Most PCI penetration testing quotes arrive as a single number with no breakdown, which makes them impossible to compare and easy to inflate. Requirement 11.4 is made of separate tests with separate scopes, so the price should be too. This guide gives our fixed prices for each component, explains what moves the number, and lists the ways companies end up paying for the same test twice.
The requirement itself is explained in PCI DSS penetration testing requirements. Our full price list is on the pricing page.
The components of a PCI penetration test, priced
Requirement 11.4 asks for an external test, an internal test, application-layer testing, and segmentation testing. Here is what each costs from us, fixed before work begins, with the retest of remediated findings included in every price.
| Component | Requirement | Invadel fixed price, from | What it covers |
|---|---|---|---|
| External network penetration test | 11.4.3 | $4,200 | The CDE perimeter from the internet: exposed services, remote access, mail, DNS, edge devices |
| Internal network penetration test, including segmentation testing | 11.4.2 and 11.4.5 | $6,000 | From an assumed foothold inside the network: Active Directory, lateral movement, and every path from out-of-scope segments into the CDE |
| Web application penetration test | 11.4.1 (application layer) | $5,200 | The payment application or any application that touches cardholder data, every role, against the 6.2.4 vulnerability classes |
| API penetration test | 11.4.1 (application layer) | $4,000 | Payment and tokenization APIs, authorization from every role and tenant |
| Cloud penetration test | 11.4.2, 11.4.3, 11.4.5 for cloud-hosted CDEs | $6,800 | The cloud account: IAM, exposed workloads, storage, and segmentation between accounts and VPCs |
| Managed vulnerability scan (internal, 11.3.1) | 11.3 | $1,500 flat per scan | Analyst-validated internal scanning; not a substitute for the penetration test |
A typical merchant with one payment application, one office network and a segmented CDE buys the external test, the internal test with segmentation, and the web application test: $15,400 as a starting point, fixed, with retests included. A service provider adds the six-month segmentation retest under 11.4.6.
We do not run ASV scans (11.3.2); those come from a PCI SSC Approved Scanning Vendor, and the ASV scan vs penetration test guide explains why they are a separate purchase.
What moves the price up
The “from” prices cover a small CDE. These are the factors that raise a fixed quote, and we tell you which apply before the engagement starts:
- Number of external hosts and services. Ten internet-facing hosts and two hundred are different tests.
- Size of the internal network and number of segments. Segmentation testing is priced by the number of out-of-scope segments to test from and the number of paths to the CDE.
- Application size. Roles, workflows, integrations, and whether payments are embedded or redirected to a hosted page.
- Cloud complexity. Multiple accounts, regions and providers.
What does not move our price: the number of findings, the included retest, or a scoping call. The price is set from the scope form and fixed in writing.
The hidden costs of a cheap PCI test
- No retest included. 11.4.4 requires the fix to be verified by repeating the test. A quote without the retest is a quote for half the requirement; the retest arrives later as a second invoice.
- No segmentation test. The most commonly omitted component and the one that fails the RoC. If the quote does not say “segmentation” it probably does not include it.
- Scan sold as a test. An automated scan with a report template costs less because it is not a penetration test. Your QSA will notice.
- Day-rate estimates. An estimate of “8 to 12 days” is a price range of 50%. Ask for a fixed number.
- No methodology document. 11.4.1 requires one. If the vendor cannot produce it, you write it, or the QSA writes a finding.
- Tester qualifications not provided. Your QSA will ask; if the vendor has to be chased for them, the assessment slips.
How PCI penetration testing compares to the alternative
The average cost of a data breach in the United States reached $11.5 million in 2026, and the average in financial services was $6.3 million. (IBM Cost of a Data Breach Report 2026) Small and medium-sized enterprises averaged $264,000 per incident in insurer claims data, with $152,000 of that in crisis services. (NetDiligence Cyber Claims Study 2025) A complete 11.4 program at our prices costs a fraction of one incident’s forensics bill, before any card brand assessment or the cost of a failed RoC is counted.
Frequently asked questions
How often do we pay this? The external and internal tests are annual, plus after significant changes. Segmentation testing is annual for merchants and every six months for service providers. See how often you should do a penetration test.
Can we do one test that covers everything? The external, internal and application tests are different scopes with different starting points. They can be scheduled as one engagement, and usually are, but the report has to show each one separately for the QSA.
Does the price include the ASV scan? No. ASV scans are performed by PCI SSC Approved Scanning Vendors under a separate program and are a separate requirement (11.3.2).
What if we are an SAQ A merchant? Your scope is small and may not require a penetration test at all; check your SAQ and confirm with your acquirer. If you have any system in scope, the external test is usually the only component you need.
Can the components be booked together? Yes, and most PCI engagements are. The prices stay per component so the quote and the report both show the QSA which test covers which sub-requirement.
The short version
A complete PCI DSS 11.4 program for a typical merchant starts at $15,400 with us: external, internal with segmentation, and the web application, each with the retest included and each mapped to its sub-requirement in the report. Ask any other vendor to break their number down the same way. If you want ours in writing, scope a PCI test.
Written by
Invadel Team
Senior penetration testers writing from real engagements, the same team that scopes, tests, and reports for our clients. About Invadel →