Home / Penetration Testing / PCI DSS Segmentation

PCI DSS
Segmentation Testing

Penetration testing to validate that your cardholder data environment is properly isolated from out-of-scope networks — the segmentation testing PCI DSS requires to keep your scope and your audit under control.

Overview

Prove your CDE is isolated.

If you rely on network segmentation to reduce PCI DSS scope, the standard requires you to prove that segmentation works — at least annually, and after any change. Segmentation penetration testing is that proof.

We test from out-of-scope networks toward your cardholder data environment, attempting to bypass the controls meant to isolate it. Deliverables are written to satisfy PCI DSS requirements 11.4.5 and 11.4.6, with remediation guidance and a free retest within 60 days.


Coverage

What we validate.

Evidence that scope-reducing segmentation controls are effective.

Methodologies: PCI DSS v4.0 Requirement 11.4 PTES NIST SP 800-115

FAQ

PCI DSS segmentation testing FAQ

The questions we're asked most about scope, cost, and timing.

How much does PCI DSS segmentation testing cost?
Segmentation testing typically starts around €2,500 and depends on the number of network segments and connection points to the CDE. Use our estimator for a tailored figure.
How often is segmentation testing required under PCI DSS?
At least every 12 months for merchants, and every six months for service providers, plus after any significant change to segmentation controls.
What is the difference between segmentation testing and a full PCI penetration test?
Segmentation testing validates that out-of-scope networks cannot reach the CDE. A full PCI penetration test also tests the in-scope systems. Many clients need both.
Will the report satisfy our QSA?
Yes — reports are written to evidence PCI DSS requirements 11.4.5 and 11.4.6 and are designed to be handed straight to your QSA.
Do you also help with broader PCI DSS compliance?
Yes — see our PCI DSS compliance service for gap analysis, SAQ support, and remediation.
What do you need to scope segmentation testing?
A network diagram showing the CDE and surrounding segments, plus the segmentation controls in place. We test from out-of-scope toward the CDE.
How does this differ from a PCI penetration test?
Segmentation testing proves isolation of the CDE; a full PCI penetration test also tests the in-scope systems. Requirement 11.4 expects both.
Will the report name the PCI requirements?
Yes — it is mapped to PCI DSS 11.4.5 and 11.4.6 so your QSA can use it directly.
How often do we need it?
At least annually for merchants and every six months for service providers, plus after segmentation changes.
Can you also help with full PCI compliance?
Yes — see our PCI DSS compliance service for gap analysis, SAQ/RoC support, and remediation.

Related services

Explore more.

Ready to validate your segmentation?

A 30-minute scoping call costs nothing. A failed PCI audit costs considerably more.

Book a meeting Send an email