Compliance · PCI DSS compliance

Penetration testing and segmentation testing for PCI DSS

PCI DSS v4 requires annual and post-change penetration testing of the cardholder data environment, plus segmentation validation. We run both and package the evidence for your QSA.

Scope

What we cover

Requirement 11.4

Internal and external penetration testing of the CDE using an industry-accepted methodology.

Segmentation testing

Validation that out-of-scope networks cannot reach the CDE, run at the frequency your merchant level requires.

Application testing

Requirement 6 coverage for public-facing payment applications and APIs.

ASV coordination

Quarterly external scans coordinated with an Approved Scanning Vendor and remediation support.

How it works

From scoping call to closed findings

01

Define

Confirm CDE boundaries, connected systems and segmentation controls with your compliance lead.

02

Test

Internal and external testing plus segmentation checks, with findings visible as they are confirmed.

03

Remediate

Fix guidance per finding and retesting until the CDE is clean.

04

Evidence

Report and attestation formatted to what QSAs expect, ready for your ROC or SAQ.

Deliverables

What you receive

  • PCI DSS penetration test report mapped to 11.4
  • Segmentation test report
  • Attestation letter for your QSA
  • Retest confirmation of closed findings
FAQ

Common questions about pci dss compliance

Requirement 11.4 (penetration testing and segmentation testing) and the testing parts of requirement 6 for public-facing applications. ASV scanning under 11.3.2 is coordinated separately.

Book a scoping call

Scope your pci dss compliance engagement

A 30-minute call with a SecureBlock lead to align on objectives, assets and timeline. We follow up with a written scope and fixed-fee proposal within two business days.

Prefer email? sales@secureblock.io

No commitment. We reply within one business day.