PCI DSS Requirement 11.4 demands manual testing, not just a scan. We deliver compliant penetration tests for your retail, e-commerce, and payment-handling clients.
PCI DSS v4.0 doesn’t leave much room for ambiguity. If your client stores, processes, or transmits cardholder data, they need a penetration test of the cardholder data environment at least annually and after any significant change. The standard is explicit that this means manual testing, not just an automated scan.
Requirement 11.4 calls for documented methodology, internal and external testing, segmentation validation, and application-layer testing where in-scope apps exist. v4.0 also tightened expectations around the qualifications of the tester and the rigor of the methodology. A QSA reviewing the report will check for evidence that a real human, not a tool, exercised the controls protecting the CDE.
Don’t let your clients get caught by this. Migrating to a new payment processor, deploying a new web app in scope, or restructuring the CDE network all count as significant changes under v4.0 and require a fresh pentest. We make that affordable enough that your clients can stay compliant without blowing their security budget on one engagement per year.
You take the client conversation, we do the testing. Reports are fully white-labeled. We never approach your clients directly, and our pricing is structured so you can build a real margin on top of compliance work, turning a painful audit requirement into a profitable, recurring service line.
Partners can rebrand our compliance assessment reports as their own, or name MSP Pentesting as an attested third-party assessor.
Our MSP partners benefit from cost-effective compliance assessments, enabling them to maintain competitive pricing while ensuring audit readiness.
Partners benefit from swift scheduling and execution of pentests, ensuring quick turnaround without unexpected costs.
Tell us about your client's framework and we'll respond within 24 hours with pricing scoped to satisfy the auditor.