Short answer: VAPT for PCI-DSS means meeting Requirement 11's mandate for regular vulnerability scanning and penetration testing of your cardholder data environment. PCI-DSS requires both quarterly ASV external scans and at least annual internal and external penetration tests, including segmentation testing where used.
If your business stores, processes or transmits payment card data, PCI-DSS (the Payment Card Industry Data Security Standard) applies to you. Unlike some frameworks, PCI-DSS is prescriptive about security testing: it names specific activities, frequencies and conditions. This guide explains what Requirement 11 asks for, the difference between ASV scans and penetration tests, why segmentation testing matters, and where our services fit, honestly, in the PCI-DSS picture.
The cardholder data environment (CDE)
Everything in PCI-DSS revolves around the cardholder data environment (CDE): the people, processes and technology that store, process or transmit cardholder data, plus any connected systems. Defining your CDE accurately is the first step, because the scope of your testing depends on it. A common cost-control strategy is network segmentation, isolating the CDE from the rest of your network so fewer systems are in scope. If you rely on segmentation, PCI-DSS requires you to prove it works.
Requirement 11: testing security of systems and networks
PCI-DSS Requirement 11 covers regular testing of security systems and processes. The two headline activities are vulnerability scanning and penetration testing.
Vulnerability scanning (including ASV scans)
- Internal vulnerability scans must be run at a defined regular frequency (historically quarterly) and after significant change, with high-risk issues resolved and rescans confirming the fix.
- External vulnerability scans of internet-facing systems in scope must be performed at least quarterly, and after any significant change, by a PCI SSC Approved Scanning Vendor (ASV). To pass, scans must meet the ASV programme requirements.
Penetration testing
- External and internal penetration tests must be performed at least annually and after any significant infrastructure or application change.
- Testing must cover the CDE perimeter and critical systems, at both the network and application layers.
- If segmentation is used to reduce scope, segmentation controls must be tested to confirm isolation is effective, at least annually (and, for service providers, more frequently, typically every six months).
- Exploitable vulnerabilities found during a pentest must be corrected and the testing repeated to verify the fix.
ASV scans vs penetration testing: not the same thing
This is where many businesses get confused, so let us be precise.
| Aspect | ASV external scan | Penetration test |
|---|---|---|
| Nature | Automated vulnerability scan of external-facing systems | Manual, goal-oriented testing with exploitation |
| Who can perform it | Must be a PCI SSC Approved Scanning Vendor (ASV) | A qualified, independent tester (no ASV status required) |
| Frequency | At least quarterly and after significant change | At least annually and after significant change |
| Depth | Breadth: finds known vulnerabilities across many hosts | Depth: chains and exploits issues to prove real impact |
| Output | Pass/fail ASV scan report in a prescribed format | Narrative report with exploited findings and remediation |
Both are required, and they are complementary. ASV scans give regular, broad coverage of your external attack surface in a format the card brands accept. Penetration testing goes deeper, manually verifying whether a determined attacker could actually reach cardholder data, and it is the only way to satisfy the segmentation-testing and application-layer requirements meaningfully.
Honest positioning: we scope pentests, we are not an ASV
Here is the part we want to be completely straight about. Cyber Defence is not a PCI SSC Approved Scanning Vendor. The quarterly external ASV scans required by PCI-DSS must be performed by a vendor on the official ASV list, and we are not on that list. What we do provide is the penetration testing side of Requirement 11: manual internal and external pentests of your CDE, application-layer testing, and segmentation testing, delivered by qualified testers.
In a typical PCI-DSS programme, you would engage an ASV for the quarterly external scans and engage a penetration-testing partner like us for the annual (and post-change) internal/external pentest and segmentation validation. We will happily coordinate with your ASV so the two workstreams line up. We also make no claim of CERT-In empanelment; we are an ISO-certified, GeM-registered testing firm.
What "significant change" means for testing frequency
PCI-DSS repeatedly ties testing to "significant change," which trips up many teams. There is no universal definition, because it depends on your environment, but changes that typically qualify include: new server or component installations in or connected to the CDE; changes to network topology or firewall rules; upgrades or modifications to applications that handle cardholder data; adding or removing devices from the CDE; and moving to a new data centre or cloud environment. When any of these happen, you generally cannot wait for the next scheduled quarter or year, you need to scan and, for material changes, retest promptly. Building this trigger into your change-management process keeps you continuously compliant rather than scrambling before an assessment.
Merchant levels and SAQ vs ROC
How much testing scrutiny applies also depends on your merchant or service-provider level, which is driven by transaction volume. Larger merchants and service providers typically undergo a full Report on Compliance (ROC) assessed by a Qualified Security Assessor (QSA), while smaller merchants may validate via a Self-Assessment Questionnaire (SAQ). The specific SAQ type you qualify for determines which requirements, including which testing obligations, apply to you. Two practical takeaways: confirm your level and SAQ type early, because they shape your testing scope; and remember that even where a full pentest is not strictly mandated by your SAQ, application-layer testing is strongly advisable wherever you handle cardholder data directly, because that is where the most damaging breaches originate.
Scoping a PCI-DSS penetration test
A defensible PCI pentest for the CDE usually includes:
- External network testing of internet-facing systems that form or connect to the CDE.
- Internal network testing from inside the network, simulating a foothold.
- Application-layer testing of web apps and APIs that handle cardholder data (OWASP-based).
- Segmentation testing to confirm out-of-scope networks genuinely cannot reach the CDE.
- Remediation retesting to verify exploitable issues are fixed, which PCI requires.
How pentest findings map to a clean PCI report
A penetration test is only useful for PCI-DSS if it drives closure. PCI-DSS is explicit that exploitable vulnerabilities found during testing must be corrected and the testing repeated to confirm the fix. This is why a credible PCI pentest engagement is a cycle, not a one-off report. After the initial test, your team remediates the exploitable findings; the tester then retests to verify the fixes actually hold; and the final documentation package, comprising the original report, the remediation record and the retest confirmation, is what your QSA reviews. A report that lists critical exploited findings with no evidence they were resolved is not a compliance asset; it is an open question your assessor will pursue. Planning remediation time into your PCI calendar, and using a provider that includes retesting, keeps this from becoming a last-minute crisis.
How Cyber Defence supports PCI-DSS
Founded by Amit Kumar (CEH, CRTA) and based in Hisar, Haryana, Cyber Defence delivers manual VAPT across web, mobile, API, network and cloud. For PCI-aligned engagements we scope internal and external penetration tests, application-layer testing and segmentation validation, and every engagement includes a free retest of remediated findings plus a completion certificate that can serve as third-party evidence within a PCI-aligned review. We are ISO-certified and GeM-registered, and, to repeat the important caveat, we are not a PCI ASV and do not perform the quarterly external ASV scans; pair us with an ASV for that piece.
Useful next steps: build skills with our VAPT training, review VAPT services in Delhi and VAPT services in Haryana, and read our guides on VAPT cost in India and what a VAPT report contains.
FAQ
Does PCI-DSS require both scanning and penetration testing?
Yes. Requirement 11 mandates regular vulnerability scanning (including quarterly external ASV scans) and separate penetration testing at least annually and after significant change. They are different activities and both are required.
What is the difference between an ASV scan and a pentest?
An ASV scan is an automated external vulnerability scan that must be run by a PCI SSC Approved Scanning Vendor, at least quarterly. A penetration test is manual, exploitation-based testing, performed at least annually, that verifies whether an attacker could actually reach cardholder data.
Is Cyber Defence a PCI Approved Scanning Vendor?
No. We are not an ASV and cannot perform the mandatory quarterly external ASV scans. We provide the penetration-testing side of Requirement 11, including segmentation testing, and coordinate with your chosen ASV.
What is segmentation testing and why does it matter?
If you use network segmentation to keep systems out of PCI scope, PCI-DSS requires you to prove the segmentation works. Segmentation testing confirms that out-of-scope networks cannot reach the cardholder data environment, which keeps your scope, and cost, controlled.
How often must PCI penetration testing be done?
At least annually and after any significant infrastructure or application change. Service providers must validate segmentation more frequently, typically every six months.
Will your pentest report be accepted for our PCI assessment?
Our reports are structured with defined scope, recognised methodology, exploited findings, remediation guidance and retest evidence, which is what a QSA expects for the penetration-testing requirement. Your QSA makes the final compliance determination.
Need the penetration-testing pillar of PCI-DSS Requirement 11? Cyber Defence scopes internal, external and segmentation testing with free retest. Call +91-75175-72000 to plan your PCI pentest.

