PCI DSS 4.0:
the testing required by 11.3 and 11.4
A guide for merchants, processors and service providers: what gets scanned, what gets tested by hand, how often, and what evidence the assessor asks for.
PCI DSS is the only framework in this series that says "penetration test" explicitly and fixes its frequency. Version 4.0 did not change the principle, but it tightened the screws: several requirements became mandatory after 31 March 2025, and segmentation testing took a central role. This guide separates what must be scanned automatically from what must be tested by a human.
What is in scope: the CDE and everything touching it
Scope is not "the payment server". It is the cardholder data environment (CDE) plus any system that can connect to it or affect its security: administration workstations, authentication systems, monitoring solutions, connected service providers. A system excluded from scope must also be excluded technically — and that is proven through segmentation testing.
Requirement 11.3 — vulnerability scanning
Requirement 11.3 mandates internal and external scans at least quarterly and after any significant change. External scans must be performed by an ASV (Approved Scanning Vendor) authorised by the PCI SSC. Internal scans may be done in house, but by staff independent of the system administrators. In both cases a "passing" result means zero high-severity vulnerabilities — not "we logged them all".
Requirement 11.4 — penetration testing
Here the standard becomes unusually specific. It requires a documented methodology, external and internal testing at least annually and after significant infrastructure or application changes, coverage of the entire CDE perimeter and of both the network and application layers, and correction of exploitable vulnerabilities followed by re-testing.
For service providers, requirement 11.4.6 raises the bar to segmentation testing every six months rather than annually. And 11.4.7 adds tenant isolation testing for multi-tenant providers — a requirement that catches up with exactly how payment SaaS platforms operate.
Who tests what, and how often
| Requirement | What is tested | Minimum frequency |
|---|---|---|
| 11.3.1 | Internal vulnerability scanning | Quarterly + after changes |
| 11.3.2 | External scanning by an approved ASV | Quarterly + after changes |
| 11.4.2 | Internal penetration test (network + application) | Annually + after major changes |
| 11.4.3 | External penetration test | Annually + after major changes |
| 11.4.5 | Segmentation testing (all entities) | Annually |
| 11.4.6 | Segmentation testing — service providers | Every 6 months |
| 11.4.7 | Tenant isolation (multi-tenant) | Per the applicable segmentation requirement |
What the QSA expects from the report
- A stated, industry-accepted methodology (PTES, OWASP, NIST SP 800-115).
- Scope justification: why these systems and not others, referencing the cardholder data flow diagram.
- Proof the testing covered both the network layer and the application layer.
- For segmentation: which controls were probed from outside the CDE and the result of each attempt.
- A documented re-test for every exploitable vulnerability, with date and final state.
- Tester independence from the team administering the tested systems.
Frequently asked questions
Does PCI DSS mandate a penetration test?
Yes. Unlike ISO 27001 or the GDPR, PCI DSS explicitly requires internal and external penetration tests, at least annually and after any significant infrastructure or application change. Requirement 11.4 also fixes the minimum content: a documented methodology, coverage of the whole CDE scope, both layers (network and application) and re-testing of exploitable vulnerabilities.
What is the difference between ASV scanning and a penetration test?
ASV scanning is automated, quarterly, run from the outside by a PCI SSC approved vendor, and answers requirement 11.3.2. A penetration test is manual, annual, and answers 11.4. One finds known vulnerabilities on exposed services; the other tries to exploit them, chain them and actually reach cardholder data. They do not replace each other — the standard requires both.
What is segmentation testing and why does it matter so much?
Segmentation testing practically verifies whether networks declared out of scope truly cannot reach the cardholder data environment. It matters because segmentation is the mechanism that reduces scope: if it does not hold, every system that can reach the CDE enters scope and brings all PCI DSS requirements with it. Service providers test every six months; other entities test annually.
What changed moving from 3.2.1 to 4.0?
The testing requirements were renumbered (11.3 becomes scanning, 11.4 becomes pentesting), new requirements appeared for multi-tenant isolation and multi-factor authentication, and a set of requirements treated as "best practice" became mandatory after 31 March 2025. The customised approach also arrived, allowing a requirement objective to be met through alternative controls — at the cost of significantly heavier documentation and validation.
Does PCI DSS apply to a company in Moldova?
PCI DSS is not law but a contractual requirement imposed by the card schemes through banks and processors. It applies to any entity that stores, processes or transmits cardholder data, regardless of country. For companies in Moldova the requirement usually arrives through the acquiring bank or the partner processor, and the validation level depends on annual transaction volume.
Related guides
- What a pentest costs — what drives the price, how effort is estimated, and what makes two quotes comparable.
- DORA & TLPT — digital operational resilience in finance and threat-led penetration testing.
- ISO 27001 & SOC 2 — which controls require technical testing and what evidence the auditor accepts.
- Moldova’s Law 48/2023 — the national cybersecurity framework: who is in scope and what obligations it brings.
- OWASP Top 10 — the ten web risk categories, explained with examples and what gets tested in each.
- Pentest vs vulnerability scanning — what each one finds, what it misses, and what auditors accept as evidence.
- How to prepare for a pentest — scope, access, rules of engagement and everything settled before day one.
This material is informational and does not replace a QSA assessment. Exact requirements and validation level depend on entity type and transaction volume.
Do you have a PCI DSS deadline this year?
Book a free consultation and get a testing plan for your CDE scope, with segmentation testing and re-test included.