PCI DSS Penetration Testing
PCI DSS penetration testing is one of the few tests genuinely required by a standard: requirements 11.4.1 to 11.4.6 mandate internal, external and segmentation testing on a fixed cadence, and EJN Labs delivers all of them. You get a fixed price, a named UK-based tester, and a report your QSA will accept as evidence. Free retests are included so you can close out 11.4.4.
- Unlimited retesting
- Unlimited pre-retesting
- No hidden fees
“I would highly recommend EJN Labs to any organisation seeking reliable, detailed, and well-managed penetration testing services, particularly for government or enterprise-level projects.”
“There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.”
separate PCI DSS testing duties: vulnerability scanning under 11.3 and penetration testing under 11.4
Passing your scans is not passing PCI DSS
An ASV scan meets Requirement 11.3.2. It does nothing for Requirement 11.4. Automated scanning is broad and shallow by design: it flags known signatures, but it does not chain weaknesses, bypass controls, or prove what an attacker could actually reach inside your cardholder data environment.
Requirement 11.4 asks for a manual, goal-driven penetration test that a scanner cannot replace. That is where business-logic flaws, access-control gaps, and exploitable paths into the CDE are found. It is also what your QSA expects to see, mapped to the sub-requirements, before they sign.
We scope every engagement against 11.4 directly, so the deliverable lines up with the evidence your assessor checks. Findings are triaged by exploitability, remediation is practical, and the retest to satisfy 11.4.4 is included rather than billed again.
In practice, two gaps come up repeatedly in the PCI engagements our CREST-certified consultants run. The first is segmentation controls between the cardholder data environment and the wider corporate network that have never been penetration tested. The second is an ASV scan being treated as the penetration test itself. Our methodology follows industry-accepted guidance including NIST SP 800-115 and the PCI SSC Penetration Testing Guidance, so the report ties each part of the engagement back to the sub-requirement your assessor checks.
PCI DSS REQUIREMENT 11.4
What a PCI DSS Penetration Test Covers
Requirement 11.4 is specific about scope, cadence and independence. Here is how each sub-requirement maps to the test we deliver.
Documented methodology
An industry-accepted approach (for example NIST SP 800-115) covering the full CDE perimeter and critical systems, at both the application and network layer.
Internal penetration testing
From inside the network, at least every 12 months and after any significant change.
External penetration testing
Against internet-facing CDE systems, at least every 12 months and after any significant change.
Remediate and retest
Exploitable findings are corrected and the testing repeated to verify the fix held.
Segmentation testing
Where segmentation isolates the CDE, those controls are tested at least every 12 months.
Segmentation, service providers
That segmentation testing rises to at least every 6 months.
Multi-tenant support
Multi-tenant service providers must support customer external testing.
Application layer
The web applications and APIs in and around the CDE, tested for business-logic and access-control flaws scanners miss.
Network layer
Hosts, services and configuration across the CDE perimeter and internal segments.
Significant-change testing
New components, topology or rule changes to the CDE trigger a fresh test, not just the annual one.
THE MANDATE
What requirements 11.4.1 to 11.4.6 require
PCI DSS v4.0.1 spells out the testing duty clause by clause. The source text is in the PCI SSC document library.
Documented methodology
A penetration testing methodology based on an industry-accepted approach: NIST SP 800-115, OWASP, OSSTMM or PTES.
Internal penetration testing
At least every 12 months and after significant infrastructure or application change.
External penetration testing
At least every 12 months and after significant change.
Correct and retest
Exploitable vulnerabilities are corrected and testing repeated to confirm the fix. Our retest is free.
Segmentation testing (with 11.4.6)
Where segmentation isolates the CDE: merchants at least every 12 months, service providers every 6 months under 11.4.6.
SEGMENTATION
Segmentation testing
Segmentation testing proves that the controls isolating your cardholder data environment actually hold, so systems outside the CDE stay out of scope.
Where segmentation is used to isolate the CDE, merchants must test it at least every 12 months.
Service providers must test the same controls every 6 months, so that line item lands twice a year.
Done well, it is also how you shrink your assessment scope and your bill.
METHODOLOGY
How a PCI DSS Engagement Runs
From scoping the cardholder data environment to a QSA-ready report and the retest that satisfies 11.4.4, here is how the engagement runs.
Scope
We define the CDE boundary and connected systems, confirm the 11.4.1 methodology, and fix the price and timeline.
Test
Internal and external, application and network layer, plus segmentation controls, with findings shared live to your portal.
Report
A QSA-ready report: an executive summary, technical detail, and every finding mapped to the 11.4 sub-requirement it evidences.
Retest
We verify your remediation to satisfy 11.4.4 and issue a letter of attestation.
CREDENTIALS
Verified Accreditations Auditors Accept
Every credential below is independently verifiable. UK procurement teams, FCA supervisors, ISO 27001 / SOC 2 auditors, and cyber insurance underwriters all recognise these standards.
GET YOUR QUOTE
Get your fixed-price quote in 24 hours from a CREST-certified consultant, with no sales pipeline to chase
A fixed-price quote back in one working day, from a CREST-certified consultant. No sales pipeline, no chasing.
- CREST and IASME accredited. Testing your auditors and clients already recognise.
- Fast-track testing within 24 hours where required. Free retest of every fix included.
- Live findings via your client portal, not a four-week PDF.
- Fixed, scope-based price from £1,200 for a small penetration test scope, agreed up front. Certifications such as Cyber Essentials are priced separately. In our experience most engagements run £3,000 to £8,000. No day-rate surprises.
Under NDA Further named references available on a scoping call.
- Nazia replies the same working dayYou will receive a fixed quote prepared by a CREST-certified consultant.
- You approve the scopeEngagement date is set, usually within 24 hours.
- Live findings land in your client portalTesting is live with free retests for every fix.
Get your fixed-price quote in 24 hours
Quote request received
We will reply within one working day with your fixed-price quote from a CREST-certified consultant.
Your data stays with us. No newsletter signup.
or book a 20-min scoping call first
We reply within one working day. Your data stays with us. No newsletter signup.
COMPLIANCE READY
Reports Mapped to Every Framework
Findings are explicitly tagged to the relevant control reference. Your audit team submits the report directly without translation work.
PCI DSS 11.4
Internal + external + segmentation testing, mapped sub-requirement by sub-requirement.
ISO 27001 A.8.29
The same evidence supports secure-testing controls for your ISMS.
SOC 2 CC7.1
Penetration testing evidence auditors expect for vulnerability detection.
UK GDPR Article 32
Regular testing of the effectiveness of your security measures.
Cyber Essentials Plus
Complements the CE+ assessment for a fuller assurance picture.
NIST SP 800-115
The technical testing methodology behind the engagement.
QSA EVIDENCE
Evidence your QSA accepts
Your report is the same one described across this page: fixed price, named tester, accepted by QSAs as 11.4 evidence. It documents four things.
Aligned to an industry-accepted approach (NIST SP 800-115, OWASP, OSSTMM, PTES), as 11.4.1 requires.
The tested scope, documented in full.
Every finding with evidence and a clear remediation path.
The retest that closes out 11.4.4. Free with us.
PRICING
Transparent PCI DSS Pen Test Pricing
A PCI DSS pen test is priced at £1,100 to £1,400 a day for a defined scope, with a fixed price before work starts. The full per-requirement breakdown is in our PCI DSS penetration testing cost guide, the wider maths in the penetration testing cost guide, and every figure on the published price list.
2-day engagement
A single application or a small, well-segmented CDE.
Get a fixed quote4-day engagement
A typical CDE: internal + external + segmentation.
Get a fixed quote8-day engagement
A large or multi-site CDE, or a service provider on the 6-month segmentation cadence.
Get a fixed quoteBY SECTOR
PCI DSS Testing for Your Sector
Sector-specialist scoping for UK businesses with sector-specific compliance regimes and threat models.
Fintech
Payment APIs and SCA authentication flows.
Fintech sector pageSaaS
Multi-tenant cardholder data environments and Requirement 11.4.7 support.
SaaS sector pageE-commerce & Retail
Checkout journeys and card-capture pages.
Retail sector pageHealthcare
Card payment data and patient-data overlap.
Healthcare sector pageFinancial Services
Card payments and the systems inside your CDE.
Financial services sector pageHospitality
Point-of-sale estates and card-present environments.
Hospitality sector pageWHY EJN LABS
What You Get From a PCI DSS Pen Test
Six concrete differentiators competitors don’t all match.
Fixed price in 24h
Send your CDE scope and we return a fixed price and timeline within one working day.
Named CREST-accredited UK tester
Every engagement is run by a named, CREST-accredited, UK-based tester.
A report your QSA accepts
QSA-ready evidence, mapped finding by finding to the Requirement 11.4 sub-requirements.
Live findings to your portal
Findings land in your portal as we test, so remediation can start straight away.
Free retests for 11.4.4
We retest your fixes to satisfy Requirement 11.4.4, at no extra charge.
Letter of attestation
A letter of attestation on completion, for your QSA and your records.
FAQ
Frequently Asked
Does PCI DSS require a penetration test?
Yes. Requirement 11.4 requires internal and external penetration testing, at least every 12 months and after any significant change.
How often is PCI DSS penetration testing required?
At least every 12 months, and after any significant change. For service providers, segmentation testing rises to at least every 6 months (Requirement 11.4.6).
What is the difference between an ASV scan and a PCI DSS penetration test?
Scanning is Requirement 11.3 and automated. Penetration testing is Requirement 11.4 and manual. PCI DSS requires both: quarterly scanning under Requirements 11.3.1 and 11.3.2, and penetration testing under Requirement 11.4.
Who can perform a PCI DSS penetration test?
A qualified and organisationally independent tester. PCI DSS names no specific scheme, and QSAs widely accept CREST accreditation as evidence of competence.
What does the test need to cover?
The full cardholder data environment perimeter and critical systems, internal and external, at both the application and network layer, plus segmentation controls.
Will the report be accepted by my QSA?
Yes. It is structured as QSA-ready evidence, with every finding mapped to the Requirement 11.4 sub-requirement it supports.
What happens if you find vulnerabilities?
We map practical remediation, and Requirement 11.4.4 requires a retest to verify the fixes held. That retest is included.
How much does a PCI DSS penetration test cost?
It is priced on your cardholder data environment scope, as a fixed price, benchmarked against our published day rate of £1,100 to £1,400 on the price list. Request a fixed quote and we will reply within one working day.
20+ CREST-accredited testing services in one place
Web, mobile, API, cloud, AI, infrastructure, red team. Pick the test that fits your environment.
Get your PCI DSS pen test scoped in 24 hours
Send us your cardholder data environment scope and we will return a fixed price, a timeline, and the name of the CREST-accredited tester who will run it.



