PCI DSS 4.0 Gap Analysis: What to Fix Before Your QSA Arrives | Lorikeet Security Skip to main content
Back to Blog

PCI DSS 4.0 Gap Analysis: What to Fix Before Your QSA Arrives

Lorikeet Security Team August 17, 2026 12 min read

PCI DSS is the strictest of the common frameworks about one thing in particular: it does not treat penetration testing as optional. Requirement 11 names it directly. So a PCI gap analysis is not just about paperwork — it is about confirming that your cardholder data environment is scoped correctly and that the technical testing the standard mandates is actually happening. Get this wrong and your Qualified Security Assessor (QSA) finds it during the assessment, when it is expensive to fix.

PCI DSS 4.0 is fully in force. The transition from 3.2.1 is complete, and as of 31 March 2025 the previously "future-dated" 4.0 requirements became mandatory — things like more rigorous authentication, targeted risk analyses, and expanded testing expectations. A gap analysis mapped to 3.2.1, or to 4.0's early grace period, is measuring against a target that no longer exists.

Scope first: the cardholder data environment

Everything in PCI flows from scope. The cardholder data environment (CDE) — the systems that store, process, or transmit cardholder data, plus anything connected to them — defines what the assessment covers. The single highest-leverage output of a PCI gap analysis is an accurate, defensible scope and, where possible, network segmentation that shrinks it. A gap analysis that does not nail scope will either under-scope (a compliance failure waiting to happen) or over-scope (paying to secure and assess systems that never needed to be in).

The 12 requirements a PCI gap analysis covers

PCI DSS 4.0 organizes its controls into 12 requirements across six goals. A gap analysis walks each one against your environment:

Requirement 11: where penetration testing is mandatory

This is what sets PCI apart. Requirement 11 explicitly requires:

A gap analysis confirms whether your pentest program meets this bar: is it annual, is the scope the full CDE, does it test both layers, is segmentation validated, and — critically — are findings corrected and re-tested? A pentest that never re-tests its findings does not satisfy Requirement 11.

Common PCI gaps we find: a CDE scope that quietly grew and was never re-drawn, segmentation assumed but never tested, a penetration test that covered the app but not the internal network (or vice versa), exploitable findings closed on paper but never re-tested, missing targeted risk analyses under 4.0, and authentication that has not caught up to the 4.0 requirements now in force.

SAQ or ROC — the gap analysis tells you which world you are in

Depending on your merchant level and how you handle card data, you validate via a Self-Assessment Questionnaire (SAQ) or a full Report on Compliance (ROC) with a QSA. The gap analysis clarifies which applies and, for the SAQ path, which SAQ type fits your setup — a decision that dramatically changes how many of the 12 requirements you must satisfy. Getting this wrong means either doing far more work than required or attesting to the wrong thing.

How Lorikeet runs the PCI gap analysis and the pentest

We start with scope — mapping your CDE and identifying segmentation opportunities to shrink it — then run a gap analysis across all 12 requirements against PCI DSS 4.0 as it stands today, future-dated requirements included. For Requirement 11 we deliver the penetration testing the standard mandates: external and internal, network and application layer, plus segmentation testing, on our PTaaS platform with Lory's autonomous testing countersigned by a human pentester. Because we re-test remediated findings, the report demonstrates the correct-and-verify loop 11.3 requires. One coordinated engagement covers both the assessment readiness and the mandatory testing your QSA will expect.

Get PCI DSS-Ready — Gap Analysis + Required Pentest

Lorikeet Security scopes your cardholder data environment, runs a PCI DSS 4.0 gap analysis across all 12 requirements, and delivers the Requirement 11 penetration testing — including segmentation testing — your QSA will expect.

-- views
Link copied!
Lorikeet Security

Lorikeet Security Team

Penetration Testing & Cybersecurity Consulting

Lorikeet Security helps modern engineering teams ship safer software. Our work spans web applications, APIs, cloud infrastructure, and AI-generated codebases — and everything we publish here comes from patterns we see in real client engagements.

Lory waving

Hi, I'm Lory! Need help finding the right service? Click to chat!