Compliance

PCI DSS Penetration Testing.

PCI DSS 4.0 Requirement 11.4 testing. Internal, external, segmentation, application layer. Operator-led. Mapped to PCI evidence requirements.

File · What PCI

What PCI DSS 4.0 requires

PCI DSS 4.0 Requirement 11.4 mandates penetration testing of the cardholder data environment at least annually and after any significant change. The standard explicitly requires application-layer testing, network-layer testing, segmentation control testing, and remediation verification.

Operator Note

Segmentation is where PCI engagements fall apart

Proving an out-of-scope network cannot reach the CDE means actually trying to cross that boundary: an operator improvising against the real firewall and routing posture, not a port sweep against the documented one. A QSA who knows Requirement 11.4 can tell which one you bought.

Operator Note OPR · STANDARD-OF-WORK
“Segmentation that passed a scanner has been broken in front of me by an operator with five minutes and a working knowledge of the network. PCI 11.4 exists because of exactly that gap.”
Bailey Besheer, Managing Director of Cybersecurity Services

File · Scope coverage

Scope coverage

  • [01] External network testing against internet-facing CDE assets.
  • [02] Internal network testing from inside the CDE perimeter.
  • [03] Segmentation testing to validate that out-of-scope networks cannot reach the CDE.
  • [04] Application-layer testing for in-scope payment applications.
  • [05] Remediation verification on every fix, retested until the QSA has clean evidence to close 11.4.

File · FAQ

Frequently Asked Questions

Q1 Does Alacrinet meet PCI DSS 11.4 evidence requirements?

Yes. The technical report includes scope, methodology, tester qualifications, findings with remediation, and retest evidence.

Q2 Are your testers PCI QSA?

We are not a QSA firm; we are the pentest vendor that QSAs and ROC writers point clients at for the 11.4 evidence.

Q3 How long does a PCI pentest take?

Typical engagements run three to five weeks depending on CDE size and segmentation complexity.

Talk to an Operator

Ready to See Your Environment the Way Attackers Do?

Real operators. Real attack paths. Real business impact. Talk to us about your security goals.