What are the PCI DSS penetration testing requirements under Requirement 11.4?
PCI DSS Requirement 11.4 requires organizations to perform internal and external penetration testing at least every 12 months and after any significant infrastructure or application changes. If network segmentation is used to isolate the Cardholder Data Environment (CDE), segmentation testing must also be performed at least annually, or every 6 months for service providers. Testing must follow defined methodologies, include retesting after remediation, and maintain documented results to validate that security controls are functioning as intended.