PCI DSS Penetration Testing.
PCI DSS 4.0 Requirement 11.4 testing. Internal, external, segmentation, application layer. Operator-led. Mapped to PCI evidence requirements.
PCI DSS 4.0 Requirement 11.4 testing. Internal, external, segmentation, application layer. Operator-led. Mapped to PCI evidence requirements.
File · What PCI
PCI DSS 4.0 Requirement 11.4 mandates penetration testing of the cardholder data environment at least annually and after any significant change. The standard explicitly requires application-layer testing, network-layer testing, segmentation control testing, and remediation verification.
Operator Note
Proving an out-of-scope network cannot reach the CDE means actually trying to cross that boundary: an operator improvising against the real firewall and routing posture, not a port sweep against the documented one. A QSA who knows Requirement 11.4 can tell which one you bought.
“Segmentation that passed a scanner has been broken in front of me by an operator with five minutes and a working knowledge of the network. PCI 11.4 exists because of exactly that gap.”
File · Scope coverage
File · FAQ
Q1 Does Alacrinet meet PCI DSS 11.4 evidence requirements?
Yes. The technical report includes scope, methodology, tester qualifications, findings with remediation, and retest evidence.
Q2 Are your testers PCI QSA?
We are not a QSA firm; we are the pentest vendor that QSAs and ROC writers point clients at for the 11.4 evidence.
Q3 How long does a PCI pentest take?
Typical engagements run three to five weeks depending on CDE size and segmentation complexity.
Talk to an Operator
Real operators. Real attack paths. Real business impact. Talk to us about your security goals.
Related
The cardholder-data surfaces a QSA examines, and the sectors that live under PCI.
Where PCI DSS 11.4 fits alongside SOC 2, HIPAA, CMMC, and ISO.
Perimeter testing for the cardholder data environment.
Checkout and payment-page application-layer testing.
Payment and back-office API testing for Requirement 11.4.x.
Where card data and revenue actually live.
Payment processors and fintech under PCI scope.