testing included.
Free 48-hour retest included.
FAQ

Common Questions About
PCI DSS Pentesting

Does PCI DSS v4.0 require a penetration test?

Yes. Requirement 11.4 is explicit: you need manual penetration testing of your CDE — internal and external — at least annually and after any significant change. An ASV scan doesn’t satisfy Requirement 11.4. Neither does a vulnerability assessment.

What’s the difference between an ASV scan and a PCI pentest?

An ASV scan satisfies Requirement 11.3.2. A penetration test satisfies Requirement 11.4. They are separate requirements with different methodologies. v4.0 makes this distinction more explicit than v3.2.1.

How often does PCI DSS require a penetration test?

At minimum annually for both internal and external testing, plus after every significant change. Service providers must also perform segmentation testing every six months under 11.4.5.

Does the tester need specific PCI qualifications?

The tester must be organizationally independent and qualified. Our testers hold OSCP, CREST, and CEH — credentials your QSA will recognize on sight. We document our methodology to satisfy Requirement 11.4.1.

How much does a PCI DSS penetration test cost?

Starting from $2,000. Fixed price scoped to your CDE size and complexity. Get a quote within 24 hours — no hourly billing, no surprise overruns.