2026.08.09 · Compliance

How to Prepare for a PCI DSS Penetration Test

PCI DSS Requirement 11.4 calls for annual penetration testing, plus segmentation testing if you rely on network segmentation to reduce your cardholder data environment scope. A few things make the process smoother:

Have an accurate network diagram before testing starts — testers can’t validate segmentation against a diagram that doesn’t match reality. Know your CDE boundary precisely, including any third-party systems that touch cardholder data. Confirm whether your last significant change (a new integration, a network change) requires a fresh test, since PCI DSS requires testing after significant changes, not just annually.

A report built for engineers isn’t automatically a report your QSA will accept — make sure whoever you engage understands what a PCI-scoped report needs to include.

← back to insights