Internal and external penetration testing of the CDE using an industry-accepted methodology.
Validation that out-of-scope networks cannot reach the CDE, run at the frequency your merchant level requires.
Requirement 6 coverage for public-facing payment applications and APIs.
Quarterly external scans coordinated with an Approved Scanning Vendor and remediation support.
Confirm CDE boundaries, connected systems and segmentation controls with your compliance lead.
Internal and external testing plus segmentation checks, with findings visible as they are confirmed.
Fix guidance per finding and retesting until the CDE is clean.
Report and attestation formatted to what QSAs expect, ready for your ROC or SAQ.
Requirement 11.4 (penetration testing and segmentation testing) and the testing parts of requirement 6 for public-facing applications. ASV scanning under 11.3.2 is coordinated separately.
A 30-minute call with a SecureBlock lead to align on objectives, assets and timeline. We follow up with a written scope and fixed-fee proposal within two business days.
Prefer email? sales@secureblock.io