Skip to content
Raxis Logo
  • Home
  • Services
      Core Services
    • Penetration Testing
    • Penetration Testing as a Service
    • Red Team
    • Pentest Specialties
    • Web Application Penetration Testing
    • API Security
    • Salesforce Applications
    • Internal Networks, Cloud, and VPC
    • External Networks and Internet
    • Wireless Networks
    • Mobile Applications
    • Phishing & Vishing Testing
    • Physical Penetration Testing
    • IoT Penetration Testing Services
    • OT Penetration Testing Services
    • AI & LLM Penetration Testing Services
    • Cybersecurity Services
    • Cybersecurity Services
    • Breach and Attack Simulation
    • Attack Surface Management
    • Cybersecurity Code Review
  • Industries
      Critical Infrastructure
    • Energy
    • Communications
    • Transportation
    • Water
    • Compliance Driven
    • Credit Card Industry (PCI)
    • Healthcare (HIPAA, FDA)
    • SOC 2
    • Education
    • Finance and Banking
    • GLBA Safeguards Rule
    • Government Agencies
    • Manufacturing
    • Technology
    • Technology and Software Development
    • Blockchain and Cryptocurrency
    • Media and Entertainment
    • Social Media
  • Resources
      Company Information
    • About Raxis
    • Become a Raxis Partner
    • Careers
    • Certifications
    • Meet Our Team
    • Trust Center
    • Security Research
    • Resources
    • Raxis One
    • AI vs. Human Penetration Testing
    • Penetration Test Glossary
    • Red, Blue, and Purple Teams
    • Transporter Remote Pentesting
    • What is a Penetration Test?
    • The Exploit Blog
    • Let’s Talk About These “Top 10 Pentesting Companies” Lists
    • Signup for Raxis Newsletter
  • About Us
Contact Raxis Login
Raxis Logo
Contact
  • Home
  • Services
      Core Services
    • Penetration Testing
    • Penetration Testing as a Service
    • Red Team
    • Pentest Specialties
    • Web Application Penetration Testing
    • API Security
    • Salesforce Applications
    • Internal Networks, Cloud, and VPC
    • External Networks and Internet
    • Wireless Networks
    • Mobile Applications
    • Phishing & Vishing Testing
    • Physical Penetration Testing
    • IoT Penetration Testing Services
    • OT Penetration Testing Services
    • AI & LLM Penetration Testing Services
    • Cybersecurity Services
    • Cybersecurity Services
    • Breach and Attack Simulation
    • Attack Surface Management
    • Cybersecurity Code Review
  • Industries
      Critical Infrastructure
    • Energy
    • Communications
    • Transportation
    • Water
    • Compliance Driven
    • Credit Card Industry (PCI)
    • Healthcare (HIPAA, FDA)
    • SOC 2
    • Education
    • Finance and Banking
    • GLBA Safeguards Rule
    • Government Agencies
    • Manufacturing
    • Technology
    • Technology and Software Development
    • Blockchain and Cryptocurrency
    • Media and Entertainment
    • Social Media
  • Resources
      Company Information
    • About Raxis
    • Become a Raxis Partner
    • Careers
    • Certifications
    • Meet Our Team
    • Trust Center
    • Security Research
    • Resources
    • Raxis One
    • AI vs. Human Penetration Testing
    • Penetration Test Glossary
    • Red, Blue, and Purple Teams
    • Transporter Remote Pentesting
    • What is a Penetration Test?
    • The Exploit Blog
    • Let’s Talk About These “Top 10 Pentesting Companies” Lists
    • Signup for Raxis Newsletter
  • About Us

PCI & Credit Cards

We show your QSA exactly where the CDE breaks under a real attack, then prove the fix holds.

Request a Quote
Schedule a 30 Minute Walkthrough

PCI Pentests That Prove Your CDE Holds, Not Just That It Exists on a Diagram

We test your CDE, payment apps, APIs, and segmentation the way an attacker would, then hand your QSA PCI DSS v4.0.1 proof.

Request A Quote Schedule Call

CDE & Segmentation Validation

Real lateral movement from out-of-scope networks toward the CDE. We prove your segmentation works, not that it looks right on a network map.

Built Around Requirement 11.4

Documented methodology, exploitation evidence, prioritized remediation, and retesting your security team and QSA can stand behind.

Payment App, API & E-Commerce Testing

Hands-on testing of gateways, tokenization, carts, and integrations. The systems that move card data, not just the network perimeter.

PCI DSS v4.0.1 Requirement 11.4

PCI DSS v4.0.1 Requirement 11.4 calls for a defined penetration testing methodology and regular internal and external testing, with exploitable vulnerabilities corrected and retested. Where you use segmentation to reduce scope, those controls have to be tested to confirm out-of-scope systems stay isolated from the cardholder data environment.

PCI area

Description

How Raxis supports it

11.4.1

Maintain a penetration testing methodology

Documented rules of engagement, scope, approach, tools, exclusions, and evidence.

11.4.2

Internal penetration testing

Manual exploitation across in-scope internal CDE networks and systems.

11.4.3

External penetration testing

Internet-facing testing against CDE-connected assets, exposed services, and attack paths.

11.4.4

Remediation and retesting

Findings include fix guidance, and retesting verifies corrective actions.

11.4.5

Segmentation testing where segmentation is used to reduce scope

Attempts to bypass segmentation and validate CDE isolation from out-of-scope networks.

11.4.6

Service provider segmentation testing every six months

Six-month segmentation testing for service providers, validating CDE isolation.

11.4.7

Multi-tenant service provider support for customer external testing

Support for customer external penetration testing under 11.4.3 and 11.4.4.

Requirement 11.4 Does Not Stand Alone

Requirement 11.4 covers the penetration testing detailed in the table above. We test with the full picture in mind so your evidence lines up.

Request A Quote Schedule Call

11.3 — Vulnerability Scanning

Quarterly internal and external scans (11.3.1 and 11.3.2) sit alongside pen testing. We validate which scan findings an attacker can actually exploit, so you fix what matters first.

11.6 — Payment Page Change Detection

PCI v4.0.1 targets e-skimming and Magecart-style attacks on payment pages. We test the client-side scripts, redirects, and third-party JavaScript that put cardholder data at risk in the browser.

6.4 — Application-Layer Testing

Public-facing apps and APIs in the payment path must be evaluated annually and after significant change. Our web app and API testing surfaces the logic flaws and authorization gaps scanners walk past.

How Often PCI Pen Testing Is Required

The cadence trips up more teams than any other part of 11.4. Here is the short version.

Merchants

Internal and external penetration testing at least annually, plus after any significant change to the environment. Segmentation testing at least annually where segmentation reduces scope.

Service Providers

Same annual internal and external testing, but segmentation testing every six months and after any change to segmentation controls.

Significant Changes Reset the Clock

New infrastructure, a major app release, network re-architecture, or moving the CDE all trigger a fresh test regardless of when the last one ran.

PCI DSS expects you to keep pen test results and remediation records for at least 12 months. Every Raxis engagement lives in Raxis One, so your history and retest evidence stay in one place when the QSA asks.

The Problem with Most PCI Pentests

Most PCI pentests stop at automated output and never answer the question that matters: could an attacker reach cardholder data? We test the paths attackers actually use. App flaws, API weaknesses, identity issues, misconfigurations, segmentation gaps, and lateral movement.

Scanner Output Dressed Up as a Pentest

Scans are useful. They are not manual exploitation, business logic testing, or attack-path validation, and a QSA can tell the difference.

Segmentation That Only Works on Paper

If segmentation reduces your scope, it has to hold under attack. We run real paths from out-of-scope networks toward the CDE and document what gets through.

Payment Flows Nobody Tested

Gateways, tokenization, carts, client-side JavaScript, APIs, redirects, and third-party integrations all shape PCI risk. We test the whole flow.

Remediation Without Proof

A ticket marked “fixed” does not prove the risk is gone. We retest corrective actions and document what changed.

Request A Quote Schedule Call

What We Find in Cardholder Data Environments

These are the findings that show up across real PCI engagements. Most started as something a scan flagged and nobody validated.

Segmentation Gaps

Firewall, ACL, VLAN, and routing misconfigurations that let out-of-scope systems talk to the CDE. The exact paths 11.4.5 exists to catch.

Payment API & Gateway Flaws

Broken authentication, IDOR, injection, and weak session handling in the APIs and gateways moving card data.

Privilege Escalation Inside the CDE

Low-privilege accounts climbing to admin through patch gaps, weak RBAC, and configuration flaws once inside the boundary.

Exposed and Insecure Services

Non-essential services running on CDE-connected hosts that hand an attacker a foothold.

Client-Side Skimming Exposure

Third-party scripts and tag managers on payment pages that can be abused to lift card data straight from the browser.

PCI Testing Backed by Raxis Trust

Raxis X icon on report

Raxis PCI penetration testing is performed by U.S.-based offensive security professionals and delivered through secure Raxis One workflows. For details on our SOC 2 Type II status, data handling, insurance, internal controls, and team credentials, visit the Raxis Trust Center.

Request A Quote Schedule Call

Why Raxis for PCI Penetration Testing

The tester on your scope call is the one breaking into the CDE. And the one retesting your fix.

Human-led exploitation

Senior testers validate attack paths by hand. Several ran retail cybersecurity before Raxis, so they test the way someone who has defended these systems would attack them.

CDE and segmentation expertise

We test whether your CDE boundary holds under real lateral movement, not whether it passes a config review.

Fortune 500 Experience

We have pulled cardholder data, intercepted live transactions, and gained administrator access at Fortune 500 retailers.

QSA-ready reporting

Every report includes scope, methodology, evidence, impact, remediation, and retest status. Built for a QSA to review and accept.

Secure delivery

Reports and evidence land in Raxis One, with Trust Center documentation for controls, SOC 2 status, insurance, and data handling.

Upgrade to Continuous PTaaS

Raxis Attack PTaaS delivers continuous, AI-augmented PCI testing with real-time results and unlimited retesting, so you are not flying blind for 11 months between engagements.

What a PCI Pentest Costs

PCI pen testing runs from around $8,000 for a tightly scoped CDE up to $40,000 or more for large, multi-segment, multi-app environments. The cheapest quote is rarely the one a QSA respects.

Scope

Live system count, the size of in-scope apps and APIs, and how much sits inside the CDE versus connected to it.

Segmentation Complexity

The number of distinct segmentation methods and out-of-scope zones we test paths from. More boundaries, more validation.

Test Type

Black box, grey box, or white box. Deeper access means deeper coverage and more tester hours.

Add-Ons

Wireless, social engineering, payment app testing, and physical testing layered onto the core PCI scope.

We scope every engagement to your actual environment and give you a fixed quote before anything starts. No surprise change orders mid-test.

Request A Quote Schedule Call

“We’d already spent well into six figures with a well-known firm trying to find how we were losing store credit card data, and they couldn’t. Raxis found it for less than we’d paid them.“

CISO, Retail Chain

FAQ: PCI Penetration Testing

Yes. Requirement 11.4 covers your testing methodology, internal and external testing, remediation validation, and segmentation testing where segmentation reduces PCI scope.

Merchants test internally and externally at least annually and after significant changes, with segmentation testing at least annually where used. Service providers test segmentation every six months.

Most PCI engagements run from roughly $8,000 for a tight CDE to $40,000 or more for large, multi-segment environments. Scope, segmentation complexity, test type, and add-ons set your number. We give you a fixed quote before testing starts.

No. Scanning falls under 11.3 and pen testing under 11.4. Both are required, and they do different jobs. A scan lists what might be wrong. A pentest proves what an attacker can actually do with it.

Yes. When segmentation isolates the CDE, we test whether out-of-scope systems can reach or affect in-scope CDE systems, the way 11.4.5 requires.

Yes. We test payment apps, APIs, e-commerce workflows, authentication, authorization, business logic, and the integrations that shape cardholder data risk.

Yes. Reports include scope, methodology, evidence, findings, severity, remediation guidance, and retest status, so your QSA can see exactly what was tested and validated.

PCI expects results and remediation records held for at least 12 months. Your full history and retest evidence stay in Raxis One for as long as you need them.

No. We work inside strict contractual boundaries with clear rules of engagement. The goal is to expose vulnerabilities without downtime, data loss, or interruption to live transactions.

Let’s Chat About Your Project
Name(Required)
Please let us know what's on your mind. Have a question for us? Ask away.
Popped Culture Newsletter
Would you like to opt in and receive our Popped Culture Newsletter? Typically about once a month, we send out an email with news on the latest in the cybersecurity industry, as well as insights on penetration testing trends.

Our security experts will contact you within 1 business day

Raxis Company Logo
2870 Peachtree Road
Suite #915-8924
Atlanta, GA 30305 USA
+1 678.421.4544
Contact Us Online
  • Facebook
  • X
  • Instagram
  • LinkedIn
  • YouTube
Company Information
  • About Raxis
  • Careers
  • Terms and Conditions
  • Trust Center
  • Privacy Policy
  • Penetration Testing Partner Program
Resources
  • The Exploit Blog
  • Transporter Remote Penetration Testing
  • Penetration Test Glossary
  • What is a Penetration Test?
Penetration Tests
  • Cybersecurity Red Teaming
  • External / Internet
  • Cloud / Internal Systems
  • Web Application
  • Wireless
  • Mobile Applications
  • API Services
  • Salesforce Applications
  • Physical Penetration Testing
Content Update On June 18, 2026 By Mark Puckett – Raxis
©2026 Raxis LLC