Of the major frameworks, PCI DSS is the one that names penetration testing outright. Requirement 11.4 sets out the methodology, the frequency, the scope, and the retesting you must do. This guide walks through 11.4 in plain language and shows where continuous testing supports it.
Requirement 11.4 sets a floor of once a year and after significant change. In a modern environment, significant change happens constantly, and a purely annual test cannot see what shipped last week.
Planck Operator runs continuously, so a significant change is exercised when it lands, and every finding arrives with the reproduction evidence and CVSS rating an assessor expects. The formal annual test is still human led and, where you need it, signed by a certified practitioner.
Yes. Requirement 11.4 requires internal and external penetration testing at least once every 12 months and after any significant change, following a defined methodology such as NIST SP 800-115.
PCI DSS expects a qualified human tester following a documented methodology. Automated and autonomous testing is valuable for continuous coverage and for hardening the surface before the assessment, but the annual 11.4 test is expected to be human led. A certified practitioner can sign the assessment.
It requires that exploitable vulnerabilities and security weaknesses found during penetration testing are corrected, and that the testing is repeated to verify the corrections. Retesting is not optional under 11.4.
Continuous testing after every significant change, with the human led annual assessment auditors expect.