Industry
SECURITYFRAMEWORKPCI DSS

Pentesting for PCI DSS

PCI DSS is the payment-card security standard. It applies to any merchant, processor, or service provider that stores, processes, or transmits cardholder data, regardless of size. Requirement 11.4 explicitly demands internal and external penetration testing at least every 12 months and after significant changes. Failure can mean fines, higher fees, corrective action, or losing the right to process cards.

The controls we cover

Requirement summary

A documented methodology covers the CDE perimeter, application and network layers, and internal and external tests run at least every 12 months and after significant changes, with exploitable issues corrected and retested.

AISafe supports discovery, validation, remediation, and retest evidence around the required cadence. The qualified resource who owns the engagement still defines methodology and scope.

Requirement summary

When segmentation isolates the cardholder data environment, the segmentation controls must be tested at the required interval and after changes, confirming the CDE is effectively isolated from out-of-scope systems.

AISafe can validate that network and application segmentation actually isolates the CDE, and re-verify after changes.

Requirement summary

Internal and external vulnerability scans run at least quarterly and after significant changes, with external scans by an Approved Scanning Vendor, prioritized remediation, and rescans to confirm fixes.

AISafe complements the required ASV scans with deeper validation; it does not replace the Approved Scanning Vendor or the QSA.

Quick facts

ApplicabilityAny merchant, processor, or service provider that stores, processes, or transmits cardholder data, regardless of size.
RequirementYes. Requirement 11.4 explicitly requires internal and external penetration testing.
CostScales with the cardholder data environment; a small merchant’s scope costs far less than a large processor’s, and automation cuts the per-test cost.
CadenceAt least every 12 months and after significant changes; quarterly external ASV scans are separate.

AISafe Labs delivers on-demand, audit-ready evidence for PCI DSS: discovery, recurrent validation, remediation, and retesting , in hours, where other vendors take weeks. Your assessor confirms tester qualification and evidence; AISafe Labs does not replace a QSA or a required ASV scan.

Related frameworks

Get your Audit Evidence right now

Run a security assessment of your system, or contact us if your compliance programme requires additional support.