PCI DSS is the strictest of the common frameworks about one thing in particular: it does not treat penetration testing as optional. Requirement 11 names it directly. So a PCI gap analysis is not just about paperwork — it is about confirming that your cardholder data environment is scoped correctly and that the technical testing the standard mandates is actually happening. Get this wrong and your Qualified Security Assessor (QSA) finds it during the assessment, when it is expensive to fix.
PCI DSS 4.0 is fully in force. The transition from 3.2.1 is complete, and as of 31 March 2025 the previously "future-dated" 4.0 requirements became mandatory — things like more rigorous authentication, targeted risk analyses, and expanded testing expectations. A gap analysis mapped to 3.2.1, or to 4.0's early grace period, is measuring against a target that no longer exists.
Scope first: the cardholder data environment
Everything in PCI flows from scope. The cardholder data environment (CDE) — the systems that store, process, or transmit cardholder data, plus anything connected to them — defines what the assessment covers. The single highest-leverage output of a PCI gap analysis is an accurate, defensible scope and, where possible, network segmentation that shrinks it. A gap analysis that does not nail scope will either under-scope (a compliance failure waiting to happen) or over-scope (paying to secure and assess systems that never needed to be in).
The 12 requirements a PCI gap analysis covers
PCI DSS 4.0 organizes its controls into 12 requirements across six goals. A gap analysis walks each one against your environment:
- 1–2: network security controls and secure configuration (no vendor defaults).
- 3–4: protect stored account data and encrypt transmission across open networks.
- 5–6: anti-malware and secure systems/software development.
- 7–9: restrict access by need-to-know, authenticate access (including the strengthened 4.0 authentication rules), and restrict physical access.
- 10: log and monitor all access to system components and cardholder data.
- 11: test security of systems and networks regularly — this is the penetration-testing requirement.
- 12: maintain an information-security policy, including the new targeted risk analyses 4.0 introduced.
Requirement 11: where penetration testing is mandatory
This is what sets PCI apart. Requirement 11 explicitly requires:
- 11.3 — Penetration testing performed at least annually and after any significant change, covering both the external and internal perimeter of the CDE, at the network and application layers.
- 11.4 — Segmentation testing — if you rely on segmentation to reduce scope, you must prove the segmentation actually works, at least annually (and every six months for service providers).
- 11.3.x methodology, correction of exploitable findings, and re-testing to verify the fix.
A gap analysis confirms whether your pentest program meets this bar: is it annual, is the scope the full CDE, does it test both layers, is segmentation validated, and — critically — are findings corrected and re-tested? A pentest that never re-tests its findings does not satisfy Requirement 11.
Common PCI gaps we find: a CDE scope that quietly grew and was never re-drawn, segmentation assumed but never tested, a penetration test that covered the app but not the internal network (or vice versa), exploitable findings closed on paper but never re-tested, missing targeted risk analyses under 4.0, and authentication that has not caught up to the 4.0 requirements now in force.
SAQ or ROC — the gap analysis tells you which world you are in
Depending on your merchant level and how you handle card data, you validate via a Self-Assessment Questionnaire (SAQ) or a full Report on Compliance (ROC) with a QSA. The gap analysis clarifies which applies and, for the SAQ path, which SAQ type fits your setup — a decision that dramatically changes how many of the 12 requirements you must satisfy. Getting this wrong means either doing far more work than required or attesting to the wrong thing.
How Lorikeet runs the PCI gap analysis and the pentest
We start with scope — mapping your CDE and identifying segmentation opportunities to shrink it — then run a gap analysis across all 12 requirements against PCI DSS 4.0 as it stands today, future-dated requirements included. For Requirement 11 we deliver the penetration testing the standard mandates: external and internal, network and application layer, plus segmentation testing, on our PTaaS platform with Lory's autonomous testing countersigned by a human pentester. Because we re-test remediated findings, the report demonstrates the correct-and-verify loop 11.3 requires. One coordinated engagement covers both the assessment readiness and the mandatory testing your QSA will expect.
Get PCI DSS-Ready — Gap Analysis + Required Pentest
Lorikeet Security scopes your cardholder data environment, runs a PCI DSS 4.0 gap analysis across all 12 requirements, and delivers the Requirement 11 penetration testing — including segmentation testing — your QSA will expect.