View all pentests
Technical evidence for your PCI DSS programme
A PCI DSS pentest investigates whether an attacker could access cardholder data or the systems protecting it. We test applications, networks and, where applicable, segmentation, with a scope aligned to your payment environment and applicable PCI DSS requirements.
Certified ethical hackers · CCV Keurmerk Pentesten

Where could an attacker gain access?
An internet-facing test answers different questions from testing inside your network. For PCI DSS, we bring the required perspectives together.
External
From outside your network
We investigate accessible systems and applications at the external perimeter. These may include payment applications, APIs and internet-facing services.
View the coverageInternal
From inside your network
We investigate attack paths within the cardholder data environment and from relevant internal networks. What could a vulnerable application or compromised account expose?
About segmentation testingScoping starts with your payment environment
The Cardholder Data Environment (CDE) is the environment in which cardholder data is stored, processed or transmitted. Systems that can affect its security also need consideration when defining scope.
Applications and APIs
We investigate areas such as access controls, sessions, input handling and payment process logic. Testing goes beyond identifying known software vulnerabilities.
Networks and systems
We test relevant services, configurations and attack paths. The test plan sets out the systems and starting points required.
Segmentation
If segmentation reduces PCI DSS scope, we test whether that separation works in practice. A firewall rule or network diagram alone does not demonstrate this.
Boundaries
Does the separation around your CDE hold?
We investigate whether the cardholder data environment can be reached from systems that should be isolated from it. This involves the segmentation controls in use and the agreed test positions, not just one port or network connection.
We discuss scope using network diagrams, data flows and your PCI DSS assessment. Involve your Qualified Security Assessor (QSA) or other assessment owner early so that assumptions and evidence needs are clear.
Pentest, ASV scan or PCI DSS assessment?
Pentest
Focused investigation of exploitation and attack paths. This is the service offered on this page.
ASV scan
A separate external vulnerability scan performed by an Approved Scanning Vendor. A pentest does not replace it.
Compliance assessment
Assessment of all applicable PCI DSS requirements. A pentest report is supporting evidence, not full approval of your compliance.
Your results
A report your team can act on
We make clear what was tested, the risk each finding presents and how to address it.
Scope and methodology
Systems assessed, internal and external test positions, segmentation where applicable and relevant limitations.
Validated findings
Technical evidence, risk ratings and remediation advice. A second pentester reviews the reporting under our four-eyes principle.
Verification of fixes
We agree retesting and recording of remediation status in advance. This distinguishes reported issues from those whose fixes have been verified.
How we align the pentest with your programme
Agree scope
We discuss your role, CDE, data flows, applicable requirements and questions arising from your PCI DSS assessment.
Prepare testing
We establish test positions, accounts, test windows, contacts and permission for third-party systems.
Allow for remediation
We plan testing and reporting with time for fixes and retesting ahead of your assessment.
A tailored proposal
What does a PCI DSS pentest cost?
Pricing depends on the size of your CDE, applications, test positions and segmentation tests required. Testing a single external IP address is different from a full internal and external pentest. After a free scoping conversation, you receive a proposal with clear agreements on coverage, reporting and retesting.
PCI DSS penetration testing FAQs
Which PCI DSS requirement covers penetration testing?
In PCI DSS v4.0.1, requirement 11.4 covers internal and external penetration testing, remediation and segmentation testing. Applicability depends on your environment and assessment. We align the test scope accordingly.
How often is a PCI DSS pentest required?
Where requirements 11.4.2 and 11.4.3 apply, internal and external pentests are required at least every twelve months and after significant infrastructure or application changes. Segmentation has additional testing intervals. An annual engagement does not automatically cover changes made between tests.
When is segmentation testing needed?
If segmentation isolates the CDE from other networks, its effectiveness must be tested at least every twelve months and after changes to segmentation controls. For service providers, this is at least every six months and after changes.
Is a vulnerability scan enough for PCI DSS?
Not where a pentest is required. Scanning and pentesting serve different purposes. The external ASV scan is also a separate service with its own requirements. We therefore do not treat a Basic Scan or a regular pentest as a replacement for a required ASV scan.
Does every online shop need a full PCI DSS pentest?
Not automatically. Your payment solution, outsourcing arrangements, role and applicable Self-Assessment Questionnaire (SAQ) or assessment determine the requirements. Confirm these with your acquiring bank or PCI DSS assessor. We then help define the required technical testing scope.
Will the pentest make me PCI DSS-compliant?
A pentest alone does not demonstrate full compliance. All applicable requirements must be assessed. We provide a technical report; identified vulnerabilities need follow-up and, where required, retesting to verify remediation.
Read the requirements at the source:
Nederlands