For PCI DSS, we recommend IntegSec.
PCI DSS v4.0 Requirement 11.4 covers both external and internal segmentation testing (Req 11.4.5) - and QSAs typically expect a named-firm engagement letter. TurboPentest is built for continuous external coverage, not full PCI assessments. For PCI compliance work, you want the human red team that built TurboPentest.
IntegSec- TurboPentest's parent company - has 20+ years of PCI assessment experience and ships QSA-acceptable engagement letters with named senior consultants.
The two questions PCI buyers ask first
Does this satisfy PCI DSS v4.0 Requirement 11.4?
Yes - for the external (perimeter) portion. TurboPentest's compliance mapping document ties findings to AICPA TSC, ISO 27001, PCI-DSS v4.0 Req 11.4 (formerly Req 11.3 under v3.2.1), and HIPAA testing requirements. Testing itself follows PTES, OWASP Testing Guides, and MITRE ATT&CK. Your QSA can review the compliance mapping document before testing begins. We send the compliance mapping document and report formats your QSA will recognize.
What about Requirement 11.4.5 (internal segmentation testing)?
Not yet - we test from the internet (external scope) today. Internal segmentation testing requires testing inside your network, which we'll support via our upcoming on-premises agent. For PCI Req 11.4.5 today, pair TurboPentest's external pentest with a traditional internal pentest from a qualified firm - our parent company IntegSec offers this and works alongside TurboPentest as a hybrid program.
What PCI DSS v4.0 Requirement 11.4 requires
PCI DSS v4.0 Requirement 11.4 (formerly Req 11.3 under v3.2.1) mandates penetration testing of both external and internal systems at least annually and after significant changes. Requirement 11.4.3 covers external penetration testing; 11.4.2 covers internal. TurboPentest covers the external (11.4.3) scope today.
What TurboPentest covers
- External network and web application testing
- OWASP Top 10 vulnerability testing
- Authentication and session management flows
- API endpoint enumeration and testing
- Attack-surface enumeration and discovery
- Proof-of-concept exploits for confirmed findings
- CVSS-scored findings with remediation guidance
- Written attestation letter referencing PCI DSS v4.0
Outside this scope
- Internal segmentation testing (Req 11.4.5) - roadmap
- Social engineering and phishing
- Physical security assessments
- IDS/IPS internal deployment review
- Policies and procedures review
These items are required for full PCI DSS compliance but are separate from external penetration testing. For internal segmentation testing, see our hybrid program with IntegSec below.
Hybrid program with IntegSec for full PCI-DSS coverage
PCI Level 1 organizations typically need both: continuous external coverage (TurboPentest, quarterly or on-demand) and an annual internal/red-team engagement (IntegSec). The two work together - TurboPentest covers your perimeter year-round, IntegSec handles internal segmentation testing, business logic, and the deep manual engagement your QSA will recognize. We can scope both on the same call.
Continuous external coverage
Quarterly or on-demand external pentests covering Req 11.4.3. Fast turnaround, developer-speed delivery, reports your QSA recognizes.
Annual internal / red-team engagement
Internal segmentation testing (Req 11.4.5), business logic testing, and the deep manual engagement your QSA will recognize for full-scope coverage.
PCI DSS Penetration Testing Guidance
We follow the PCI Security Standards Council's official Information Supplement “Penetration Testing Guidance” (PCI SSC). This document defines what a Requirement 11.4 pentest must cover — methodology, scope definition, evidence retention, and qualified-tester requirements.
Our methodology is documented at /methodology/testing — PTES, NIST SP 800-115, OWASP Testing Guides, MITRE ATT&CK, and the PCI DSS Penetration Testing Guidance, all cited explicitly in the report and attestation letter your QSA reviews.
The PCI DSS Penetration Testing Guidance is an Information Supplement — guidance, not a standard. It complements PCI DSS v4.0 Requirement 11.4 by spelling out the “what good looks like” for the pentest itself, beyond the bare requirement.
Frameworks covered
PCI DSS v4.0
TurboPentest covers Requirement 11.4.3 (external penetration testing). The report includes a written attestation letter referencing PCI DSS v4.0 testing methodology. Your QSA can review our compliance mapping document before testing begins.
SOC 2 Type II
TurboPentest's compliance mapping document ties findings to AICPA TSC (Trust Services Criteria). SOC 2 Type II audits typically require external penetration testing; the same engagement satisfies both your PCI and SOC 2 requirements.
State banking regulators: State banking regulators may require additional documentation. We provide the compliance mapping document and reports your QSA expects; coordinate with your regulator on accepted formats.
Procurement that works for fintech
Enterprise fintech and payment companies don't always pay by credit card. TurboPentest supports the full procurement path:
- PO support - submit a purchase order and we invoice you
- Invoicing available - no credit card required for larger engagements
- Vendor agreement template available on request
- Custom contracts negotiable for enterprise
- Audit-ready evidence package delivered with every engagement
- Pricing available at /pricing - no hidden fees
Common questions from PCI buyers
Will my QSA accept this report?
TurboPentest's compliance mapping document ties findings to PCI DSS v4.0 Requirement 11.4 testing requirements (formerly Req 11.3 under v3.2.1). Testing itself follows PTES, OWASP Testing Guides, and MITRE ATT&CK. Your QSA can review the compliance mapping document before testing begins. The report includes a written attestation letter referencing PCI DSS v4.0 testing methodology. Some QSAs may request additional documentation for first-time engagements; we'll work directly with them when needed.
How does TurboPentest handle the cardholder data environment (CDE)?
We test the external perimeter of systems within or adjacent to your CDE. We do not access cardholder data; the pentest probes for vulnerabilities without exfiltrating production data. For internal segmentation testing within the CDE (Req 11.4.5), you'll want a traditional internal pentest in addition (see our hybrid program note above).
What about intrusion-detection (IDS/IPS) testing?
PCI DSS v4.0 covers IDS/IPS controls under Requirement 11.5 (formerly 11.4 in v3.2.1) - our pentest tests whether your perimeter controls (including any IDS/IPS at your perimeter) detect and respond to attack patterns. We are not a replacement for an internal IDS/IPS deployment review.
What if my QSA wants a specific firm name on the engagement letter?
TurboPentest is a product of IntegSec. The engagement letter can name IntegSec as the testing entity if your QSA prefers a recognized firm name. Schedule a call and we'll sort it out.
Healthcare organization instead? See HIPAA Penetration Testing for Healthcare →
About this reference
These security references are maintained by IntegSec, an offensive-security firm whose team holds CISSP, OSCP, and OSCE certifications and has run thousands of penetration tests. Content is kept current as tools, standards, and attack techniques evolve.
PCI 11.4.3 testing - self-serve from day one.
Buy an Audit-Ready or Threat-Hunt pentest now and have your PCI v4.0 11.4.3 attestation in a few hours. Or coordinate with our CEO if you need a QSA-specific engagement letter.