Skip to Content

Discover Our Newest Resources Resource Center

Dark teal and black gradient

Webinar

PCI Compliance and Pen Testing: Fundamental Keys to Success

PCI Compliance is no longer a checkbox exercise—it’s a critical component of protecting cardholder data in today’s evolving threat landscape. And with PCI DSS 4.0 introducing new requirements and complexities, many organizations are navigating fresh challenges when it comes to compliance and Penetration Testing.

In this expert-led webinar, Tevora’s cybersecurity leaders—Clayton Riness, Kevin Dick, and Mikayla Bartell—break down the biggest areas of confusion around PCI 4.0 and how Penetration Testing plays a crucial role in ensuring both compliance and security. Drawing from real-world experience, they’ll highlight practical insights and strategies to help organizations stay ahead of emerging requirements.

Key Takeaways:

  • Common areas of confusion with PCI 4.0 requirements
  • How PCI Compliance and Penetration Testing reinforce each other
  • Ways to align Penetration Testing with PCI strategy for stronger outcomes
  • Frequent issues Pen Tests uncover that impact compliance New and emerging tactics in Penetration Testing tied to PCI 4.0 updates

Whether you’re updating your current program or preparing for your first PCI 4.0 assessment, this session will give you actionable insights to strengthen your compliance efforts.

PCI Compliance and Pen Testing: Fundamental Keys to Success

PCI compliance and penetration testing are often discussed together, but many organizations still struggle to understand where compliance requirements end and security testing begins.

In this webinar, Clayton Reiness (Principal Consultant) sat down with Mikayla Bartell (Manager, Payments Practice and QSA) and Kevin Dick (Senior Director, Threat Practice) to unpack the fundamentals of PCI DSS 4.0 penetration testing requirements, vulnerability scanning, segmentation testing, and common misconceptions organizations face when preparing for assessments.

Why PCI and Penetration Testing Go Hand-in-Hand

Clayton Reiness: Organizations frequently say, “I need a penetration test for PCI compliance.” But there’s often confusion about what PCI actually requires.

Mikayla Bartell:
PCI DSS requires organizations to regularly test the security of systems and networks under Requirement 11. Depending on the environment, this can include several different types of testing:

  • External penetration testing
  • Internal penetration testing
  • Segmentation penetration testing (when segmentation is used to reduce scope)

Each serves a different purpose.

External Penetration Testing

Focuses on:

  • Internet-facing systems
  • External network perimeters
  • Systems connected to the Cardholder Data Environment (CDE)

Internal Penetration Testing

Focuses on:

  • Internal systems and networks
  • Testing from within trusted environments
  • Testing from inside and into the CDE

Segmentation Testing

Validates that segmentation controls actually work and prevent out-of-scope systems from impacting the CDE.

PCI DSS 4.0: A Bigger Focus on the CDE

One notable PCI DSS 4.0 change is the requirement to perform testing from within the Cardholder Data Environment itself.

Kevin Dick:
Initially, many expected this requirement to reveal significant weaknesses inside CDEs. Surprisingly, most environments tested have been relatively well hardened.

The bigger challenge has often been logistical:

  • Obtaining testing access to highly protected environments
  • Coordinating testing without disrupting operations
  • Ensuring testers can reach the systems that require validation

The good news is that many organizations have invested significant effort protecting their “crown jewels,” resulting in fewer critical findings than expected.

What Segmentation Really Means

Segmentation remains one of the most misunderstood areas of PCI.

Clayton: Many organizations hear “segmentation” and assume it means no connectivity whatsoever.

Mikayla:
That is not the PCI definition.

Segmentation means that systems outside the CDE:

Cannot impact the security of the CDE if they become compromised.

This allows for legitimate business connections between environments, provided security controls prevent a compromise from spreading into PCI systems.

The goal is risk containment—not necessarily complete isolation.

How Segmentation Testing Works

Kevin:
For traditional PCI segmentation testing, the goal is generally to validate that:

  • Out-of-scope networks cannot access the CDE
  • Network controls function as designed
  • Segmentation boundaries remain intact

The baseline segmentation test is not an exploitation exercise.

Instead, it largely involves:

  • Network validation
  • Port analysis
  • Connectivity testing

However, during a full penetration test, testers may go further by attempting to chain vulnerabilities together to determine whether segmentation protections can be bypassed through real-world attack paths.

Understanding PCI Scope: More Than Just the CDE

One of the most important concepts discussed during the session was PCI scoping.

Mikayla: Organizations frequently confuse “out of the CDE” with “out of scope.”

There are actually three categories:

1. Cardholder Data Environment (CDE)

Systems that:

  • Store cardholder data
  • Process cardholder data
  • Transmit cardholder data

2. PCI Scope (Broader Than the CDE)

Includes:

  • Systems with administrative access to the CDE
  • Security-impacting systems
  • Authentication services
  • Connected systems capable of affecting PCI security

3. Out-of-Scope Systems

Systems that are properly segmented and cannot impact CDE security.

Understanding these distinctions is critical because many organizations underestimate what must be assessed.

PCI DSS 4.0 and Multi-Tenant Applications

PCI DSS 4.0 introduced additional scrutiny around logical separation, especially for multi-tenant service providers.

Mikayla:
Organizations operating multi-tenant environments must now demonstrate that one customer cannot gain access to another customer’s data.

Testing may include validation of:

  • Authorization controls
  • Application logic
  • Tenant isolation
  • Role segregation

For cloud-native and SaaS providers, these requirements have become increasingly important.

PCI Penetration Testing in Cloud Environments

As organizations migrate to AWS, Azure, and Google Cloud, traditional notions of infrastructure are changing.

Kevin:
Cloud testing introduces unique challenges:

  • Serverless environments
  • Lambda functions
  • Dynamic IP addresses
  • Ephemeral infrastructure
  • API-driven architectures

Rather than focusing solely on fixed infrastructure, testing increasingly evaluates:

  • Cloud service configurations
  • Identity controls
  • External exposure
  • Architectural security

When appropriate, organizations may provide auditors with read-only cloud access to facilitate deeper analysis and improved visibility.

What Makes a Good PCI Penetration Test?

Organizations often submit third-party testing reports as part of PCI assessments.

What are assessors looking for?

Clear Methodology

The report should document:

  • Scope
  • Testing techniques
  • Methodology used
  • Systems reviewed

Qualified Testers

PCI requires testers to demonstrate:

  • Independence
  • Appropriate qualifications
  • Relevant expertise

Comprehensive Coverage

Mikayla:
One major red flag is receiving a penetration test report with no findings whatsoever.

No environment is perfect.

Even if findings are low risk, assessors generally expect evidence that meaningful testing occurred.

Does PCI Require Destructive Testing?

A common misconception is that penetration testers attempt to break environments.

Kevin:
PCI does not require destructive testing.

Testers are not attempting to:

  • Crash systems
  • Delete databases
  • Overload infrastructure

Instead, testing focuses on identifying weaknesses that attackers could exploit without impacting business operations.

One example of a controlled testing activity is password spraying, which mirrors real-world attacker behavior but is carefully managed to minimize disruption.

Production vs. Non-Production Testing

Can organizations perform testing in non-production environments?

The answer is often yes.

Application Testing

For application assessments:

  • UAT environments
  • Development environments
  • Replica environments

are commonly used if they accurately reflect production configurations.

Network Testing

For network penetration testing, however, assessors generally need visibility into the actual production perimeter because implementation details matter.

Internal vs. External Vulnerability Scanning

The panel also discussed another commonly misunderstood requirement: vulnerability scanning.

Internal Vulnerability Scans

Organizations must conduct internal scans regularly and, under PCI DSS 4.0, use authenticated scanning where technically feasible.

Authenticated scans provide significantly deeper visibility than traditional unauthenticated scans.

External Vulnerability Scans

External scans must be performed by an:

Approved Scanning Vendor (ASV)

These scans uniquely evaluate PCI-specific requirements and may identify compliance issues that traditional vulnerability scanners would overlook.

What Happens If You Miss a Quarterly Scan?

PCI requires vulnerability scanning at defined intervals.

However, mistakes happen.

Michaela:
Organizations generally have two options:

Compensating Controls

If alternative controls achieve the intent of the requirement, compliance may still be maintained.

Documented Exception Process

PCI now provides mechanisms for handling exceptional circumstances, provided organizations:

  • Document the issue
  • Correct the process failure
  • Prevent recurrence

The key is demonstrating ongoing compliance and operational control.

Can Organizations Perform Their Own Penetration Tests?

PCI allows internal personnel to conduct penetration testing under certain conditions.

However, significant requirements apply.

The tester must be:

  • Organizationally independent
  • Qualified and experienced
  • Separate from the systems being evaluated

Mikayla:
In practice, most organizations choose third-party testers because penetration testing requires specialized expertise and ongoing exposure to evolving attack techniques.

Why Annual Testing Still Matters

Some organizations argue:

“Nothing has changed since last year.”

The panel disagreed.

New Threats Emerge Continuously

Kevin:
Even if infrastructure remains unchanged:

  • Attack techniques evolve
  • Vulnerabilities are discovered
  • Tools improve

The methods used by testers today are significantly different than those used just a few years ago.

Annual testing helps ensure organizations stay ahead of emerging attack paths.

Endpoint Detection and Response (EDR): What Works?

The discussion closed with a question about endpoint security technologies.

While the panel avoided vendor endorsements, Kevin highlighted the value of mature EDR programs.

Key observations:

  • Effective EDR solutions raise detection rates significantly
  • Modern EDR tools make traditional attack techniques much harder to execute
  • Alerting and monitoring are often more important than the agent itself

The most effective solution is one that:

  • Detects threats
  • Escalates alerts appropriately
  • Reaches the right personnel quickly

As Kevin noted:

“It doesn’t help if the EDR identifies the attack if nobody sees the alert.”

Final Takeaways

PCI penetration testing should not be viewed as a compliance burden alone.

Done properly, it provides organizations with valuable insight into:

  • Security weaknesses
  • Segmentation effectiveness
  • Vulnerability management gaps
  • Emerging attack paths

Key recommendations from the panel included:

  • Don’t confuse PCI scope with the CDE alone.
  • Treat segmentation as a security control, not just a compliance exercise.
  • Use penetration testing to improve security, not simply satisfy requirements.
  • Cast a wider net when scoping assessments.
  • Continuously reassess environments, even if they appear unchanged.

Ultimately, PCI penetration testing is at its most valuable when it helps organizations identify risks before an attacker does—and that benefit extends well beyond compliance.

Authors