Let's Get One Thing Straight Right Away
Penetration testing is not the same as vulnerability scanning. I can’t tell you how many business owners I’ve spoken with who assume running an automated scan once a quarter checks the box for PCI compliance. It doesn’t.
A vulnerability scan is automated and identifies potential weaknesses. A penetration test, on the other hand, involves a live person actively digging into the complexities of your network, attempting to exploit vulnerabilities to see how far they can actually get. One identifies holes; the other proves they can be exploited.
With PCI DSS v4.0.1 now fully in effect (all future-dated requirements became mandatory in March 2025), the expectations around penetration testing have become significantly more rigorous. If you’re responsible for PCI compliance at your organization, here’s everything you need to know about the penetration testing requirements.

What Exactly Does PCI DSS Require for Penetration Testing?
The core requirement is found in PCI DSS Requirement 11.4, which mandates that organizations perform regular penetration testing to identify and correct exploitable vulnerabilities and security weaknesses. This is not a suggestion—it is mandatory for all entities that store, process, or transmit cardholder data.
