Skip to content
Raxis X Logo
  • Home
  • Services
      Core Services
      Penetration
      Testing
      Pentest
      As A Service
      Red Team Icon
      Adversary
      Simulation
      Cybersecurity Services Icon
      Cybersecurity
      Services
      Pentest Specialties
    • Web Application Penetration Testing
    • API Security
    • Salesforce Applications
    • Internal Networks, Cloud, and VPC
    • External Networks and Internet
    • Wireless Networks
    • Mobile Applications
    • Phishing & Vishing Testing
    • Physical Penetration Testing
    • IoT Penetration Testing Services
    • OT Penetration Testing Services
    • AI & LLM Penetration Testing Services
    • Cybersecurity Services
    • Breach and Attack Simulation
    • Attack Surface Management
    • Cybersecurity Code Review
  • Industries
      Critical Infrastructure
    • Energy
    • Communications
    • Transportation
    • Water
    • Compliance Driven
    • Finance and Banking
    • GLBA Safeguards Rule
    • Healthcare
    • HIPAA
    • ISO 27001
    • PCI DSS / Credit Cards
    • SOC 2
    • Blockchain and Cryptocurrency
    • Education
    • Government Agencies
    • Manufacturing
    • Media and Entertainment
    • Technology and Software Development
    • Social Media
  • Resources
      Company Information
    • About Raxis
    • Become a Raxis Partner
    • Careers
    • Certifications
    • Meet Our Team
    • Trust Center
    • Security Research
    • Resources
    • Raxis One
    • AI vs. Human Penetration Testing
    • Penetration Test Glossary
    • Red, Blue, and Purple Teams
    • Transporter Remote Pentesting
    • What is a Penetration Test?
    • The Exploit Blog
    • About These “Top 10 Pentesting Companies” Listicles
    • Signup for Raxis Newsletter
  • About Us
Contact Raxis Login
Raxis X Logo
Contact
  • Home
  • Services
      Core Services
      Penetration
      Testing
      Pentest
      As A Service
      Red Team Icon
      Adversary
      Simulation
      Cybersecurity Services Icon
      Cybersecurity
      Services
      Pentest Specialties
    • Web Application Penetration Testing
    • API Security
    • Salesforce Applications
    • Internal Networks, Cloud, and VPC
    • External Networks and Internet
    • Wireless Networks
    • Mobile Applications
    • Phishing & Vishing Testing
    • Physical Penetration Testing
    • IoT Penetration Testing Services
    • OT Penetration Testing Services
    • AI & LLM Penetration Testing Services
    • Cybersecurity Services
    • Breach and Attack Simulation
    • Attack Surface Management
    • Cybersecurity Code Review
  • Industries
      Critical Infrastructure
    • Energy
    • Communications
    • Transportation
    • Water
    • Compliance Driven
    • Finance and Banking
    • GLBA Safeguards Rule
    • Healthcare
    • HIPAA
    • ISO 27001
    • PCI DSS / Credit Cards
    • SOC 2
    • Blockchain and Cryptocurrency
    • Education
    • Government Agencies
    • Manufacturing
    • Media and Entertainment
    • Technology and Software Development
    • Social Media
  • Resources
      Company Information
    • About Raxis
    • Become a Raxis Partner
    • Careers
    • Certifications
    • Meet Our Team
    • Trust Center
    • Security Research
    • Resources
    • Raxis One
    • AI vs. Human Penetration Testing
    • Penetration Test Glossary
    • Red, Blue, and Purple Teams
    • Transporter Remote Pentesting
    • What is a Penetration Test?
    • The Exploit Blog
    • About These “Top 10 Pentesting Companies” Listicles
    • Signup for Raxis Newsletter
  • About Us

PCI Penetration Testing

We show your QSA exactly where the CDE breaks under a real attack, then prove the fix holds.

Request a Quote
Schedule a 30 Minute Walkthrough
Top Clutch Penetration Testing 2026

PCI Pentests That Prove Your CDE Holds, Not Just That It Exists on a Diagram

Raxis tests your CDE, payment apps, APIs, and segmentation the way an attacker would. Then we hand your QSA the proof PCI DSS v4.0.1 requires.

Verify us the way you’d verify a finding. Our published CVEs, certifications, and security posture are all public in the Raxis Trust Center.

Request A Quote Schedule Call

CDE & Segmentation Validation

Real lateral movement from out-of-scope networks toward the CDE. We prove your segmentation works, not that it looks right on a network map.

Built Around Requirement 11.4

Documented methodology, exploitation evidence, prioritized remediation, and retesting your security team and QSA can stand behind.

Payment App, API & E-Commerce Testing

Hands-on testing of gateways, tokenization, carts, and integrations. The systems that move card data, not just the network perimeter.

PCI DSS v4.0.1 Requirement 11.4

PCI DSS v4.0.1 Requirement 11.4 calls for a defined penetration testing methodology and regular internal and external testing, with exploitable vulnerabilities corrected and retested. Where you use segmentation to reduce scope, those controls have to be tested to confirm out-of-scope systems stay isolated from the cardholder data environment.

Our testing methodology is built on industry standards your QSA already knows: NIST SP 800-115 for technical assessment structure, PTES for engagement phases, and the OWASP Testing Guide and API Security Top 10 for application and API work. That is what 11.4.1 means by a defined, documented, and implemented methodology, and it is written into every Raxis report.

PCI area

Description

How Raxis supports it

11.4.1

Maintain a penetration testing methodology

Documented rules of engagement, scope, approach, tools, exclusions, and evidence, aligned with the standards above.

11.4.2

Internal penetration testing

Manual exploitation across in-scope internal CDE networks and systems.

11.4.3

External penetration testing

Internet-facing testing against CDE-connected assets, exposed services, and attack paths.

11.4.4

Remediation and retesting

Findings include fix guidance, and retesting verifies corrective actions.

11.4.5

Segmentation testing where segmentation is used to reduce scope

Attempts to bypass segmentation and validate CDE isolation from out-of-scope networks.

11.4.6

Service provider segmentation testing every six months

Six-month segmentation testing for service providers, validating CDE isolation.

11.4.7

Multi-tenant service provider support for customer external testing

Support for customer external penetration testing under 11.4.3 and 11.4.4.

Who Can Perform a PCI Penetration Test?

If you have to get a penetration test, get one that will actually improve security across the organization. Raxis engineers have uncovered 12 published CVEs to date.

Qualified Means Credentials Your QSA Recognizes

Qualified means demonstrable penetration testing experience and credentials your QSA will recognize. Raxis testers hold certifications including OSCP, OSWE, OSCE, OSEP, GPEN, and CISSP, and every PCI engagement is led by a senior U.S.-based tester. See our team certifications for the full list.

Organizational Independence Required

Independence is where internal teams usually fall short. Even a capable in-house security team often manages or influences the controls under test, which a QSA can flag. A third-party test removes the question entirely and gives your QSA evidence with no asterisk on it.

No QSA or ASV Required

PCI DSS does not require your penetration test to come from a QSA or an ASV. Those designations apply to assessors and scanning vendors, not pen testers. What Requirement 11.4 does require is that the tester be qualified and organizationally independent from the team that manages the systems being tested. Your network admin cannot pentest their own firewall rules.

Requirement 11.4 Does Not Stand Alone

We test with the full picture in mind so your evidence lines up.

11.3 — Vulnerability Scanning

Quarterly internal and external scans (11.3.1 and 11.3.2) sit alongside pen testing. We validate which scan findings an attacker can actually exploit, so you fix what matters first.

11.6 — Payment Page Change Detection

PCI v4.0.1 targets e-skimming and Magecart-style attacks on payment pages. We test the client-side scripts, redirects, and third-party JavaScript that put cardholder data at risk in the browser.

6.4 — Application-Layer Testing

Public-facing apps and APIs in the payment path must be evaluated annually and after significant change. Our web app and API testing surfaces the logic flaws and authorization gaps scanners walk past.

How Often PCI Pen Testing Is Required

The cadence trips up more teams than any other part of 11.4. Here is the short version.

Merchants

Internal and external penetration testing at least annually, plus after any significant change to the environment. Segmentation testing at least annually where segmentation reduces scope.

Service Providers

Same annual internal and external testing, but segmentation testing every six months and after any change to segmentation controls.

Significant Changes Reset the Clock

New infrastructure, a major app release, network re-architecture, or moving the CDE all trigger a fresh test regardless of when the last one ran.

PCI DSS expects you to keep pen test results and remediation records for at least 12 months. Every Raxis engagement lives in Raxis One, so your history and retest evidence stay in one place when the QSA asks.

Which SAQ Types Require a Penetration Test?

Not every merchant needs a full penetration test. Your SAQ type, set by how you handle card data, determines what Requirement 11.4 asks of you. Here is the v4.0.1 breakdown.

SAQ Type

Who Uses It

Pentesting Required

SAQ A

E-commerce fully outsourced to a validated third party; no card data touches your systems

None. But 11.6.1 payment page monitoring and 6.4.3 script controls now apply

SAQ A-EP

E-commerce sites that don’t store card data but affect transaction security

External pen test (11.4.3), plus segmentation testing (11.4.5) where segmentation is used

SAQ B / B-IP

Imprint machines or standalone dial-out / IP-connected terminals

No internal or external pen test. B-IP: segmentation testing (11.4.5) where segmentation reduces scope

SAQ C

POS or payment application systems connected to the internet; no electronic storage

No internal or external pen test. Segmentation testing (11.4.5) where segmentation reduces scope

SAQ C-VT

Web-based virtual terminals, one transaction at a time

None

SAQ P2PE

Validated point-to-point encryption solution only

None

SAQ D (Merchant)

Everyone else, including anyone storing cardholder data electronically

Full 11.4: internal (11.4.2), external (11.4.3), remediation retesting (11.4.4), annual segmentation testing (11.4.5)

SAQ D (Service Provider)

Service providers eligible for self-assessment

Full 11.4, with segmentation testing every six months (11.4.6) and multi-tenant support obligations (11.4.7)

ROC (Level 1)

Merchants over 6M transactions/year and service providers assessed by a QSA

Full 11.4, same as SAQ D for your entity type

Your acquirer and QSA make the final scoping call, and card brands can require a higher validation level regardless of transaction count. If you are not sure which SAQ applies, that is a five-minute conversation. Schedule a call.

The Problem with Most PCI Pentests

Most PCI pentests stop at automated output and never answer the question that matters: could an attacker reach cardholder data? We test the paths attackers actually use. App flaws, API weaknesses, identity issues, misconfigurations, segmentation gaps, and lateral movement.

Scanner Output Dressed Up as a Pentest

Scans are useful. They are not manual exploitation, business logic testing, or attack-path validation, and a QSA can tell the difference.

Segmentation That Only Works on Paper

If segmentation reduces your scope, it has to hold under attack. We run real paths from out-of-scope networks toward the CDE and document what gets through.

Payment Flows Nobody Tested

Gateways, tokenization, carts, client-side JavaScript, APIs, redirects, and third-party integrations all shape PCI risk. We test the whole flow.

Remediation Without Proof

A ticket marked “fixed” does not prove the risk is gone. We retest corrective actions and document what changed.

Request A Quote Schedule Call

What We Find in Cardholder Data Environments

These are the findings that show up across real PCI engagements. Most started as something a scan flagged and nobody validated.

Segmentation Gaps

Firewall, ACL, VLAN, and routing misconfigurations that let out-of-scope systems talk to the CDE. The exact paths 11.4.5 exists to catch.

Payment API & Gateway Flaws

Broken authentication, IDOR, injection, and weak session handling in the APIs and gateways moving card data.

Privilege Escalation Inside the CDE

Low-privilege accounts climbing to admin through patch gaps, weak RBAC, and configuration flaws once inside the boundary.

Exposed and Insecure Services

Non-essential services running on CDE-connected hosts that hand an attacker a foothold.

Client-Side Skimming Exposure

Third-party scripts and tag managers on payment pages that can be abused to lift card data straight from the browser.

PCI Testing Backed by Raxis Trust

Raxis X icon on report

Raxis PCI penetration testing is performed by U.S.-based offensive security professionals and delivered through secure Raxis One workflows. For details on our SOC 2 Type II status, data handling, insurance, internal controls, and team credentials, visit the Raxis Trust Center.

Request A Quote Schedule Call

Why Raxis for PCI Penetration Testing

The tester on your scope call is the one breaking into the CDE. And the one retesting your fix.

Human-led exploitation

Senior testers validate attack paths by hand. Several ran retail cybersecurity before Raxis, so they test the way someone who has defended these systems would attack them.

CDE and segmentation expertise

We test whether your CDE boundary holds under real lateral movement, not whether it passes a config review.

Fortune 500 Experience

We have pulled cardholder data, intercepted live transactions, and gained administrator access at Fortune 500 retailers.

QSA-ready reporting

Every report includes scope, methodology, evidence, impact, remediation, and retest status. Built for a QSA to review and accept.

Secure delivery

Reports and evidence land in Raxis One, with Trust Center documentation for controls, SOC 2 status, insurance, and data handling.

Upgrade to Continuous PTaaS

Raxis Attack PTaaS delivers continuous, AI-augmented PCI testing with real-time results and unlimited retesting, so you are not flying blind for 11 months between engagements.

What a PCI Pentest Costs

PCI pen testing runs from around $8,000 for a tightly scoped CDE up to $100,000 or more for large, multi-segment, multi-app environments. The cheapest quote is rarely the one a QSA respects.

Scope

Live system count, the size of in-scope apps and APIs, and how much sits inside the CDE versus connected to it.

Segmentation Complexity

The number of distinct segmentation methods and out-of-scope zones we test paths from. More boundaries, more validation.

Test Type

Black box, grey box, or white box. Deeper access means deeper coverage and more tester hours.

Add-Ons

Wireless, social engineering, payment app testing, and physical testing layered onto the core PCI scope.

We scope every engagement to your actual environment and give you a fixed quote before anything starts. No surprise change orders mid-test.

Request A Quote Schedule Call

“We’d already spent well into six figures with a well-known firm trying to find how we were losing store credit card data, and they couldn’t. Raxis found it for less than we’d paid them.”

CISO, Retail Chain

FAQ: PCI Penetration Testing

Yes. Requirement 11.4 covers your testing methodology, internal and external testing, remediation validation, and segmentation testing where segmentation reduces PCI scope.

The pentesting requirements moved from 11.3 to 11.4 and became more prescriptive. The methodology must now be defined, documented, and implemented per 11.4.1, including retention of results and remediation records for at least 12 months. Internal vulnerability scans must now be authenticated (11.3.1.2). New requirements 6.4.3 and 11.6.1 target payment page scripts and e-skimming, and 11.4.7 adds obligations for multi-tenant service providers to support customer external testing. If your last pentest report references 11.3, it was written against a retired standard.

Merchants test internally and externally at least annually and after significant changes, with segmentation testing at least annually where used. Service providers test segmentation every six months.

Most PCI engagements run from roughly $8,000 for a tight CDE to $100,000 or more for large, multi-segment environments. Scope, segmentation complexity, test type, and add-ons set your number. We give you a fixed quote before testing starts.

Most PCI penetration tests run one to three weeks of active testing, depending on the size of the CDE, the number of segmentation boundaries, and how many applications and APIs are in scope. A segmentation-only test for a service provider is usually days, not weeks. Plan backwards from your QSA assessment date and leave room for remediation and retesting, which is its own pass.

No. Scanning falls under 11.3 and pen testing under 11.4. Both are required, and they do different jobs. A scan lists what might be wrong. A pentest proves what an attacker can actually do with it.

Yes. When segmentation isolates the CDE, we test whether out-of-scope systems can reach or affect in-scope CDE systems, the way 11.4.5 requires.

Yes. We test payment apps, APIs, e-commerce workflows, authentication, authorization, business logic, and the integrations that shape cardholder data risk.

Yes. Reports include scope, methodology, evidence, findings, severity, remediation guidance, and retest status, so your QSA can see exactly what was tested and validated.

PCI expects results and remediation records held for at least 12 months. Your full history and retest evidence stay in Raxis One for as long as you need them.

No. We work inside strict contractual boundaries with clear rules of engagement. The goal is to expose vulnerabilities without downtime, data loss, or interruption to live transactions.

No. QSA and ASV designations apply to compliance assessors and scanning vendors, not penetration testers. PCI DSS 11.4 requires a qualified tester who is organizationally independent of the systems under test. That can be a third party like Raxis or, in theory, an independent internal team, though in-house teams often fail the independence requirement because they manage the controls being tested. Raxis testers hold OSCP, OSWE, OSCE, OSEP, GPEN, and CISSP certifications.

Let’s Chat About Your Project
Name(Required)
Please let us know what's on your mind. Have a question for us? Ask away.
Popped Culture Newsletter
Would you like to opt in and receive our Popped Culture Newsletter? Typically about once a month, we send out an email with news on the latest in the cybersecurity industry, as well as insights on penetration testing trends.

Our security experts will contact you within 1 business day

Raxis Company Logo
2870 Peachtree Road
Suite #915-8924
Atlanta, GA 30305 USA
+1 678.421.4544
Contact Us Online
  • Facebook
  • X
  • Instagram
  • LinkedIn
  • YouTube
Company Information
  • About Raxis
  • Careers
  • Terms and Conditions
  • Trust Center
  • Privacy Policy
  • Partner Program
  • Sign Up For Our Newsletter
Resources
  • The Exploit Blog
  • Penetration Test Glossary
  • What is a Penetration Test?
Content Update On July 27, 2026 By Mark Puckett – Raxis
©2026 Raxis LLC