It’s been noted that many merchants aren’t complying properly with the penetration testing requirement found in section 11 of the PCI DSS. In PCI 3.0 the penetration testing guidelines have been updated. The changes in penetration testing for PCI 3.0 were a best practice until June 30, 2015. Since that date, it is no longer acceptable for merchants to follow the PCI v2 penetration testing guidelines.
You might be wondering, “How does this affect me and what do I need to do to be compliant with penetration testing in PCI DSS version 3.0?”
Before going any further, you might just make sure that penetration testing is required for your business. If you are eligible to use one of the Self Assessment Questionnaires, check to see if your SAQ document has section 11.3. If section 11.3 is not included, the penetration testing is optional.
Assuming that you know penetration testing is required for your business, keep in mind the refinements contained in PCI version 3.0 regarding penetration testing. If you are looking for a penetration testing vendor for PCI compliance, ensure that any testing follows these guidelines:
All members of Backbone Security’s 1 Stop PCI Scan team are qualified to perform PCI 3.0 penetration tests, holding advanced penetration testing certifications. Backbone Security employs Offensive Security Certified Professionals (OSCP), a credential specifically highlighted in the PCI Security Standards September 2017 penetration testing guidance. In fact, OSCP is first on the PCI SSC’s list of recommended credentials, so rest assured that we are qualified to assist.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
Stripe is a payment processing platform that enables businesses to accept online payments securely and efficiently.
Service URL: stripe.com (opens in a new window)
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
Google reCAPTCHA helps protect websites from spam and abuse by verifying user interactions through challenges.
SourceBuster is used by WooCommerce for order attribution based on user source.
Marketing cookies are used to follow visitors to websites. The intention is to show ads that are relevant and engaging to the individual user.
Facebook Pixel is a web analytics service that tracks and reports website traffic.
Service URL: www.facebook.com (opens in a new window)