Requirement 11: Test Security of Systems and Networks Regularly

PCI DSS v4.0.1 Requirement 11: vulnerability scanning cadence, ASV scans, penetration testing scope, and the 11.6.1 payment page change detection control.

Requirement 11 is where the standard asks you to attack yourself on a schedule and act on what you find.

PCI DSS v4.0.1 breaks this requirement into 6 sections containing 21 individual controls.

What this requirement is actually asking

11.3.1 requires internal vulnerability scans at least every three months, with high-risk and critical findings resolved and a rescan confirming it. 11.3.2 requires external scans on the same cadence performed by a PCI SSC Approved Scanning Vendor (ASV). A formal accreditation, and the scan is only valid if the vendor holds it.

11.6.1 is the second anti-skimming control. Payment page HTTP headers and script content are monitored for unauthorised modification, at least weekly. It pairs with 6.4.3: 6.4.3 authorises what should be there, 11.6.1 detects when that changes. Both became mandatory on 31 March 2025.

Penetration testing (11.4) is annual and after significant change, and must include segmentation testing where segmentation is used to reduce scope. Service providers test segmentation every six months.

Does it apply to you?

All in-scope systems. If you rely on segmentation to reduce scope, the segmentation itself becomes a test target.

The controls

Requirement 11 contains 21 controls across 6 sections. Each links to its own page with the requirement in full and the testing procedures an assessor uses to verify it.

11.1: Governance for security testing

Control What it requires Guidance
11.1.1 All security policies and operational procedures that are identified in Requirement 11… Yes
11.1.2 Roles and responsibilities for performing activities in Requirement 11 are documented… Yes

11.2: Detecting unauthorised wireless access points

Control What it requires Guidance
11.2.1 Authorized and unauthorized wireless access points… Yes
11.2.2 An inventory of authorized wireless access points is maintained… Yes

11.3: Internal and external vulnerability scanning, including ASV scans

Control What it requires Guidance
11.3.1 Internal vulnerability scans… Yes
11.3.1.1 All other applicable vulnerabilities… Yes
11.3.1.2 Internal vulnerability scans are performed via authenticated scanning… Yes
11.3.1.3 Internal vulnerability scans are performed after any significant change… Yes
11.3.2 External vulnerability scans… Yes
11.3.2.1 External vulnerability scans are performed after any significant change… Yes

11.4: Penetration testing, including segmentation validation

Control What it requires Guidance
11.4.1 A penetration testing methodology is defined, documented, and implemented by the entity… Yes
11.4.2 Internal penetration testing is performed… Yes
11.4.3 External penetration testing is performed… Yes
11.4.4 Exploitable vulnerabilities and security weaknesses found during penetration testing… Yes
11.4.5 If segmentation is used to isolate the CDE from other networks… Yes
11.4.6 Service providers: If segmentation is used to isolate the CDE from other networks… Yes
11.4.7 Multi-tenant service providers support their customers for external penetration testing per… Yes

11.5: Intrusion detection and file integrity monitoring

Control What it requires Guidance
11.5.1 Intrusion-detection and/or intrusion-prevention techniques are used to detect and/or prevent… Yes
11.5.1.1 Service providers: Intrusion-detection and/or intrusion-prevention techniques detect, alert on/prevent… Yes
11.5.2 A change-detection mechanism (for example, file integrity monitoring tools)… Yes

11.6: Detecting unauthorised change to payment pages (new in v4)

Control What it requires Guidance
11.6.1 A change- and tamper-detection mechanism… Yes

Evidence your assessor will ask for

  • Four consecutive quarters of passing ASV scan reports, plus internal scan output on the same cadence
  • Rescan evidence showing high-risk findings were resolved, not just recorded
  • A penetration test report scoped to the CDE, with retest evidence for findings
  • Change-detection alerts and their disposition for payment pages

Where this commonly fails

  • Assuming any vulnerability scanner satisfies 11.3.2. It must be an ASV, and the ASV must be listed by PCI SSC
  • Scans that pass because the scanner could not reach the target
  • Treating 11.6.1 as covered by a generic uptime monitor

An important limitation

PCIComplianceHub is not an Approved Scanning Vendor. ASV scans under 11.3.2 must be performed by a vendor listed on the PCI SSC website; our tooling supports your internal testing and evidence gathering, and does not substitute for an ASV scan.

Official source

This page is original commentary. It cites requirement identifiers and the official requirement title, and does not reproduce the text of the standard. For the authoritative wording, including each testing procedure and the customized approach objective, download PCI DSS v4.0.1 (June 2024) from the PCI Security Standards Council document library.

PCI DSS is a registered standard of the PCI Security Standards Council, LLC, which does not endorse this site.