Compliance / PCI DSS

PCI DSS and the penetration test

Requirednamed in the standard as a mandatory control

PCI DSS names the penetration test outright. Requirement 11.4 sets the methodology, the scope, and the cadence: internal and external, network and application layer, every 12 months and after any significant change.

PCI DSS, in one panel

Standard
PCI DSS v4.0.1 (Payment Card Industry Data Security Standard, June 2024)
Pentest status
Required · named in the standard as a mandatory control
Where it lives
Requirement 11.4.1 through 11.4.7
Frequency
Every 12 months and after significant change (segmentation every 6 for service providers)
Scope
The full cardholder data environment and anything that could impact it: external and internal, network layer and application layer, plus validation of any segmentation controls.
What the assessor wants
A methodology-conformant report proving perimeter, application and network coverage, tester independence, correct scope mapping, findings with remediation, retest evidence for 11.4.4, and segmentation results at the right cadence.

What PCI DSS is

PCI DSS is the security standard for any organization that stores, processes or transmits payment card data. It is enforced by the payment brands and your acquiring bank, not by a government, and it is prescriptive where most frameworks are principles-based.

The current version is v4.0.1, published in June 2024. Every future-dated v4 requirement became mandatory on 31 March 2025, so as of 2026 there is no grace period left.

Where the pentest fits

Requirement 11.4 names penetration testing directly and breaks it into parts. 11.4.1 mandates a documented methodology based on an industry-accepted approach such as NIST SP 800-115, covering the whole cardholder data environment, application layer and network layer.

11.4.2 and 11.4.3 require internal and external testing at least every 12 months and after any significant change. 11.4.4 requires exploitable findings to be corrected and retested. 11.4.5 and 11.4.6 require segmentation controls to be tested, every 12 months, or every 6 months for service providers.

How an AI-native pentest meets it

PCI rewards testing after every significant change, not just once a year. Uvy runs the network and application-layer test on each change and produces methodology-aligned, retested, audit-ready evidence.

Verified findings with proof of exploit are exactly the artifact a QSA reads 11.4.4 closure against.

To be precise

A QSA assesses against the 11.4.1 methodology and needs a qualified, independent test. Uvy makes that test continuous and audit-ready; the assessed-methodology bar stays in place.

What a seasoned assessor knows

Requirement 11.4 is a penetration test, not a scan. It demands the manual exploitation, application-layer testing, and segmentation validation that a quarterly ASV scan, Requirement 11.3, never performs. Uvy delivers the 11.4 test and retests it after every significant change.

Find every way in, before an attacker does

Uvy runs continuous offense and defense across your applications, agents, and embodied AI, at machine speed, and hands your team proof and the exact fix. Start with an application pentest, or talk to sales to cover the rest.

Free to test. No card to start.

Or write to [email protected]