Skip to content

E-commerce and retail

Penetration Testing for E-commerce and Retail Companies

Online retailers run checkout, loyalty, and customer accounts on storefronts that attackers probe every hour of the day. Invadel tests the storefront, its APIs, and the cardholder data environment at a fixed price, with a free retest and evidence for PCI DSS Requirement 11.4.

OSCP & OSCE3 certified testers150+ years combined experienceOnboarding within 24 hoursFree retest includedOur methodology
DTCCCity National BankBrewDogLuluEmeriaIP Telecom

The stakes

Why e-commerce gets tested differently

Retail attackers are patient and automated. They skim card data through scripts injected into the checkout page and stuff credentials against the login to take over accounts holding stored cards. Promotions, gift cards, and return flows are abused for direct profit. Behind the storefront, the order management system and the integrations with payment, shipping, and marketing platforms offer quieter routes to the same customer data.

Any merchant that accepts cards answers to PCI DSS. Requirement 11.4 calls for penetration testing of the cardholder data environment, including segmentation testing where scope has been reduced. E-commerce merchants whose site affects the payment page carry application-layer obligations too. Marketplaces and platform partners send their own security requirements, and customers in New York are covered by the SHIELD Act’s reasonable safeguards standard.

A scanner run against a storefront produces a list of library versions and misses the findings that cost money. A coupon that stacks under a race condition, a price altered between cart and payment, a payment provider webhook trusted without a signature check. Retail testing needs testers who understand the order lifecycle and a scope that includes the CDE, not just the homepage.

What we test

The systems attackers go after first

01

Storefront and checkout

The customer-facing web application and its payment page, tested for injection, script inclusion risks, account takeover, and logic flaws in cart, pricing, discount, and return workflows.

02

Customer accounts and loyalty

Login, registration, stored payment methods, and loyalty balances, tested for credential stuffing exposure, weak recovery flows, and authorization gaps between customer records.

03

Commerce and order APIs

The APIs behind the storefront, mobile app, and marketplace listings, tested for broken object authorization, mass assignment on orders, and unthrottled endpoints attackers automate.

04

Cardholder data environment

The network segment and systems that store, process, or transmit card data, tested externally, internally, and from every out-of-scope segment to prove segmentation holds.

05

Mobile shopping apps

iOS and Android apps, tested for insecure storage of tokens and card details, certificate pinning gaps, and backend calls that bypass web-only checkout controls.

06

Point of sale and store networks

In-store terminals, kiosks, and the store network connecting them to headquarters, tested for lateral movement from the retail floor into corporate and payment systems.

How it runs

Typical engagements

Illustrative scopes for this industry, written to show what a test covers and what you walk away with. They are not client stories; our anonymized engagements are on the case studies page.

Typical engagement

Direct-to-consumer brand before its first Report on Compliance

A direct-to-consumer apparel brand has grown past the transaction volume where self-assessment suffices and needs Requirement 11.4 evidence for a Report on Compliance. We confirm the cardholder data environment with the team and test the storefront and checkout at the application layer. External, internal, and segmentation testing then runs against the CDE. The QSA receives a methodology statement, segmentation evidence from every out-of-scope segment, and retest results showing findings closed.

Typical engagement

Marketplace operator with an abused promotions system

A marketplace operator notices coupon and referral abuse and wants the whole order lifecycle tested. We test the storefront and commerce API across buyer, seller, and support roles. A race condition in the discount endpoint is chained with price manipulation between cart and payment. An authorization flaw exposes other sellers’ payout details. Engineering receives reproduction steps and fixes, and the retest confirms the workflow no longer leaks money.

Typical engagement

Regional retailer connecting stores to headquarters

A regional retail chain rolling out new point-of-sale terminals wants to know what a compromised store network could reach. We test from a device on the retail floor and attempt to move from the store VLAN into the corporate network and the payment segment. The external perimeter around headquarters is tested as well. The report ranks segmentation fixes by which one breaks the most paths, and the retest documents the new boundary for the next PCI assessment.

FAQ

What e-commerce buyers ask

01Does PCI DSS require a penetration test for an online store?

Yes, if your validation route includes Requirement 11.4, which covers a Report on Compliance, SAQ D, and SAQ A-EP for merchants whose site affects the payment page. It calls for internal and external testing at least annually and after significant change, plus segmentation testing where scope is reduced. Our e-commerce penetration testing guide walks through the routes and what each requires.

02We use a hosted payment page. Are we still in scope?

Fully outsourced payment pages under SAQ A carry no Requirement 11.4 obligation, but your acquirer, a marketplace partner, or a customer may still ask for testing. If your own site loads scripts that affect the payment page, SAQ A-EP applies and testing is required. Tell us your validation route during scoping and we match the scope to it.

03Can you test during peak season without affecting sales?

We test against staging wherever one exists. When production is the only option, we agree written rules. No denial-of-service techniques, no real orders beyond agreed test transactions, defined windows outside your peak hours, and immediate escalation of anything critical. Most retailers schedule testing well ahead of the holiday freeze, and we plan around it.

04How much does an e-commerce penetration test cost?

Web application testing starts at $5,200, API testing at $4,000, external network testing at $4,200, and internal network testing at $6,000. Each is fixed in writing before work starts with a free retest of remediated findings. A full PCI engagement usually combines the application test with external, internal, and segmentation testing, quoted as one number.

05Do you test the mobile app and the storefront together?

Yes, and we recommend it, because the app and the site usually share an API and the app often bypasses controls enforced only in the web checkout. Mobile testing starts at $6,000 with iOS and Android included, and one report covers the storefront, the app, and the API they share.

Get a fixed price for your storefront scope

Tell us what needs testing. You get a written fixed price within one business day, with the compliance mapping your auditors and customers expect.

Prefer the full scoping questionnaire? 

Get a Fixed-Scope Quote

Tell us what you need tested. We reply within one business day.