External perimeter
All internet-facing components of the cardholder data environment, at the network and application layers, per 11.4.3.
PCI DSS is the one framework that spells out exactly what a penetration test must include. Requirement 11.4 is prescriptive about methodology, coverage, frequency and segmentation — so this engagement is built directly against it.
Under PCI DSS v4.0, requirement 11.4.1 requires a defined and documented penetration testing methodology. 11.4.2 requires internal testing and 11.4.3 external testing, both at least annually and after any significant change. 11.4.4 requires that exploitable vulnerabilities be corrected and the testing repeated to verify the correction.
11.4.5 is the one that catches organisations out. If you use segmentation to reduce the scope of your cardholder data environment, you must test that the segmentation actually works — at least every six months for service providers, and annually for merchants. A QSA will ask for that evidence specifically, and a general network test does not substitute for it.
Because 11.4.4 requires retesting to verify correction, the free retest included in every engagement is not a nice extra here — it is part of what the requirement asks for.
Coverage
All internet-facing components of the cardholder data environment, at the network and application layers, per 11.4.3.
Testing from inside the network toward the CDE, covering the paths an attacker would take after an initial foothold, per 11.4.2.
Confirming that out-of-scope networks genuinely cannot reach the CDE, tested and reported as its own deliverable, per 11.4.5.
Payment and cardholder-facing applications tested authenticated across roles, including the flows that touch or transmit card data.
FAQ
Annually and after any significant change, for both internal and external testing. Segmentation testing under 11.4.5 is every six months for service providers and annually for merchants.
There is no universal list — your QSA decides. In practice it includes new infrastructure in the CDE, network topology changes, application upgrades that alter data flows, and moving components between environments. Ask your QSA and we will scope to their answer.
No. ASV scanning under requirement 11.3.2 must be performed by a PCI-approved scanning vendor, which is a separate accreditation. Penetration testing under 11.4 has no such requirement, and the two are distinct deliverables.
Yes. Service providers frequently need a six-monthly segmentation test between full annual penetration tests, and we scope that as a standalone engagement.
Next step
Tell us what you have built. You get a reply within one business day, an NDA, and a free 30-minute scoping call with the person who will do the testing.