PCI Penetration Testing
We show your QSA exactly where the CDE breaks under a real attack, then prove the fix holds.
PCI Pentests That Prove Your CDE Holds, Not Just That It Exists on a Diagram
Raxis tests your CDE, payment apps, APIs, and segmentation the way an attacker would. Then we hand your QSA the proof PCI DSS v4.0.1 requires.
Verify us the way you’d verify a finding. Our published CVEs, certifications, and security posture are all public in the Raxis Trust Center.
PCI DSS v4.0.1 Requirement 11.4
PCI DSS v4.0.1 Requirement 11.4 calls for a defined penetration testing methodology and regular internal and external testing, with exploitable vulnerabilities corrected and retested. Where you use segmentation to reduce scope, those controls have to be tested to confirm out-of-scope systems stay isolated from the cardholder data environment.
Our testing methodology is built on industry standards your QSA already knows: NIST SP 800-115 for technical assessment structure, PTES for engagement phases, and the OWASP Testing Guide and API Security Top 10 for application and API work. That is what 11.4.1 means by a defined, documented, and implemented methodology, and it is written into every Raxis report.
|
PCI area |
Description |
How Raxis supports it |
|
11.4.1 |
Maintain a penetration testing methodology |
Documented rules of engagement, scope, approach, tools, exclusions, and evidence, aligned with the standards above. |
|
11.4.2 |
Internal penetration testing |
Manual exploitation across in-scope internal CDE networks and systems. |
|
11.4.3 |
External penetration testing |
Internet-facing testing against CDE-connected assets, exposed services, and attack paths. |
|
11.4.4 |
Remediation and retesting |
Findings include fix guidance, and retesting verifies corrective actions. |
|
11.4.5 |
Segmentation testing where segmentation is used to reduce scope |
Attempts to bypass segmentation and validate CDE isolation from out-of-scope networks. |
|
11.4.6 |
Service provider segmentation testing every six months |
Six-month segmentation testing for service providers, validating CDE isolation. |
|
11.4.7 |
Multi-tenant service provider support for customer external testing |
Support for customer external penetration testing under 11.4.3 and 11.4.4. |
Who Can Perform a PCI Penetration Test?
If you have to get a penetration test, get one that will actually improve security across the organization. Raxis engineers have uncovered 12 published CVEs to date.
Requirement 11.4 Does Not Stand Alone
We test with the full picture in mind so your evidence lines up.
How Often PCI Pen Testing Is Required
The cadence trips up more teams than any other part of 11.4. Here is the short version.
PCI DSS expects you to keep pen test results and remediation records for at least 12 months. Every Raxis engagement lives in Raxis One, so your history and retest evidence stay in one place when the QSA asks.
Which SAQ Types Require a Penetration Test?
Not every merchant needs a full penetration test. Your SAQ type, set by how you handle card data, determines what Requirement 11.4 asks of you. Here is the v4.0.1 breakdown.
|
SAQ Type |
Who Uses It |
Pentesting Required |
|
SAQ A |
E-commerce fully outsourced to a validated third party; no card data touches your systems |
None. But 11.6.1 payment page monitoring and 6.4.3 script controls now apply |
|
SAQ A-EP |
E-commerce sites that don’t store card data but affect transaction security |
External pen test (11.4.3), plus segmentation testing (11.4.5) where segmentation is used |
|
SAQ B / B-IP |
Imprint machines or standalone dial-out / IP-connected terminals |
No internal or external pen test. B-IP: segmentation testing (11.4.5) where segmentation reduces scope |
|
SAQ C |
POS or payment application systems connected to the internet; no electronic storage |
No internal or external pen test. Segmentation testing (11.4.5) where segmentation reduces scope |
|
SAQ C-VT |
Web-based virtual terminals, one transaction at a time |
None |
|
SAQ P2PE |
Validated point-to-point encryption solution only |
None |
|
SAQ D (Merchant) |
Everyone else, including anyone storing cardholder data electronically |
Full 11.4: internal (11.4.2), external (11.4.3), remediation retesting (11.4.4), annual segmentation testing (11.4.5) |
|
SAQ D (Service Provider) |
Service providers eligible for self-assessment |
Full 11.4, with segmentation testing every six months (11.4.6) and multi-tenant support obligations (11.4.7) |
|
ROC (Level 1) |
Merchants over 6M transactions/year and service providers assessed by a QSA |
Full 11.4, same as SAQ D for your entity type |
Your acquirer and QSA make the final scoping call, and card brands can require a higher validation level regardless of transaction count. If you are not sure which SAQ applies, that is a five-minute conversation. Schedule a call.
The Problem with Most PCI Pentests
Most PCI pentests stop at automated output and never answer the question that matters: could an attacker reach cardholder data? We test the paths attackers actually use. App flaws, API weaknesses, identity issues, misconfigurations, segmentation gaps, and lateral movement.
What We Find in Cardholder Data Environments
These are the findings that show up across real PCI engagements. Most started as something a scan flagged and nobody validated.
Raxis PCI penetration testing is performed by U.S.-based offensive security professionals and delivered through secure Raxis One workflows. For details on our SOC 2 Type II status, data handling, insurance, internal controls, and team credentials, visit the Raxis Trust Center.
Why Raxis for PCI Penetration Testing
The tester on your scope call is the one breaking into the CDE. And the one retesting your fix.
What a PCI Pentest Costs
PCI pen testing runs from around $8,000 for a tightly scoped CDE up to $100,000 or more for large, multi-segment, multi-app environments. The cheapest quote is rarely the one a QSA respects.
We scope every engagement to your actual environment and give you a fixed quote before anything starts. No surprise change orders mid-test.