---
title: What are the PCI DSS penetration testing requirements under Requirement 11.4?
description: What PCI DSS Requirement 11.4 requires for internal, external, and segmentation testing.
---

[Skip to content](https://info.echeloncyber.com/resources/what-are-the-pci-dss-penetration-testing-requirements-under-requirement-114#main-content)

English

Show submenu for translations

Echelon Risk + Cyber

Open main navigation

Close main navigation

- English
  
  Show submenu for translations
- Contact us

 Contact us

 How can we help you?

- There are no suggestions because the search field is empty.

1. [Echelon Resources](https://info.echeloncyber.com/resources?hsLang=en)
2. [Offensive Security + Adversary Simulation](https://info.echeloncyber.com/resources/offensive-security-adversary-simulation?hsLang=en)
3. [PCI DSS Penetration Testing](https://info.echeloncyber.com/resources/offensive-security-adversary-simulation?hsLang=en#pci-dss-penetration-testing)

# What are the PCI DSS penetration testing requirements under Requirement 11.4?

PCI DSS Requirement 11.4 requires organizations to perform internal and external penetration testing at least every 12 months and after any significant infrastructure or application changes. If network segmentation is used to isolate the Cardholder Data Environment (CDE), segmentation testing must also be performed at least annually, or every 6 months for service providers. Testing must follow defined methodologies, include retesting after remediation, and maintain documented results to validate that security controls are functioning as intended.

- [Managed Security Services (MSSP)](https://info.echeloncyber.com/resources/managed-security-services-mssp?hsLang=en)
- [vCISO-Led Security Team as a Service](https://info.echeloncyber.com/resources/vciso-led-security-team-as-a-service?hsLang=en)
- [Offensive Security + Adversary Simulation](https://info.echeloncyber.com/resources/offensive-security-adversary-simulation?hsLang=en#main-content)
  
  
  
  
  
    - [PCI DSS Penetration Testing](https://info.echeloncyber.com/resources/offensive-security-adversary-simulation?hsLang=en#pci-dss-penetration-testing)
    - [Mobile Application Penetration Testing](https://info.echeloncyber.com/resources/offensive-security-adversary-simulation?hsLang=en#mobile-application-penetration-testing)
    - [Penetration Testing](https://info.echeloncyber.com/resources/offensive-security-adversary-simulation?hsLang=en#penetration-testing)
    - [Web Application Penetration Testing](https://info.echeloncyber.com/resources/offensive-security-adversary-simulation?hsLang=en#web-application-penetration-testing)
    - [Red Teaming](https://info.echeloncyber.com/resources/offensive-security-adversary-simulation?hsLang=en#red-teaming)
- [Defensive Security + Hardening](https://info.echeloncyber.com/resources/defensive-security-hardening?hsLang=en#main-content)
  
  
  
  
  
    - [CrowdStrike Platform Services](https://info.echeloncyber.com/resources/defensive-security-hardening?hsLang=en#crowdstrike-platform-services)
- [Risk Advisory + GRC](https://info.echeloncyber.com/resources/risk-advisory-grc?hsLang=en#main-content)
  
  
  
  
  
    - [CMMC 2.0 Compliance](https://info.echeloncyber.com/resources/risk-advisory-grc?hsLang=en#cmmc-2-0-compliance)
    - [AI Governance](https://info.echeloncyber.com/resources/risk-advisory-grc?hsLang=en#ai-governance)

# Echelon Risk + Cyber

<https://www.facebook.com/> <https://www.twitter.com/> <https://www.instagram.com/> <https://podcasts.apple.com/> [mailto:email@email.com](mailto:email@email.com)

Copyright © 2026, Echelon Risk + Cyber