PCI DSS 4.0 Network Segmentation Pentesting: Proving CDE Isolation to Your QSA | Lorikeet Security Skip to main content
Back to Blog

PCI DSS 4.0 Network Segmentation Pentesting: Proving CDE Isolation to Your QSA

Lorikeet Security Technical Team September 23, 2026 11 min read PCI DSS & Network Security

Network segmentation is not strictly mandatory under PCI DSS, but without it, your entire corporate enterprise falls into audit scope. For any business processing card payments, failing to segment means every employee workstation, printer, Wi-Fi access point, and development server must meet the 300+ technical controls of PCI DSS.

To legally reduce audit scope, organizations segment their Cardholder Data Environment (CDE) using firewalls, VLANs, and cloud security groups. However, claiming segmentation on an architectural diagram is worthless in an audit. Under PCI DSS v4.0 Requirement 11.4, you must provide objective, empirical proof in the form of a Network Segmentation Penetration Test.

The QSA Standard of Proof: A Qualified Security Assessor (QSA) will not accept firewall configuration screenshots as proof of segmentation. The QSA must inspect an independent penetration test report proving that active port scans and exploit payloads originating from out-of-scope networks were blocked by segmentation boundaries.

Requirement 11.4.5 vs. 11.4.6: Merchants vs. Service Providers

PCI DSS v4.0 enforces different testing frequencies depending on your entity classification:

How a Legitimate Segmentation Pentest is Executed

A defensible segmentation penetration test must prove negative connectivity. Testers position assessment nodes across all out-of-scope zones and attempt to reach the CDE:

1. Source Zone Mapping

Identify every non-CDE network: corporate LAN, developer VLANs, guest networks, staging cloud VPCs, and third-party management subnets.

2. Exhaustive Port Scanning (TCP/UDP)

Execute comprehensive SYN scans and UDP sweeps targeting all IP addresses and services inside the CDE. Testers must verify that no unauthorized ports respond.

3. Route & Dual-Homed Host Analysis

Inspect jump boxes, bastion hosts, and CI/CD runners to ensure that dual-homed machines cannot be leveraged to pivot traffic into the cardholder environment.

4. Stateful Protocol Verification

Ensure that firewall rules do not allow established/related connection state table hijacking or DNS tunneling across egress boundaries.

Common Failures That Blow Audit Deadlines

During our segmentation assessments, Lorikeet Security frequently catches critical control failures:

  1. Permissive Outbound Egress: Allowing CDE database servers to initiate arbitrary outbound HTTP/S connections to the internet, creating reverse-shell vulnerability risks.
  2. Shared Active Directory Forests: Utilizing the same domain controller for both out-of-scope corporate laptops and sensitive CDE servers, which enables Kerberos ticket attacks to cross segmentation lines.
  3. Overly Broad Management Rules: Allowing full SSH (port 22) or RDP (port 3389) access from entire developer subnets rather than dedicated, MFA-locked bastions.

Book Your PCI DSS 4.0 Segmentation Pentest

Satisfy your QSA and protect cardholder data. Lorikeet Security provides accredited 6-month and annual segmentation penetration testing with guaranteed audit-defensible reporting.

-- views
Link copied!
Lorikeet Security

Lorikeet Security Team

Penetration Testing & Cybersecurity Consulting

Lorikeet Security helps modern engineering teams ship safer software. Our work spans web applications, APIs, cloud infrastructure, and AI-generated codebases — and everything we publish here comes from patterns we see in real client engagements.

Lory waving

Hi, I'm Lory! Need help finding the right service? Click to chat!