Requirement 11: Test Security of Systems and Networks Regularly
The requirement that generates the calendar: quarterly scans inside and out, annual penetration tests, segmentation validation — plus v4’s newcomers, authenticated internal scanning and tamper detection on payment pages.
Reviewed by Abhay Singh, PCI SSC-qualified QSA professional · CyberSigma is a PCI SSC-listed QSA company · Part of the Requirement 1–12 series
The controls that decide your assessment
Control numbers reference PCI DSS v4.0.1 (June 2024). Verify wording against the standard itself — PCI SSC document library.
Where programmes actually fail
External-only scanning is half the control; 11.3.1 internal quarterly scans with rescan evidence are sampled first.
Post-March-2025, scans without credentials (where feasible) fail 11.3.1.2 — and miss most of what matters.
A pentest that never attempts to cross segment boundaries cannot support 11.4.5; scope language decides this before testing starts.
11.6.1 requires tamper detection on payment pages — CSP reporting, integrity monitoring or equivalent, alerting at least weekly.
Evidence a QSA accepts
A policy document proves intent; configuration proves control. Bring these to the assessment:
- Four quarters of internal scan reports with credentialled configuration and rescans
- Four quarters of ASV scan attestations
- Penetration-test reports: methodology, findings, retest, segmentation results
- Wireless-detection records per quarter
- Payment-page tamper-detection configuration and alert samples (11.6.1)
Requirement 11 FAQ
How often are penetration tests required?
At least annually and after significant changes (11.4.2/11.4.3); segmentation tests annually — every six months for service providers (11.4.6).
Must internal vulnerability scans be authenticated?
Yes, since 31 March 2025 (11.3.1.2) — with sufficient credentials, and documentation for systems that cannot accept them.
What is 11.6.1 asking for on payment pages?
A change-and-tamper-detection mechanism over payment-page headers and scripts (e.g. CSP violation reporting plus integrity monitoring), evaluated at least weekly — pairs with the script inventory in 6.4.3.
Requirement 11 in your environment
A PCI SSC-listed QSA firm can tell you in one session whether your controls will survive assessment — before the assessment.
