Segmentation Penetration Testing
PCIComplianceHubLast updated
Testing performed specifically to prove that the controls isolating the cardholder data environment from the rest of the network actually hold, as distinct from a general penetration test of the environment. PCI DSS requires it at least once every 12 months and after any change to segmentation controls or methods, with service providers required to test at least once every six months. If segmentation is being relied on to reduce scope and this testing fails, the scope reduction fails with it.
Applies to. Any entity relying on segmentation to keep systems out of scope. Not required where nothing is being excluded.
Example. From the office network a tester attempts to reach every CDE address on every port, and from a segment believed to be out of scope tries to reach any in-scope system. A single open path is a failed test.
Limits. At least every 12 months and after any change to segmentation controls or methods (11.4.5), at least every six months for service providers (11.4.6), following the entity's documented methodology (11.4.1), by a qualified internal resource or external third party with organisational independence, who need not be a QSA or ASV. A failed test does not merely produce a finding; it collapses the scope reduction until the path is closed and retested.
Sources. PCI DSS v4.0.1 (June 2024)