Services / PCI DSS Penetration Testing Requirements, Explained
Compliance

PCI DSS Penetration Testing Requirements, Explained

If credit card data touches your environment in any form, PCI DSS almost certainly applies to you — here's what the testing requirement actually asks for, in plain language.

Key Takeaways
  • Requirement 11.3 requires both internal and external penetration testing, at minimum annually.
  • Testing is required again after any significant infrastructure or application change.
  • An automated scan does not satisfy this requirement — active exploitation by a qualified tester is required.
  • Compliance-ready reports document methodology and remediation, not just a raw findings list.

What Requirement 11.3 Covers

PCI DSS requirement 11.3 requires both internal and external penetration testing, conducted at least annually and after any significant change to your environment. This isn't a one-time checkbox — it's an ongoing obligation tied to how your infrastructure actually evolves.

If your business relies on network segmentation to reduce the scope of systems subject to PCI DSS, segmentation testing is also required to confirm that segmentation is actually working as intended, not just configured correctly on paper.

  • Both internal and external penetration testing, at least annually
  • Testing after any significant infrastructure or application change
  • Segmentation testing if you rely on network segmentation to reduce PCI scope
  • Testing that addresses threats specific to your industry, not a generic scan

What Makes a Report Compliance-Ready

Auditors and assessors want a report that documents methodology, scope, findings, and remediation steps — not just a raw list of vulnerabilities pulled from a scanning tool. The report needs to demonstrate that testing was actually performed by a qualified person using a defensible methodology, not just that a tool was run.

We structure our reporting with that documentation requirement in mind from the start of scoping, rather than trying to retrofit a standard report into compliance format after the fact.

How This Differs From Vulnerability Scanning

PCI DSS treats vulnerability scanning and penetration testing as two separate, distinct requirements — not interchangeable options. Scanning is typically required quarterly and can be largely automated; penetration testing requires active, hands-on exploitation attempts by a qualified tester and happens less frequently but goes considerably deeper.

Questions
Does an automated scan satisfy this requirement?

No. PCI DSS 11.3 specifically requires penetration testing, which involves active exploitation attempts by a qualified tester — not just automated vulnerability scanning, which is a separate, additional requirement under a different section.

How often does this testing need to happen?

At minimum annually, and after any significant change to your environment that could affect security, such as a new application, a major infrastructure change, or a network redesign.

Who counts as a "qualified" tester for PCI DSS purposes?

The standard doesn't mandate a specific certification, but assessors generally expect demonstrated expertise and a defensible methodology — documentation of the tester's approach matters as much as any individual credential.

Related Reading

Have a Question We Didn’t Cover?

Email Our Team