PCI DSS 4.0

PCI DSS penetration testing requirements, explained (Requirement 11.4)

Of the major frameworks, PCI DSS is the one that names penetration testing outright. Requirement 11.4 sets out the methodology, the frequency, the scope, and the retesting you must do. This guide walks through 11.4 in plain language and shows where continuous testing supports it.

Requirement 11.4

What PCI DSS 4.0 actually asks for

Where Operator Fits

Keep 11.4 true all year, not just once

Requirement 11.4 sets a floor of once a year and after significant change. In a modern environment, significant change happens constantly, and a purely annual test cannot see what shipped last week.

Planck Operator runs continuously, so a significant change is exercised when it lands, and every finding arrives with the reproduction evidence and CVSS rating an assessor expects. The formal annual test is still human led and, where you need it, signed by a certified practitioner.

  • NIST SP 800-115 aligned, the methodology 11.4.1 points to.
  • Remediation and retest built in, matching 11.4.4.
  • Segmentation checks that exercise the boundaries around the cardholder data environment.
  • Human led annual test preserved, with continuous coverage in between.
FAQ

Common questions

Does PCI DSS require a penetration test?

Yes. Requirement 11.4 requires internal and external penetration testing at least once every 12 months and after any significant change, following a defined methodology such as NIST SP 800-115.

Does PCI DSS accept automated or AI penetration testing?

PCI DSS expects a qualified human tester following a documented methodology. Automated and autonomous testing is valuable for continuous coverage and for hardening the surface before the assessment, but the annual 11.4 test is expected to be human led. A certified practitioner can sign the assessment.

What is Requirement 11.4.4?

It requires that exploitable vulnerabilities and security weaknesses found during penetration testing are corrected, and that the testing is repeated to verify the corrections. Retesting is not optional under 11.4.

Get Started

Stay inside Requirement 11.4 every day

Continuous testing after every significant change, with the human led annual assessment auditors expect.