Network segmentation is not strictly mandatory under PCI DSS, but without it, your entire corporate enterprise falls into audit scope. For any business processing card payments, failing to segment means every employee workstation, printer, Wi-Fi access point, and development server must meet the 300+ technical controls of PCI DSS.
To legally reduce audit scope, organizations segment their Cardholder Data Environment (CDE) using firewalls, VLANs, and cloud security groups. However, claiming segmentation on an architectural diagram is worthless in an audit. Under PCI DSS v4.0 Requirement 11.4, you must provide objective, empirical proof in the form of a Network Segmentation Penetration Test.
The QSA Standard of Proof: A Qualified Security Assessor (QSA) will not accept firewall configuration screenshots as proof of segmentation. The QSA must inspect an independent penetration test report proving that active port scans and exploit payloads originating from out-of-scope networks were blocked by segmentation boundaries.
Requirement 11.4.5 vs. 11.4.6: Merchants vs. Service Providers
PCI DSS v4.0 enforces different testing frequencies depending on your entity classification:
- Requirement 11.4.5 (Merchants): Penetration testing of segmentation controls must be performed at least once every 12 months, and after any significant change to segmentation controls.
- Requirement 11.4.6 (Service Providers): Third-party service providers must perform segmentation penetration testing at least once every six months, as well as after any modification to segmentation boundaries.
How a Legitimate Segmentation Pentest is Executed
A defensible segmentation penetration test must prove negative connectivity. Testers position assessment nodes across all out-of-scope zones and attempt to reach the CDE:
1. Source Zone Mapping
Identify every non-CDE network: corporate LAN, developer VLANs, guest networks, staging cloud VPCs, and third-party management subnets.
2. Exhaustive Port Scanning (TCP/UDP)
Execute comprehensive SYN scans and UDP sweeps targeting all IP addresses and services inside the CDE. Testers must verify that no unauthorized ports respond.
3. Route & Dual-Homed Host Analysis
Inspect jump boxes, bastion hosts, and CI/CD runners to ensure that dual-homed machines cannot be leveraged to pivot traffic into the cardholder environment.
4. Stateful Protocol Verification
Ensure that firewall rules do not allow established/related connection state table hijacking or DNS tunneling across egress boundaries.
Common Failures That Blow Audit Deadlines
During our segmentation assessments, Lorikeet Security frequently catches critical control failures:
- Permissive Outbound Egress: Allowing CDE database servers to initiate arbitrary outbound HTTP/S connections to the internet, creating reverse-shell vulnerability risks.
- Shared Active Directory Forests: Utilizing the same domain controller for both out-of-scope corporate laptops and sensitive CDE servers, which enables Kerberos ticket attacks to cross segmentation lines.
- Overly Broad Management Rules: Allowing full SSH (port 22) or RDP (port 3389) access from entire developer subnets rather than dedicated, MFA-locked bastions.
Book Your PCI DSS 4.0 Segmentation Pentest
Satisfy your QSA and protect cardholder data. Lorikeet Security provides accredited 6-month and annual segmentation penetration testing with guaranteed audit-defensible reporting.