Skip to main content
Home/Services/PCI-DSS Driven Penetration Testing
Security Testing

PCI-DSS Driven Penetration Testing

Required penetration testing for PCI compliance

PCI-DSS v4.0 PA-DSS PCI P2PE Payment Card Standards
engagement log PCI-DSS Driven Penetration Testing testing
day 01scopetargets confirmed · rules of engagement signedagreed
day 01reconattack surface mappedcomplete
day 02findingNetwork Segmentation Failurescritical
day 03findingUnencrypted Cardholder Datahigh
day 04triagereviewed and countersigned by a Lorikeet pentesterpublished
day 04delivertickets opened in your tracker201
afterretestfixes verified · included in scopeno charge
retest included human countersigned report your auditor accepts
2-3 weekstypical duration $11,500fixed scope, from 8deliverables 8methodology stages
Scope

What this engagement covers

The service

PCI-DSS Requirement 11.3 mandates annual penetration testing by a qualified assessor. Our PCI-DSS penetration testing meets all Payment Card Industry requirements and provides documentation needed for QSA validation and compliance reporting.

What we test

We test all systems in your cardholder data environment (CDE) including external networks, internal network segmentation, web applications that handle card data, wireless networks, and all systems connected to the CDE. Testing validates PCI security requirements are properly implemented.

Method

How we run it

Conducted by PCI-certified professionals, our testing follows PCI Penetration Testing Guidance and includes all required components. We validate network segmentation, test for CDE vulnerabilities, assess application layer security, and provide detailed remediation guidance to achieve compliance.

01

Cardholder data environment identification

02

External penetration testing

03

Internal penetration testing

04

Network segmentation validation

05

Application layer security testing

06

Wireless security assessment (if applicable)

07

Social engineering testing

08

Remediation and retesting

Deliverables

What you receive

Findings land in your tracker as you go, not only in a PDF at the end. Retest is in scope, not a change order.

  • PCI-DSS compliant penetration test report
  • ASV scan results and attestation
  • Network segmentation validation
  • Cardholder data flow analysis
  • Vulnerability remediation tracking
  • Retest validation report
  • QSA-ready documentation package
  • Attestation of Compliance (AOC) support
Typical results

What we usually find

The issues this engagement surfaces most often. Yours will differ, but this is the shape of it.

Network Segmentation Failures Unencrypted Cardholder Data Weak Authentication Controls Missing Security Patches SQL Injection in Payment Applications Inadequate Access Controls Wireless Security Weaknesses Logging and Monitoring Gaps
Fit

Who this is for

E-commerce Merchants
Payment Service Providers
Payment Gateways
Retail Organizations
Hospitality Industry
Financial Institutions
Standards this supports

Findings are mapped to PCI-DSS v4.0, PA-DSS, PCI P2PE, Payment Card Standards, so the report drops into an audit package rather than needing to be translated first. If you need the readiness work behind one of those, that is a separate engagement.

Next

Scope it in one call

Tell us what is in scope and we come back with a fixed price and a start date. No discovery-call maze, no hourly estimate that moves.

Lory waving

Hi, I'm Lory! Need help finding the right service? Click to chat!