Requirement 11.4 asks for internal and external penetration testing at least annually and after every significant change, with exploitable findings corrected and retested. PentestMe covers that testing continuously, so “after every significant change” stops being a scheduling problem.
Priced in Rand, reports dated and evidence-backed for assessor review.
PCI DSS contains two separate testing obligations, and providers are not always clear about which one they satisfy.
Most entities in scope need both. Anyone telling you a single subscription covers all of PCI Requirement 11 is either confused or hoping you are.
Four obligations, all of which produce evidence an assessor will ask to see.
From outside the network perimeter, against the systems exposed to the internet that form or protect the cardholder data environment. Also required after any significant infrastructure or application change.
From inside the network, on the same annual cadence and the same significant-change trigger. Internal testing is the one most often skipped, and the one a QSA most often asks to see.
If you use segmentation to reduce PCI scope, the controls that enforce it must be tested: at least annually for most entities, and at least every six months for service providers.
It is not enough to find and fix. The remediation has to be verified by repeating the test, and the retest evidence forms part of the assessment record.
The annual test is the part everyone budgets for. The significant-change trigger is the part that quietly puts organisations out of compliance between assessments: a new payment flow, a re-architected checkout, a migration, a new third-party integration touching the cardholder data environment. Each is a change that requires testing, and each tends to ship long before the next scheduled engagement.
Continuous testing changes the shape of that problem. When a test costs a subscription rather than a new statement of work, running one after a significant change is a decision nobody has to justify.
How continuous testing worksFindings are mapped to PCI DSS, ISO 27001 and SOC 2, and stand as evidence toward POPIA, so one engagement produces evidence for several obligations at once.
Yes. Requirement 11.4 requires internal and external penetration testing at least annually and after significant changes, following a defined, industry-accepted methodology. This is separate from the vulnerability scanning obligations in Requirement 11.3.
An ASV scan is a quarterly external vulnerability scan that must be performed by a PCI-Approved Scanning Vendor and submitted in a prescribed format. A penetration test is a deeper, methodology-driven assessment that validates whether weaknesses are genuinely exploitable. They satisfy different requirements and one cannot substitute for the other.
Unlike ASV scanning, PCI DSS does not restrict penetration testing to an approved vendor list. The tester must be organisationally independent of the systems under test and appropriately qualified, and the methodology must be documented. Our team holds OSCP and CEH certifications.
At least annually for internal and external testing, plus after any significant change. Segmentation controls are tested at least annually, or every six months if you are a service provider. In practice "significant change" happens far more often than once a year, which is why continuous testing tends to fit the requirement better than a single scheduled engagement.
Reports are dated, evidence-backed, and record what was tested as well as what was found, which is what an assessor asks for. We cannot promise a specific QSA outcome, and no honest provider can. Share a sample report with your assessor before you commit if PCI is your primary driver.
Run a real, validated pentest and judge the report against what your assessor asks for. No credit card.
Start your free pentest