PCI DSS Penetration Testing

PCI DSS Penetration Testing

PCI DSS penetration testing is one of the few tests genuinely required by a standard: requirements 11.4.1 to 11.4.6 mandate internal, external and segmentation testing on a fixed cadence, and EJN Labs delivers all of them. You get a fixed price, a named UK-based tester, and a report your QSA will accept as evidence. Free retests are included so you can close out 11.4.4.

  • Unlimited retesting
  • Unlimited pre-retesting
  • No hidden fees
Accredited & recognised
Cyber Essentials certified Cyber Essentials Plus certified IASME certifying body ISO 27001 certified ISO 9001 certified Crown Commercial Service supplier UK Cyber Security Council member
11.4
The PCI DSS requirement that makes penetration testing mandatory
12 months
Maximum interval between tests (Req 11.4.2 / 11.4.3)
6 months
Segmentation testing for service providers (Req 11.4.6)
Free
Retests to verify your fixes (Req 11.4.4)
CLIENT REFERENCE
“I would highly recommend EJN Labs to any organisation seeking reliable, detailed, and well-managed penetration testing services, particularly for government or enterprise-level projects.”
SquareOneImran SaghirProject Lead, SquareOne
CLIENT REFERENCE
“There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.”
CelloriDan WilcocksonCo-Founder, Cellori
WHY IT MATTERS
2

separate PCI DSS testing duties: vulnerability scanning under 11.3 and penetration testing under 11.4

Passing your scans is not passing PCI DSS

An ASV scan meets Requirement 11.3.2. It does nothing for Requirement 11.4. Automated scanning is broad and shallow by design: it flags known signatures, but it does not chain weaknesses, bypass controls, or prove what an attacker could actually reach inside your cardholder data environment.

Requirement 11.4 asks for a manual, goal-driven penetration test that a scanner cannot replace. That is where business-logic flaws, access-control gaps, and exploitable paths into the CDE are found. It is also what your QSA expects to see, mapped to the sub-requirements, before they sign.

We scope every engagement against 11.4 directly, so the deliverable lines up with the evidence your assessor checks. Findings are triaged by exploitability, remediation is practical, and the retest to satisfy 11.4.4 is included rather than billed again.

In practice, two gaps come up repeatedly in the PCI engagements our CREST-certified consultants run. The first is segmentation controls between the cardholder data environment and the wider corporate network that have never been penetration tested. The second is an ASV scan being treated as the penetration test itself. Our methodology follows industry-accepted guidance including NIST SP 800-115 and the PCI SSC Penetration Testing Guidance, so the report ties each part of the engagement back to the sub-requirement your assessor checks.

PCI DSS REQUIREMENT 11.4

What a PCI DSS Penetration Test Covers

Requirement 11.4 is specific about scope, cadence and independence. Here is how each sub-requirement maps to the test we deliver.

11.4.1

Documented methodology

An industry-accepted approach (for example NIST SP 800-115) covering the full CDE perimeter and critical systems, at both the application and network layer.

11.4.2

Internal penetration testing

From inside the network, at least every 12 months and after any significant change.

11.4.3

External penetration testing

Against internet-facing CDE systems, at least every 12 months and after any significant change.

11.4.4

Remediate and retest

Exploitable findings are corrected and the testing repeated to verify the fix held.

11.4.5

Segmentation testing

Where segmentation isolates the CDE, those controls are tested at least every 12 months.

11.4.6

Segmentation, service providers

That segmentation testing rises to at least every 6 months.

11.4.7

Multi-tenant support

Multi-tenant service providers must support customer external testing.

APP

Application layer

The web applications and APIs in and around the CDE, tested for business-logic and access-control flaws scanners miss.

NET

Network layer

Hosts, services and configuration across the CDE perimeter and internal segments.

CHG

Significant-change testing

New components, topology or rule changes to the CDE trigger a fresh test, not just the annual one.

THE MANDATE

What requirements 11.4.1 to 11.4.6 require

PCI DSS v4.0.1 spells out the testing duty clause by clause. The source text is in the PCI SSC document library.

11.4.1

Documented methodology

A penetration testing methodology based on an industry-accepted approach: NIST SP 800-115, OWASP, OSSTMM or PTES.

11.4.2

Internal penetration testing

At least every 12 months and after significant infrastructure or application change.

11.4.3

External penetration testing

At least every 12 months and after significant change.

11.4.4

Correct and retest

Exploitable vulnerabilities are corrected and testing repeated to confirm the fix. Our retest is free.

11.4.5

Segmentation testing (with 11.4.6)

Where segmentation isolates the CDE: merchants at least every 12 months, service providers every 6 months under 11.4.6.

SEGMENTATION

Segmentation testing

Segmentation testing proves that the controls isolating your cardholder data environment actually hold, so systems outside the CDE stay out of scope.

Merchants · 11.4.5

Where segmentation is used to isolate the CDE, merchants must test it at least every 12 months.

Service providers · 11.4.6

Service providers must test the same controls every 6 months, so that line item lands twice a year.

Done well, it is also how you shrink your assessment scope and your bill.

METHODOLOGY

How a PCI DSS Engagement Runs

From scoping the cardholder data environment to a QSA-ready report and the retest that satisfies 11.4.4, here is how the engagement runs.

01

Scope

We define the CDE boundary and connected systems, confirm the 11.4.1 methodology, and fix the price and timeline.

02

Test

Internal and external, application and network layer, plus segmentation controls, with findings shared live to your portal.

03

Report

A QSA-ready report: an executive summary, technical detail, and every finding mapped to the 11.4 sub-requirement it evidences.

04

Retest

We verify your remediation to satisfy 11.4.4 and issue a letter of attestation.

CREDENTIALS

Verified Accreditations Auditors Accept

Every credential below is independently verifiable. UK procurement teams, FCA supervisors, ISO 27001 / SOC 2 auditors, and cyber insurance underwriters all recognise these standards.

GET YOUR QUOTE

Get your fixed-price quote in 24 hours from a CREST-certified consultant, with no sales pipeline to chase

A fixed-price quote back in one working day, from a CREST-certified consultant. No sales pipeline, no chasing.

  • CREST and IASME accredited. Testing your auditors and clients already recognise.
  • Fast-track testing within 24 hours where required. Free retest of every fix included.
  • Live findings via your client portal, not a four-week PDF.
  • Fixed, scope-based price from £1,200 for a small penetration test scope, agreed up front. Certifications such as Cyber Essentials are priced separately. In our experience most engagements run £3,000 to £8,000. No day-rate surprises.
What clients say
There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.
CelloriDan WilcocksonCo-Founder, Cellori

Under NDA Further named references available on a scoping call.

What happens next
Nazia Khaleeq, Chief Revenue Officer Nazia KhaleeqChief Revenue Officer
  1. Nazia replies the same working dayYou will receive a fixed quote prepared by a CREST-certified consultant.
  2. You approve the scopeEngagement date is set, usually within 24 hours.
  3. Live findings land in your client portalTesting is live with free retests for every fix.
Accredited & recognised
CREST member Cyber Essentials certified Cyber Essentials Plus certified IASME certifying body ISO 27001 certified ISO 9001 certified UK Cyber Security Council Crown Commercial Service supplier

Get your fixed-price quote in 24 hours

24h reply CREST tester Free retests

or book a 20-min scoping call first

We reply within one working day. Your data stays with us. No newsletter signup.

COMPLIANCE READY

Reports Mapped to Every Framework

Findings are explicitly tagged to the relevant control reference. Your audit team submits the report directly without translation work.

PCI DSS 11.4

Internal + external + segmentation testing, mapped sub-requirement by sub-requirement.

ISO 27001 A.8.29

The same evidence supports secure-testing controls for your ISMS.

SOC 2 CC7.1

Penetration testing evidence auditors expect for vulnerability detection.

UK GDPR Article 32

Regular testing of the effectiveness of your security measures.

Cyber Essentials Plus

Complements the CE+ assessment for a fuller assurance picture.

NIST SP 800-115

The technical testing methodology behind the engagement.

QSA EVIDENCE

Evidence your QSA accepts

Your report is the same one described across this page: fixed price, named tester, accepted by QSAs as 11.4 evidence. It documents four things.

Methodology

Aligned to an industry-accepted approach (NIST SP 800-115, OWASP, OSSTMM, PTES), as 11.4.1 requires.

Scope

The tested scope, documented in full.

Findings

Every finding with evidence and a clear remediation path.

Retest

The retest that closes out 11.4.4. Free with us.

PRICING

Transparent PCI DSS Pen Test Pricing

A PCI DSS pen test is priced at £1,100 to £1,400 a day for a defined scope, with a fixed price before work starts. The full per-requirement breakdown is in our PCI DSS penetration testing cost guide, the wider maths in the penetration testing cost guide, and every figure on the published price list.

✦ ALWAYS · ON EVERY TIER · NO EXCEPTIONS ✦
Free retests, no time limit
Free rescheduling
No cancellation fees
24-hour scope to active testing
Live findings to client portal
Executive + technical report
60-min walkthrough call
Letter of attestation
SMALL
From £2,400
2-day engagement

A single application or a small, well-segmented CDE.

Get a fixed quote
ENTERPRISE
From £9,600
8-day engagement

A large or multi-site CDE, or a service provider on the 6-month segmentation cadence.

Get a fixed quote

See how PCI DSS pricing is calculated

WHY EJN LABS

What You Get From a PCI DSS Pen Test

Six concrete differentiators competitors don’t all match.

Fixed price in 24h

Send your CDE scope and we return a fixed price and timeline within one working day.

Named CREST-accredited UK tester

Every engagement is run by a named, CREST-accredited, UK-based tester.

A report your QSA accepts

QSA-ready evidence, mapped finding by finding to the Requirement 11.4 sub-requirements.

Live findings to your portal

Findings land in your portal as we test, so remediation can start straight away.

Free retests for 11.4.4

We retest your fixes to satisfy Requirement 11.4.4, at no extra charge.

Letter of attestation

A letter of attestation on completion, for your QSA and your records.

FAQ

Frequently Asked

Does PCI DSS require a penetration test?

Yes. Requirement 11.4 requires internal and external penetration testing, at least every 12 months and after any significant change.

How often is PCI DSS penetration testing required?

At least every 12 months, and after any significant change. For service providers, segmentation testing rises to at least every 6 months (Requirement 11.4.6).

What is the difference between an ASV scan and a PCI DSS penetration test?

Scanning is Requirement 11.3 and automated. Penetration testing is Requirement 11.4 and manual. PCI DSS requires both: quarterly scanning under Requirements 11.3.1 and 11.3.2, and penetration testing under Requirement 11.4.

Who can perform a PCI DSS penetration test?

A qualified and organisationally independent tester. PCI DSS names no specific scheme, and QSAs widely accept CREST accreditation as evidence of competence.

What does the test need to cover?

The full cardholder data environment perimeter and critical systems, internal and external, at both the application and network layer, plus segmentation controls.

Will the report be accepted by my QSA?

Yes. It is structured as QSA-ready evidence, with every finding mapped to the Requirement 11.4 sub-requirement it supports.

What happens if you find vulnerabilities?

We map practical remediation, and Requirement 11.4.4 requires a retest to verify the fixes held. That retest is included.

How much does a PCI DSS penetration test cost?

It is priced on your cardholder data environment scope, as a fixed price, benchmarked against our published day rate of £1,100 to £1,400 on the price list. Request a fixed quote and we will reply within one working day.

EXPLORE EVERY SERVICE

20+ CREST-accredited testing services in one place

Web, mobile, API, cloud, AI, infrastructure, red team. Pick the test that fits your environment.

Penetration testing services
READY TO START

Get your PCI DSS pen test scoped in 24 hours

Send us your cardholder data environment scope and we will return a fixed price, a timeline, and the name of the CREST-accredited tester who will run it.