PCI DSS Requirement 11.4 asks for a real penetration test, not an ASV scan. We deliver it for your retail, ecommerce and payment-handling clients, under your brand.
PCI DSS penetration testing leaves very little room for interpretation. If your client stores, processes or transmits cardholder data, Requirement 11.4 calls for external and internal penetration testing of the cardholder data environment at least once every 12 months and after any significant change. The current standard is PCI DSS v4.0.1, which became the sole active version after v4.0 was retired at the end of 2024, so a report written against an older version is a conversation you do not want to have with a QSA.
This is the single most common misunderstanding, and it costs clients money and time. PCI DSS keeps the two in separate requirements on purpose.
A passing ASV scan does not evidence a penetration test, and a penetration test does not replace the quarterly scans. Your client needs both, and a QSA will ask for both separately.
Requirement 11.4 breaks down into sub-requirements a QSA will work through one at a time: a defined and documented testing methodology, internal testing, external testing, correction of exploitable findings followed by a retest, and segmentation testing to prove that out-of-scope networks are genuinely isolated from the CDE. Service providers and multi-tenant environments carry extra segmentation testing obligations on a shorter cycle. v4.0.1 also tightened expectations around tester qualification and the rigor of the methodology, so the assessor is checking who tested as closely as what they found.
Do not let your clients get caught by this one. Migrating to a new payment processor, deploying a new in-scope web application, or restructuring the CDE network all count as significant changes and all require fresh testing. We price it so your client can stay compliant through the year instead of blowing the entire security budget on one annual engagement.
You take the client conversation, we do the testing. Reports are fully white-labeled. We never approach your clients directly, and our pricing is structured so you can build a real margin on top of compliance work, turning a painful audit requirement into a profitable, recurring service line.
Partners can rebrand our compliance assessment reports as their own, or name MSP Pentesting as an attested third-party assessor.
Our MSP partners benefit from cost-effective compliance assessments, enabling them to maintain competitive pricing while ensuring audit readiness.
Partners benefit from swift scheduling and execution of pentests, ensuring quick turnaround without unexpected costs.
Tell us about your client's framework and we'll respond within 24 hours with pricing scoped to satisfy the auditor.