GetPentest

PCI DSS penetration testing requirements

PCI DSS is the only common framework that writes down what a penetration test must contain. That is good news, because it means the argument with your assessor is about evidence rather than about interpretation.

Last reviewed 2026-08-27Written by Jacob Masse, TrazTech Inc.

PCI DSS requires internal and external penetration testing at least once every twelve months and after any significant change, plus separate testing of the controls that segment your cardholder data environment from everything else. That is requirement 11.4, and unlike SOC 2 and ISO 27001, which never name a penetration test at all, PCI DSS says it explicitly and sets the frequency. For a Canadian merchant or service provider, the annual cost sits between $10,000 and $40,000 CAD depending on how much of your environment is in scope. You control that number more than you think.

11.4 The requirement that names a penetration test

12 months Internal and external, plus after significant change

6 months Segmentation testing, service providers

What requirement 11.4 asks for

PCI DSS penetration testing requirements, in outline
Sub-requirementWhat it asks forFrequency
11.4.1A defined and documented methodology, based on an industry-accepted approach, covering the whole cardholder data environment perimeter and critical systems, network layer and application layer, with a defined retention period for resultsReviewed and kept current
11.4.2Internal penetration testing following that methodologyAt least every 12 months, and after significant change
11.4.3External penetration testing following that methodologyAt least every 12 months, and after significant change
11.4.4Exploitable vulnerabilities and security weaknesses corrected, and testing repeated to verify the correctionAfter each test
11.4.5Testing of segmentation controls, confirming they are operational and effective and that out-of-scope systems are isolated from the cardholder data environmentAt least every 12 months, and after any change to segmentation controls
11.4.6The same segmentation testing, for service providersAt least every 6 months, and after any change
11.4.7Multi-tenant service providers support their customers in performing testingOngoing

Read the current version of the standard rather than this table before you sign anything. The Security Standards Council revises PCI DSS and the numbering moves between versions. The shape has been stable for years: internal, external, segmentation, remediation, retest.

Segmentation testing, which is its own product

Segmentation testing is the requirement most often missed, and the only test in security where a negative result is the whole deliverable. The tester sits on an out-of-scope network and attempts to reach the cardholder data environment across every path the segmentation controls are supposed to block. The report says which attempts were made and that they failed, and that document removes the rest of your network from assessment scope.

The commercial argument for segmenting

Segmentation is a cost control before it is a security control. Every system that can reach the cardholder data environment is in scope for the whole standard, which means it needs the logging, the patching cadence, the access reviews and the testing. Two to four tester days proving a segment holds routinely removes dozens of systems from an assessment. If you are being quoted for testing across a flat network, segment first and test second.

Segmentation testing is not a firewall rule review. A rule review reads the configuration; the test tries the paths. Assessors have become less willing to accept a configuration export in place of test results, and the two cost about the same to produce.

Comparing firms for this? Tell us what you need and it goes to the ones in the directory that do this work. No charge, and no phone number required.

Scanning and testing are separate requirements

PCI DSS asks for both, and companies regularly buy one and believe they have satisfied the other. Requirement 11.3 covers vulnerability scanning: internal and external scans on a quarterly cadence, the external ones performed by an Approved Scanning Vendor, a company authorized by the Security Standards Council to run them. Requirement 11.4 is the penetration testing above, annual and performed by a person.

Two requirements that get confused
Requirement 11.3 scanningRequirement 11.4 testing
CadenceQuarterly, and after significant changeAnnually, and after significant change
Who performs itExternal scans by an Approved Scanning VendorA qualified tester, internal or external, organizationally independent
OutputA passing scan reportA test report with findings, evidence and a retest
Typical Canadian cost$1,500 to $6,000 CAD a year$10,000 to $40,000 CAD a year

A vendor offering to satisfy 11.4 for the price of a quarterly scanning subscription is selling you 11.3 under the wrong name. That argument is on vulnerability assessment versus penetration test.

Who is allowed to perform the test

PCI DSS does not require a Qualified Security Assessor or any named certification for the tester. It requires organizational independence from the team that manages the systems being tested, and a tester qualified in the methods being used. An internal security team that does not report through the group running the cardholder environment can do the work, and some large merchants do.

Most Canadian companies buy it externally. Assembling the qualification and independence evidence for an internal team costs more attention than the engagement does. If you go external, the checks worth running are the ones on choosing a Canadian testing firm, with one addition: ask them to name the methodology in 11.4.1 terms and to state in the report which parts of the cardholder data environment perimeter were covered.

What counts as a significant change

The standard leaves this to you to define, then holds you to your definition. Write it down before your assessment. A workable definition covers changes to the network topology or firewall rules around the cardholder data environment, a new or replaced payment application or gateway, a move to a new hosting provider or region, changes to segmentation controls, and the addition of a new site or acquisition that touches card data.

Routine patching and application releases that do not alter the perimeter or the payment flow are not significant changes, and defining them as such commits you to testing continuously. Assessors accept a defined, reasoned threshold. What they do not accept is the question never having been answered.

What PCI testing costs in Canada

Annual PCI DSS testing spend, CAD, 2026
ComponentTypical range
External penetration test, segmented environment$7,000 to $16,000
Internal penetration test, segmented environment$8,000 to $20,000
Segmentation testing$5,000 to $12,000
Segmentation testing, service provider, second half-year round$4,000 to $10,000
Approved Scanning Vendor scanning, four quarters$1,500 to $6,000
Retest after remediationIncluded, or $1,500 to $6,000

The largest single lever on that total is scope. A merchant who has moved card entry to a hosted payment page or an iframe from the payment provider, so that card numbers never reach their own systems, drops to a much shorter self-assessment and a much smaller testing footprint. That work is often cheaper than the testing it avoids in one year. The cost calculator prices the testing side once you know which situation you are in.

If you are a payments company rather than a merchant, PCI DSS is one of several regimes reaching you, and which others apply changes the deliverable as much as the price. That filter is on fintech penetration testing in Canada.

Scope PCI testing without over-buying

Tell us how card data flows and how the environment is segmented, and we will put one scope in front of Canadian firms.

Get matched

Common questions

Does PCI DSS require an annual penetration test?

Yes. Requirement 11.4 calls for internal and external penetration testing at least once every twelve months and after any significant change, following a documented methodology. This is the clearest testing requirement in any framework a Canadian company is likely to face, and it is the reason PCI scope creep is expensive: everything inside the cardholder data environment inherits it.

How often does segmentation testing need to happen?

At least every twelve months for merchants, at least every six months for service providers, and after any change to the segmentation controls in either case. It is a separate exercise from the internal and external tests, with its own report, and it is the most commonly missed piece of requirement 11.4.

We use a hosted payment page. Do we still need penetration testing?

Your testing obligation shrinks with your scope but does not always disappear, because the page that redirects to the payment provider is still part of the flow and can be tampered with. Which self-assessment questionnaire applies decides the detail, and that depends on exactly how the payment page is embedded. Establish your questionnaire type first, because it determines everything else, including whether requirement 11.4 applies to you at all.

Can our own security team do the testing?

Yes, if they are qualified in the methods and organizationally independent of the people who manage the systems in scope. The standard asks for independence rather than for an external firm or a specific certification. Most Canadian companies still buy it externally because producing the qualification and independence evidence for an internal team is more work than the test.

Does a PCI test satisfy our SOC 2 requirement as well?

Often yes, and this is worth planning for. A SOC 2 auditor wants evidence of independent testing and of remediation, and a PCI-scoped engagement provides both. The check is coverage: if your SOC 2 system description covers a product that reaches well beyond the cardholder data environment, the PCI test does not cover all of it and the gap will be noticed. Scope the engagement to the union of both once, rather than running two tests.