← Back to Blog

Compliance · · 10 min read · By Hackrowd Team

PCI DSS Penetration Testing in Lagos: Requirement 11.4 Guide

A PCI DSS v4.0.1 penetration testing guide for Lagos merchants, fintechs and service providers, covering Requirement 11.4 scope, cadence, retesting and evidence.

PCI DSS Penetration Testing in Lagos: Requirement 11.4 Guide
## PCI DSS in Nigeria: Start With the Right Obligation PCI DSS v4.0.1 is a global payment-card security standard maintained by the PCI Security Standards Council. It is not a Lagos or Nigerian statute. Nigerian merchants, fintechs and service providers generally face it through card-scheme, acquiring-bank and contractual obligations. CBN cybersecurity requirements may apply separately to regulated financial institutions. A CBN-aligned penetration test does not automatically satisfy PCI DSS, and a PCI DSS test does not replace the institution's wider CBN obligations. Always confirm the applicable validation route with your acquirer, card brands and Qualified Security Assessor. The [PCI Security Standards Council](https://www.pcisecuritystandards.org/) document library is the authoritative source for the current standard. ## What Requirement 11.4 Covers PCI DSS v4.0.1 Requirement 11.4 requires a documented and implemented penetration-testing programme. Its components include: - **11.4.1:** a documented methodology based on industry-accepted approaches - **11.4.2:** internal penetration testing at least once every 12 months and after significant changes - **11.4.3:** external penetration testing at least once every 12 months and after significant changes - **11.4.4:** correction of exploitable vulnerabilities followed by retesting - **11.4.5 and 11.4.6:** testing of segmentation controls, with cadence depending on entity type - **11.4.7:** support obligations for multi-tenant service providers where customers conduct applicable external testing Use the standard itself to confirm exact applicability. Requirements vary for merchants, service providers and environments that rely on segmentation. ## Merchant and Service-Provider Cadence Internal and external penetration tests are generally required at least every 12 months and after significant changes. Where segmentation is used to reduce cardholder data environment scope, segmentation controls must also be tested. Service providers face a more frequent six-month segmentation-testing cadence under Requirement 11.4.6; merchants generally follow the applicable annual and change-triggered requirement. A calendar reminder is not enough. Change management must identify events that trigger a new test, such as: - A new payment application or checkout flow - Major network or firewall changes - Cloud migration or material architecture changes - New authentication or authorization services - New connections into the cardholder data environment - Significant application releases ## What a PCI DSS Testing Methodology Should Document The methodology should define: - Scope aligned to the cardholder data environment and connected systems - Internal, external, application and network-layer coverage - Threats and vulnerabilities considered during testing - Segmentation validation where segmentation reduces scope - Tester competence and organisational independence - Rules for evidence handling and safe exploitation - Severity, remediation and retesting procedures - Treatment of significant changes A QSA is not necessarily required to perform the test, but the tester must be qualified and organisationally independent from the systems under review. ## Internal, External and Segmentation Testing **External testing** assesses exposed services and applications from outside trusted boundaries. **Internal testing** examines attack paths available after an internal foothold or compromised account. **Segmentation testing** proves that out-of-scope networks cannot reach the cardholder data environment through unintended paths. A vulnerability scan alone is not a penetration test. Scanning supports coverage, while manual testing validates exploitation, chained weaknesses and business logic. ## Evidence for Your QSA or ISA Prepare: - The approved Requirement 11.4 methodology - Current cardholder data-flow and network diagrams - A defined penetration-test scope with exclusions justified - Internal and external reports dated within the assessment period - Segmentation test reports where segmentation is relied upon - Tester competence and independence evidence - Change records and resulting test decisions - Remediation tickets for exploitable vulnerabilities - Retest results proving correction - Risk and exception approvals for unresolved items The cleanest evidence links each finding to an owner, correction, date and retest outcome. ## Common PCI DSS Penetration-Test Gaps - Testing only the public website while excluding payment APIs or administrative paths - Failing to test from inside the environment - Treating an ASV scan as the annual penetration test - Claiming segmentation without testing the controls - Missing change-triggered testing after a major release - Closing findings based only on developer confirmation - Using a tester who designed or operates the assessed control without adequate independence ## Lagos PCI DSS Readiness Checklist - Confirm merchant or service-provider status with the acquirer and QSA - Map the cardholder data environment and all connected systems - Document an industry-aligned test methodology - Complete internal and external tests on schedule - Test segmentation at the cadence applicable to your entity - Trigger testing after significant changes - Preserve tester qualification and independence records - Remediate exploitable findings and complete retesting - Map CBN obligations separately if your institution is regulated ## Frequently Asked Questions ### Must the penetration tester be a QSA? Not necessarily. PCI DSS focuses on tester competence and organisational independence. Your QSA or acquirer can confirm what evidence they expect. ### Does an ASV scan satisfy Requirement 11.4? No. Approved Scanning Vendor scans address separate vulnerability-scanning requirements. Requirement 11.4 calls for penetration testing. ### Can testing be delivered remotely for a Lagos company? Much of external, application and API testing can be delivered remotely under signed rules of engagement. Internal and segmentation scope may require controlled access, an appliance or an agreed on-site arrangement. ## Prepare for Requirement 11.4 Hackrowd provides [PCI DSS readiness](/pci-dss-compliance) and manual-led [penetration testing](/penetration-testing), including internal, external, application, API and segmentation validation with remediation retesting. Final PCI DSS validation remains with your QSA, acquirer and card brands.