We use essential cookies to run this site. Analytics & marketing cookies load only with your consent — see our Cookie Policy and Privacy Policy.

PCI DSS v4.0.1 · Requirement 11 of 12

Requirement 11: Test Security of Systems and Networks Regularly

The requirement that generates the calendar: quarterly scans inside and out, annual penetration tests, segmentation validation — plus v4’s newcomers, authenticated internal scanning and tamper detection on payment pages.

Reviewed by Abhay Singh, PCI SSC-qualified QSA professional · CyberSigma is a PCI SSC-listed QSA company · Part of the Requirement 1–12 series

The controls that decide your assessment

11.2.1
Quarterly wireless detection

Authorised and unauthorised wireless access points identified at least quarterly — rogue-AP detection even where "we have no wireless".

11.3.1 + 11.3.1.2
Quarterly internal scans — authenticated

Internal vulnerability scans at least every three months, resolving high/critical findings with rescans; scans must be authenticated (credentialled) as of 31 March 2025. Non-high/critical vulns are managed per TRA (11.3.1.1).

11.3.2
Quarterly external ASV scans

External scans by a PCI SSC Approved Scanning Vendor every three months, with passing results and rescans after failures.

11.4.2–11.4.3
Annual internal and external pentests

Penetration testing per a documented methodology at least annually and after significant change — application and network layer.

11.4.5–11.4.6
Segmentation testing

Where segmentation isolates the CDE, its effectiveness is penetration-tested at least annually — every six months for service providers.

11.6.1
Payment-page change and tamper detection

A mechanism detects unauthorised changes to payment-page HTTP headers and script contents, alerting within a TRA-defined frequency (at least weekly). New in v4, effective 31 March 2025.

Control numbers reference PCI DSS v4.0.1 (June 2024). Verify wording against the standard itself — PCI SSC document library.

Where programmes actually fail

Clean ASV, empty internal-scan folder

External-only scanning is half the control; 11.3.1 internal quarterly scans with rescan evidence are sampled first.

Unauthenticated internal scans

Post-March-2025, scans without credentials (where feasible) fail 11.3.1.2 — and miss most of what matters.

Pentest scope excludes segmentation

A pentest that never attempts to cross segment boundaries cannot support 11.4.5; scope language decides this before testing starts.

Nothing watching the checkout page

11.6.1 requires tamper detection on payment pages — CSP reporting, integrity monitoring or equivalent, alerting at least weekly.

Evidence a QSA accepts

A policy document proves intent; configuration proves control. Bring these to the assessment:

  • Four quarters of internal scan reports with credentialled configuration and rescans
  • Four quarters of ASV scan attestations
  • Penetration-test reports: methodology, findings, retest, segmentation results
  • Wireless-detection records per quarter
  • Payment-page tamper-detection configuration and alert samples (11.6.1)

Requirement 11 FAQ

How often are penetration tests required?

At least annually and after significant changes (11.4.2/11.4.3); segmentation tests annually — every six months for service providers (11.4.6).

Must internal vulnerability scans be authenticated?

Yes, since 31 March 2025 (11.3.1.2) — with sufficient credentials, and documentation for systems that cannot accept them.

What is 11.6.1 asking for on payment pages?

A change-and-tamper-detection mechanism over payment-page headers and scripts (e.g. CSP violation reporting plus integrity monitoring), evaluated at least weekly — pairs with the script inventory in 6.4.3.

← Requirement 10: Logging & MonitoringRequirement 12: Governance & Programme

Requirement 11 in your environment

A PCI SSC-listed QSA firm can tell you in one session whether your controls will survive assessment — before the assessment.