PCI DSS penetration testing
If you handle card data, PCI DSS requires penetration testing on a set cadence and scope. Here is what the standard asks for, in plain English, and how to choose a firm that will satisfy your assessor.
What PCI DSS requires
PCI DSS calls for penetration testing of the cardholder data environment at both the network and application layers, from outside (external) and inside (internal) perspectives. If you use network segmentation to keep systems out of scope, the effectiveness of that segmentation must also be tested.
Testing is required at least annually and after any significant change to the environment. The exact clauses and any version-specific detail should always be confirmed against the current PCI DSS standard and with your assessor (QSA), as requirements are periodically revised.
Scan and test are both required
A common source of confusion: PCI requires both regular vulnerability scanning and penetration testing. Scanning is an automated, recurring check for known vulnerabilities. Penetration testing is a deeper, manual-led exercise that attempts to exploit weaknesses and confirm whether controls actually hold. Passing scans does not satisfy the penetration-testing requirement.
Choosing a firm for PCI
Look for a firm that testers independently of the systems under test, documents its methodology, and produces a report structured so your assessor can map findings to the relevant requirements. Recognised accreditations such as CREST are a useful signal of quality, though PCI does not mandate one specific certification. Confirm the firm has done PCI-scoped work before and will retest remediated issues.
Frequently asked
Does PCI DSS require penetration testing?
Yes. PCI DSS requires both external and internal penetration testing of the cardholder data environment, covering the network and application layers, and testing of any segmentation controls used to reduce scope. It must be performed at least annually and after any significant change.
How often is PCI penetration testing required?
At least once every 12 months, and again after any significant change to the in-scope environment — for example a new system component, a network change, or an application upgrade. Organisations relying on segmentation to reduce scope must also test that segmentation regularly.
Who can perform PCI penetration testing?
The tester must be organisationally independent and suitably qualified. PCI does not mandate a single certification, but relevant industry credentials and demonstrable methodology are expected, and many buyers look for firms with recognised accreditations such as CREST.
What is the difference between a scan and a penetration test for PCI?
PCI requires both. Quarterly vulnerability scanning is an automated check for known issues; penetration testing is a deeper, manual-led assessment that attempts to exploit weaknesses and validate controls. They are separate requirements and one does not replace the other.
Compare UK penetration testing companies
Our independent directory lets you filter firms by service, accreditation, and size — sourced from public records, never pay-to-play.
Browse the directory