Hire certified ethical hackers to test the systems that store, process, or transmit cardholder data — meeting PCI DSS Requirement 11.3 with documented, auditor-ready results.
✔ OSCP / OSWE Certified Team ✔ NDA on Every Project ✔ Written Authorization Required ✔ 24–48h Response Time
PCI DSS Requirement 11.3, Explained
Unlike some frameworks that only imply the need for testing, PCI DSS is explicit: Requirement 11.3 requires merchants and service providers to perform penetration testing on the cardholder data environment (CDE) at least annually and after any significant infrastructure or application change, covering both network-layer and application-layer testing, plus segmentation testing if segmentation is used to reduce PCI scope.
Testing must be performed by a qualified internal resource or a qualified external third party — this is where an independent, documented engagement becomes necessary rather than optional.
What’s Covered
- Cardholder Data Environment (CDE) Testing: Network and application-layer testing of any system that stores, processes, or transmits card data.
- Segmentation Testing: Verifying that network segmentation actually isolates the CDE from the rest of your environment, as PCI DSS requires if you rely on segmentation to reduce scope.
- E-commerce Platform & Checkout Testing: Testing your payment flow and checkout pages — see Web Application Penetration Testing.
- API Testing: For platforms processing payments via API integrations — see API Security Testing.
- Internal Network Testing: Assessing internal systems connected to or near the CDE — see Network Penetration Testing.
What You Receive
A PCI DSS-aligned report documenting scope, methodology, findings, severity ratings, and remediation guidance — formatted to support your Report on Compliance (ROC) or Self-Assessment Questionnaire (SAQ) submission. Retesting is included once remediation is complete.
Frequently Asked Questions
How often does PCI DSS require penetration testing? At least annually, and after any significant change to the cardholder data environment or supporting infrastructure.
Do you test segmentation specifically? Yes — segmentation testing is included when segmentation is used to reduce your PCI scope, as required by 11.3.4.
Can this replace our ASV scans? No — Approved Scan Vendor (ASV) scans are a separate PCI requirement (11.3.2) for external vulnerability scanning. Penetration testing is a distinct, complementary requirement.
Are you a QSA (Qualified Security Assessor)? We provide the technical penetration testing required under 11.3; talk to us about how our reports fit into your broader PCI compliance process.
← Back to All Services and Industries
Ready to Meet PCI DSS Requirement 11.3?
Tell us about your cardholder data environment and we’ll scope a compliant penetration test.