11.4 Penetration testing is regularly performed
How to meet it
Perform internal and external penetration tests at least annually and after significant changes.
Defined requirements
The individual PCI DSS v4.0.1 requirements under 11.4, in plain English.
11.4.1A penetration testing methodology is defined and implemented covering the full CDE perimeter, internal and external tests, and segmentation.
11.4.2Internal penetration testing is performed at least every 12 months and after significant changes by a qualified independent tester.
11.4.3External penetration testing is performed at least every 12 months and after significant changes by a qualified independent tester.
11.4.4Exploitable vulnerabilities found in penetration testing are corrected and testing is repeated to verify fixes.
11.4.5Where segmentation isolates the CDE, segmentation controls are penetration-tested at least every 12 months.
11.4.6Service providers penetration-test segmentation controls at least every six months and after changes.
11.4.7Multi-tenant service providers support customers for external penetration testing.
Policy templates for this control
Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.
Network security policyUse for ISO 27001 A.8.20, A.8.21, A.8.22, A.8.23, SOC 2 Security, and PCI DSS requirements 1 and 4.Secure development policyUse for ISO 27001 A.8.25 to A.8.32, source code controls, change management, and SOC 2 change controls.Change management policyUse for ISO 27001 A.8.32, A.8.9, SOC 2 change management criteria, and PCI DSS requirement 6 change controls.Cloud services and outsourcing policyUse for ISO 27001 A.5.19 to A.5.23, SOC 2 vendor management, and oversight of cloud and outsourced service providers.
Open the control-to-policy map← 11.3 Vulnerabilities are regularly identified, prioritised and addressed11.5 Network intrusions and unexpected file changes are detected →
Back to Requirement 11, or see PCI DSS templates. To run PCI controls with automation, read how AI manages controls.