← PCI DSS 4.0.1 · Req 11 — Test security regularly

11.4 — Penetration testing at least every 12 months

critical pen-testsecurity-testing

Requirement

A penetration-testing methodology is defined; internal and external penetration tests are performed at least once every 12 months and after any significant infrastructure or application change by a qualified, organisationally independent tester; exploitable vulnerabilities are corrected and retested; and segmentation controls are tested (every 12 months, or every six months for service providers).

What the engine looks for

Every group below must be satisfied — by an affirmative statement, not a plan, a hedge or a denial — for the control to count as covered. A term ending in … matches any word it begins. Supporting terms do not change the verdict — they raise confidence and distinguish a policy that names a mechanism from one that gestures at a category.

Required element 1 — any one of
penetration testpenetration testspenetration testingpen testpen testspentestpentests
Required element 2 — any one of
annual…every 12 months12 monthsonce a yearyearlyafter significant changeafter any significant changeevery six months
Supporting terms — specificity signals
11.4.111.4.311.4.5segmentationinternalexternalindependentretest
Contradiction markers

Finding any of these outranks coverage — a policy that admits the gap is worse than silence.

no penetration testing we have never had a penetration test

Equivalent controls elsewhere

Matched on shared topics. Satisfying this control usually moves these too.

FrameworkControlTitleShared topics
ISO 27001 A.8.29 Security testing in development and acceptance security-testing pen-test
GLBA 314.4(d) Continuous monitoring, or annual penetration tests and six-monthly vulnerability assessments pen-test security-testing
CCPA/CPRA Regs (cybersecurity audits) Annual independent cybersecurity audit security-testing