Offensive Security Learning Center

What is a PCI Pentest? Compliance Testing | Cobalt

Written by Cobalt | May 9, 2019, 3:00:00 PM

For any company that stores, processes, or transmits cardholder data, understanding the Payment Card Industry Data Security Standard (PCI DSS) is critical. Adhering to these standards helps protect sensitive information and demonstrates a commitment to security. A key component of this standard is regularly performing a penetration test on your cardholder data environment (CDE). This goes hand in hand with vulnerability scans performed by an Approved Scanning Vendor (ASV).

The latest version, PCI DSS 4.0.1, was released in June 2024, and compliance with this version has been mandatory since March 2025

PCI DSS Compliance extends beyond a single application to include all surrounding and connected networks, from the internal network to the external network, and any components that interact with the CDE.

What is a PCI penetration test?

A PCI DSS penetration test is a cybersecurity assessment that examines a system's technical and operational components to ensure they meet the security standards set by the Payment Card Industry (PCI) Security Standards Council. This type of testing assesses a network's infrastructure and applications, both internal and external, to proactively identify potential vulnerabilities. The penetration testing methodology mimics the steps a malicious attacker or hacker would take to infiltrate a system.

Under PCI DSS 4.0.1, section 11.3 outlines penetration testing requirements. These updates emphasize risk-based testing approaches, mandate penetration testing after any significant changes—not just annually—and require organizations to validate segmentation controls rather than assume they are effective.

Effective external penetration testing services can also help a business avoid the high costs and reputation damage associated with a security breach. By proactively identifying and helping to exploit vulnerabilities, companies can act before irreversible damage occurs. A thorough penetration test also shows customers that you take protecting their data seriously.

Which organizations are compliant with PCI, and how penetration testing can help ?

The PCI DSS framework defines the CDE as “the people, processes, and technology that store, process, or transmit cardholder data or sensitive authentication data.” These security assessments should be performed on any application or infrastructure that handles credit or debit card data. This provides a comprehensive review of potential vulnerabilities.

PCI DSS applies to all entities involved in payment card processing—including merchants, processors, acquirers, issuers, and service providers. In short, if your business handles cardholder data, these requirements apply.

What are the PCI DSS requirements?

The PCI DSS framework is an extensive set of guidelines that help businesses maintain safe practices at every step of the payment process. Key requirements often include:

  • Implementing strong password policies and regularly updating all passwords within your organization.
  • Scanning of e-commerce environments by using an Approved Scanning Vendor (ASV).
  • Effective daily log monitoring.
  • Creating instructional materials for the implementation and use of secure payment systems.
  • Utilizing network segmentation and firewall controls to isolate the CDE.
  • All scripts on payment pages must be inventoried, authorized, and monitored for unauthorized modifications.
  • SSL, TLS 1.0, and TLS 1.1 are no longer permitted in the CDE. TLS 1.2 is the minimum; TLS 1.3 is recommended.

PCI DSS 4.0.1 introduced several new and strengthened requirements, including mandatory multi-factor authentication for all access into the CDE, stronger password rules (minimum length and complexity), expanded continuous monitoring and logging expectations, and a “customized approach” option that provides flexibility while ensuring the same security outcomes.

These are just some of the compliance standards. Maintaining PCI compliance benefits companies of all types by demonstrating a commitment to recommended security standards.

By showing that your company conducts regular security assessments and testing, you build trust with customers, leading to stronger client relationships and better business outcomes.

Why PCI DSS 4.0.1 matters

PCI DSS 4.0.1 has been mandatory since March 2025. It replaced the prescriptive, one-size-fits-all approach of prior versions with a risk-based model—giving organizations flexibility in how they meet requirements while holding the line on outcomes.

Key priorities include stronger authentication, modern encryption, payment page integrity, and continuous monitoring. Compliance is no longer a point-in-time exercise; 4.0.1 expects ongoing validation.

How Cobalt helps with PCI penetration testing requirements

We provide penetration testing services that follow the requirements set forth by the PCI Security Standards Council. Our services include a comprehensive penetration testing methodology performed by qualified penetration testers and clear, actionable reporting.

We use a vetted team of highly skilled penetration testers to find the right expertise to match your security needs.

We approach each assessment with the same diligence as if we were securing our own business, placing the utmost importance on accuracy and meticulousness, while also using the best-in-class methodologies to conduct the pentest.

But that’s not all. At Cobalt, we don’t just identify vulnerabilities; we provide clear, actionable plans for remediation and complementary retesting after remediation to help validate fixes discovered during the test.

After completing your penetration test, our skilled penetration testers will deliver reports through your preferred workflow integrations, such as Jira or GitHub. This makes vulnerability remediation a streamlined process. You can collaborate directly with the penetration testers on the Cobalt platform to fix any discovered issues. Using a built-in workflow, the penetration testers will also perform retesting to verify your patches at no extra charge.

This process is essential to validate the effectiveness of your remediation efforts and ensure you meet your PCI DSS retesting requirements. Additionally, retesting is a key step to take after any significant changes to your network, applications, or firewall rules, or any other changes that might impact your segmentation controls.

If you have been looking into PCI DSS compliance and penetration testing requirements, we encourage you to schedule a Penetration Testing as a Service (PTaaS) Platform demo today.