Penetration testing to validate that your cardholder data environment is properly isolated from out-of-scope networks — the segmentation testing PCI DSS requires to keep your scope and your audit under control.
If you rely on network segmentation to reduce PCI DSS scope, the standard requires you to prove that segmentation works — at least annually, and after any change. Segmentation penetration testing is that proof.
We test from out-of-scope networks toward your cardholder data environment, attempting to bypass the controls meant to isolate it. Deliverables are written to satisfy PCI DSS requirements 11.4.5 and 11.4.6, with remediation guidance and a free retest within 60 days.
Evidence that scope-reducing segmentation controls are effective.
The questions we're asked most about scope, cost, and timing.
A 30-minute scoping call costs nothing. A failed PCI audit costs considerably more.
Book a meeting Send an email