> Source: https://planckproof.ai/pci-dss-penetration-testing  |  Plain-Markdown twin of the page.

PCI DSS 4.0

# PCI DSS penetration testing requirements, explained (Requirement 11.4)

Of the major frameworks, PCI DSS is the one that names penetration testing outright. Requirement 11.4 sets out the methodology, the frequency, the scope, and the retesting you must do. This guide walks through 11.4 in plain language and shows where continuous testing supports it.

[Get a Quote](https://planckproof.ai/quote)

[Compliance Overview](https://planckproof.ai/compliance)

Requirement 11.4

## What PCI DSS 4.0 actually asks for

- **11.4.1 Methodology:** a defined, documented penetration testing methodology, based on a recognized approach such as NIST SP 800-115
- **11.4.2 Internal testing:** internal penetration testing at least once every 12 months and after significant change
- **11.4.3 External testing:** external penetration testing at least once every 12 months and after significant change
- **11.4.4 Remediate and retest:** correct exploitable findings and repeat testing to verify the fixes
- **11.4.5 Segmentation:** where segmentation isolates the cardholder data environment, test that the segmentation controls actually hold
- **Coverage:** the testing exercises the full cardholder data environment perimeter and critical systems, including the application layer and the OWASP Top 10 classes

Where Operator Fits

## Keep 11.4 true all year, not just once

Requirement 11.4 sets a floor of once a year and after significant change. In a modern environment, significant change happens constantly, and a purely annual test cannot see what shipped last week.

Operator runs continuously, so a significant change is exercised when it lands, and every finding arrives with the reproduction evidence and CVSS rating an assessor expects. The formal annual test is still human led and, where you need it, signed by a certified practitioner.

[How it compares to a scanner](https://planckproof.ai/how-its-different)

- **NIST SP 800-115 aligned**, the methodology 11.4.1 points to.
- **Remediation and retest** built in, matching 11.4.4.
- **Segmentation checks** that exercise the boundaries around the cardholder data environment.
- **Human led annual test** preserved, with continuous coverage in between.

FAQ

## Common questions

Does PCI DSS require a penetration test?

Yes. Requirement 11.4 requires internal and external penetration testing at least once every 12 months and after any significant change, following a defined methodology such as NIST SP 800-115.

Does PCI DSS accept automated or AI penetration testing?

PCI DSS expects a qualified human tester following a documented methodology. Automated and autonomous testing is valuable for continuous coverage and for hardening the surface before the assessment, but the annual 11.4 test is expected to be human led. A certified practitioner can sign the assessment.

What is Requirement 11.4.4?

It requires that exploitable vulnerabilities and security weaknesses found during penetration testing are corrected, and that the testing is repeated to verify the corrections. Retesting is not optional under 11.4.

Get Started

## Stay inside Requirement 11.4 every day

Continuous testing after every significant change, with the human led annual assessment auditors expect.

[Get a Quote](https://planckproof.ai/quote)

[HIPAA](https://planckproof.ai/hipaa-penetration-testing)
