Pentesting for PCI DSS
PCI DSS is the payment-card security standard. It applies to any merchant, processor, or service provider that stores, processes, or transmits cardholder data, regardless of size. Requirement 11.4 explicitly demands internal and external penetration testing at least every 12 months and after significant changes. Failure can mean fines, higher fees, corrective action, or losing the right to process cards.
The controls we cover
Requirement summaryA documented methodology covers the CDE perimeter, application and network layers, and internal and external tests run at least every 12 months and after significant changes, with exploitable issues corrected and retested.
AISafe supports discovery, validation, remediation, and retest evidence around the required cadence. The qualified resource who owns the engagement still defines methodology and scope.
Requirement summaryWhen segmentation isolates the cardholder data environment, the segmentation controls must be tested at the required interval and after changes, confirming the CDE is effectively isolated from out-of-scope systems.
AISafe can validate that network and application segmentation actually isolates the CDE, and re-verify after changes.
Requirement summaryInternal and external vulnerability scans run at least quarterly and after significant changes, with external scans by an Approved Scanning Vendor, prioritized remediation, and rescans to confirm fixes.
AISafe complements the required ASV scans with deeper validation; it does not replace the Approved Scanning Vendor or the QSA.
Quick facts
| Applicability | Any merchant, processor, or service provider that stores, processes, or transmits cardholder data, regardless of size. |
| Requirement | Yes. Requirement 11.4 explicitly requires internal and external penetration testing. |
| Cost | Scales with the cardholder data environment; a small merchant’s scope costs far less than a large processor’s, and automation cuts the per-test cost. |
| Cadence | At least every 12 months and after significant changes; quarterly external ASV scans are separate. |
AISafe Labs delivers on-demand, audit-ready evidence for PCI DSS: discovery, recurrent validation, remediation, and retesting , in hours, where other vendors take weeks. Your assessor confirms tester qualification and evidence; AISafe Labs does not replace a QSA or a required ASV scan.
