PCi

PCI Assessments Center

Loading your workspace…

PCiPCI Assessments Center
Free guide · PCI DSS v4.0.1

PCI DSS Requirement 11.4.3 — External penetration testing

Requirement 11.4.3 requires external penetration testing at least once every 12 months and after any significant infrastructure or application change, performed per the methodology defined in Requirement 11.4.1 by a qualified tester with organisational independence. The tester does not have to be a QSA or ASV.Timing: Applies in PCI DSS v4.0.1 and is assessed at every annual assessment.

Who it applies to

Entities with a defined cardholder data environment perimeter
SAQ D-Merchant and SAQ D for Service Providers; service providers also test segmentation under 11.4.6

What Requirement 11.4.3 asks for

Paraphrased from PCI DSS v4.0.1. Read the standard itself for the authoritative wording and testing procedures.

External penetration testing is performed per the entity's documented methodology.
Testing is performed at least once every 12 months.
Testing is repeated after any significant infrastructure or application upgrade or change.
The tester is a qualified internal resource or qualified third party with organisational independence.
The methodology in 11.4.1 must cover the whole CDE perimeter, application and network layers, and validation of segmentation controls.

Evidence an assessor expects

The documented penetration testing methodology required by 11.4.1
The most recent external test report with scope, findings and severity
Retest or remediation evidence for exploitable findings
Tester qualifications and a statement of organisational independence
Results retained for at least 12 months

Common mistakes

Submitting an automated vulnerability scan report as a penetration test.
No retest after a major migration or a new payment integration went live.
A test scope that stops at the perimeter and never validates segmentation.

Not sure whether Requirement 11.4.3 is in your scope?

Which requirements you must answer depends on the SAQ that applies to your environment. The free SAQ selector walks the official PCI SSC decision flow, records every answer and re-derives the recommendation server-side with a confidence score.

Paraphrased from PCI DSS v4.0.1 (PCI Security Standards Council). Independent summary; not endorsed by PCI SSC. Refer to the PCI SSC Document Library for the authoritative standard.