PCI DSS is the one major framework that requires penetration testing by name, in detail, on a schedule. Requirement 11.4 of PCI DSS v4.0.1 spells out a documented methodology, internal and external tests at least once every twelve months and after significant changes, correction and retest of exploitable findings, and segmentation testing on its own clock. That precision makes the buying decision simpler than for SOC 2: the tester either covers every line of 11.4 in a way your Qualified Security Assessor accepts, or you are buying the test twice.
This list is written by a penetration testing company, so Invadel is first and this is our site. Descriptions of other firms are limited to what they publicly say about themselves, with no prices, because none publish any. Ours are on the pricing page.
What Requirement 11.4 actually requires
- 11.4.1 A documented penetration testing methodology, covering the entire cardholder data environment perimeter and critical systems, testing from inside and outside the network, application-layer and network-layer testing, and review of threats and vulnerabilities from the last twelve months.
- 11.4.2 Internal penetration testing at least once every twelve months and after any significant infrastructure or application change, by a qualified internal resource or a qualified external third party with organizational independence.
- 11.4.3 External penetration testing on the same cadence and with the same independence requirement.
- 11.4.4 Exploitable vulnerabilities and security weaknesses found are corrected and the corrections verified by repeating the test.
- 11.4.5 Where segmentation isolates the cardholder data environment, penetration tests on the segmentation controls at least once every twelve months and after changes, confirming the controls are operational and effective.
- 11.4.6 For service providers, segmentation testing at least once every six months.
- 11.4.7 Multi-tenant service providers support their customers’ external penetration testing.
Requirement 11.3 sits alongside: internal vulnerability scans at least quarterly and external scans by a PCI SSC Approved Scanning Vendor at least quarterly. A penetration test does not replace those scans, and an ASV scan is not a penetration test. Our PCI DSS penetration testing page and PCI compliance checklist cover the rest of the standard.
Who counts as “qualified” and “independent”
PCI DSS does not require a specific certification. It requires that the tester is qualified and organizationally independent of the systems under test; your QSA will ask for evidence of both. An internal team can qualify if it is genuinely independent of the CDE’s owners, which is why most merchants and service providers use an outside firm and file the firm’s qualifications with the report.
The best PCI penetration testing companies in 2026
1. Invadel
Best for: fixed-price 11.4 coverage with the QSA’s evidence built in.
Our PCI engagement covers the internal test, the external test, the application layer and the segmentation test as separate line items, each mapped to its 11.4 sub-requirement in the report, with the methodology documented for 11.4.1 and the retest of remediated findings included for 11.4.4. Tester qualifications and an independence statement are part of the attestation letter your QSA receives. Prices are published; see the pricing page and the PCI DSS penetration testing page. The honest limitation: we are not a QSA and do not run ASV scans. We produce the penetration test evidence the QSA reviews.
2. Trustwave
Best for: large merchants and processors that want testing from a firm with a long PCI history.
Trustwave has been a PCI Qualified Security Assessor and a fixture of the payments security market for many years, with its SpiderLabs research and testing team delivering penetration testing at scale.
3. Coalfire
Best for: payment processors and service providers that need PCI QSA work and testing under one roof.
Coalfire is a PCI QSA and FedRAMP 3PAO with an offensive security practice, a common choice for large service providers whose assessment and testing programs run together.
4. Schellman
Best for: companies combining a PCI RoC with SOC 2 and ISO 27001.
A CPA firm, certification body and PCI QSA, often selected when the PCI assessment is one of several attestations drawn from the same evidence.
5. A-LIGN
Best for: mid-market companies pairing PCI with other frameworks.
A PCI QSA and licensed CPA firm with a penetration testing practice alongside its assessment work, separated for independence.
6. VikingCloud
Best for: merchants that want ASV scanning and PCI assessment from a payments-focused provider.
VikingCloud is a PCI QSA and Approved Scanning Vendor with a large base of merchant customers through acquirers and payment processors.
7. NetSPI
Best for: banks and large enterprises running PCI testing as a continuous program.
An enterprise penetration testing company with a large bench and delivery platform, strong in banking and other regulated industries with many in-scope systems.
8. Kroll
Best for: regulated enterprises that want testing from a global risk brand.
Kroll’s cyber practice pairs penetration testing with a large incident response operation, a fit where legal and compliance stakeholders all need to approve the vendor.
9. Rapid7
Best for: organizations already running the Rapid7 platform for vulnerability management.
Best known for vulnerability management products, Rapid7 also runs a penetration testing services arm; bundling can be efficient where the scanning already runs on its platform.
10. Packetlabs
Best for: manual-first internal and external testing with detailed reporting.
A manual-first Canadian firm whose infrastructure and application testing is written up for compliance audiences. See Invadel vs Packetlabs.
How to buy PCI testing without doing it twice
- Give the tester the CDE diagram and the segmentation design before scoping. Segmentation testing is the item most often missed, and it is the one that fails a RoC.
- Confirm which sub-requirements the report will cite. If the vendor cannot map findings to 11.4.2, 11.4.3 and 11.4.5 by number, the QSA will do it for them, slowly.
- Ask about the retest. 11.4.4 makes the retest part of the requirement, not an upsell.
- Ask for the qualifications and independence statement up front. Your QSA will.
- Fix the price. PCI scopes are well defined, which means a fixed price is reasonable to expect. See how much a penetration test costs.
Frequently asked questions
Does an ASV scan satisfy the penetration testing requirement? No. Requirement 11.3 (scans) and 11.4 (penetration testing) are separate requirements with separate evidence.
How often does PCI DSS require penetration testing? Internal and external at least every twelve months and after significant changes; segmentation testing every twelve months for merchants and every six months for service providers. See how often you should do a penetration test.
Do we need to test if we use a hosted payment page? Scope shrinks with SAQ type, but any system that could affect the security of the cardholder data environment stays in scope, and your QSA or acquirer decides where the line is.
Can our internal team do it? If it is qualified and organizationally independent of the systems tested, yes. Most companies use an outside firm to remove the independence question.
The short version
Hire a tester that covers every line of 11.4 by number, includes the retest, and hands your QSA an attestation letter with qualifications and independence on it. If that is what you want at a published price, scope a PCI penetration test.
Written by
Invadel Team
Senior penetration testers writing from real engagements, the same team that scopes, tests, and reports for our clients. About Invadel →