info@cetonix.com +91 (966) 512-1196 Mon–Fri, 09:30–18:00 IST
HomeGRCPCI DSS

PCI DSS

PCI DSS v4.0.1 readiness, cardholder data environment scoping, and the Requirement 11.4 penetration testing your assessor will ask for.

The Payment Card Industry Data Security Standard (PCI DSS) is a global standard that protects cardholder data. It applies to any organization that stores, processes or transmits payment card information.

Compliance is mandated by the card brands through your acquirer. PCI DSS v4.0.1 is the only active version — v3.2.1 retired on 31 December 2024, and every requirement previously marked future-dated became mandatory on 31 March 2025.

Two roles are formally defined by the PCI Security Standards Council and cannot be performed by anyone else: a Qualified Security Assessor (QSA) signs the Report on Compliance and the Attestation of Compliance, and an Approved Scanning Vendor (ASV) performs the quarterly external scans under Requirement 11.3.2. Cetonix is neither a QSA nor an ASV. We do not sign Attestations of Compliance and we do not perform the quarterly ASV scans. What we do is get you ready for the assessment and deliver the Requirement 11.4 penetration testing, working alongside the QSA and ASV you appoint. If a vendor tells you they can certify your PCI DSS compliance without QSA registration, check their listing on the PCI SSC website before you sign anything.

What we deliver

  • Scoping of the cardholder data environment, including segmentation validation — usually the single biggest lever on the cost of your assessment
  • Gap assessment against the PCI DSS v4.0.1 requirements, with each gap rated and owned
  • Requirement 11.4.2 and 11.4.3 penetration testing — internal and external, at least every 12 months and after any significant change, following a documented methodology (see Penetration Testing)
  • Requirement 11.4.4 remediation and retesting of exploitable findings
  • Requirement 6.2 and 6.3 secure development and vulnerability management, including secure code review
  • Evidence preparation and SAQ support ahead of your QSA engagement

Scanning and penetration testing are separate obligations

Requirement 11.3 covers vulnerability scanning. Requirement 11.4 covers penetration testing. They are distinct requirements and an assessor will expect evidence of both. A scan report is not a penetration test, and any vendor that sells you one as the other is setting you up for a finding.

Who it is for

E-commerce merchants, payment service providers and gateways, SaaS platforms that touch cardholder data, and any service provider whose customers have placed them in PCI DSS scope.

Talk to us about certification or a penetration test

Tell us the standard, the framework or the application. We come back with scope, timeline and a fixed quote.