[For PCI DSS 4.0 Requirement 11.4]

Your PCI Pentest,
Done in Two Weeks.

Your PCI Pentest,
Done in Two Weeks.

Your PCI Pentest,
Done in Two Weeks.

External, internal and segmentation testing with the retest included. One report, written against 11.4.1 to 11.4.7, by a tester with nothing to attest.

Logo 5
Logo 15
Logo 12
Logo 11
Logo 2
Logo 4
Logo 9
Logo 13
Logo 14
Logo 3
Logo 11
Logo 4
Logo 8
Logo 3
Logo 6
Logo 12
Logo 1
Logo 5
Logo 7
Logo 1
Logo 10

Insurers, fintechs, payment processors and US defense contractors renew with us because the second year needs no procurement.

Your PCI date is public.

Before your validation date, PCI DSS 4.0 asks for four things.
None of them is a scan.

11.4.3

External Pentest

Every 12 months, and after any significant change.

11.4.2

Internal pentest

An internal penetration test on the same cadence

11.4.4

Fix and retest

Every exploitable finding closed before the report goes in.

11.4.5–6

Segmentation

Every 12 months. Every 6 for service providers.

Where it usually breaks

The report misses the brief.

No scope statement, no methodology, no tester credentials.

Retest isn't in the contract.

You fixed the findings. Nobody came back to prove it.

April arrives.

The six-month segmentation test is nobody's job until it's late.

[THE OFFER]

Requirement 11.4. One test, or the whole year.

START PENTEST

NO CC REQUIRED
PCI DSS 4.0

PCI DSS 4.0

11.4.1 Testing method and independent testers

11.4.2 Internal test every year and after major changes

11.4.3 External test every year and after major changes

11.4.4 Fix and retest exploitable findings

11.4.5 Test network segmentation yearly

11.4.6 Service providers: test segmentation every six months

What assessor needs

What assessor needs

Method, qualifications, and independence statement

Dated internal test report

Dated external test report

Proof of retesting

Segmentation test results

Two dated tests per year

What we provide

All documented in the report

All documented in the report

Testing beyond scanner results

Verified fixes, logged by finding

Included in every engagement

Scheduled twice a year

What we test

External network

The perimeter, as an attacker sees it

Internal network

Inside the CDE and what touches it

Segmentation

Proof the CDE is isolated

Cloud

Accounts and services in scope

Web and API

Anything that touches card data

Mobile

Apps in scope

[CUSTOMER STORIES]

Teams trust CodeAnt
to prevent breaches

"CodeAnt is the most advanced and thorough penetration test we've run to date. It delivered superior results in a fraction of the time of our previous engagements."

Jason Powell

SVP, Engineering & Product, Phunware (Public Company)

"CodeAnt is the most advanced and thorough penetration test we've run to date. It delivered superior results in a fraction of the time of our previous engagements."

Jason Powell

SVP, Engineering & Product, Phunware (Public Company)

"CodeAnt is the most advanced and thorough penetration test we've run to date. It delivered superior results in a fraction of the time of our previous engagements."

Jason Powell

SVP, Engineering & Product, Phunware (Public Company)

[SINGLE ENGAGEMENT]

One Pentest for this year's Assessment

One Pentest for this year's Assessment

One external penetration test

Internal and segmentation testing, if your scope needs them

Retest included

Report mapped to 11.4.1 to 11.4.7

Two weeks from scope to report

[SINGLE ENGAGEMENT]

COVERS EVERY 11.4 CADENCE

COVERS EVERY 11.4 CADENCE

Four tests a year. One contract.

Four penetration tests, one each quarter

Segmentation testing, including the six-month test

Retests, always included

365-day attack-surface monitoring

One report format your assessor already knows

[HOW IT WORKS]

Scope to Report in 14 Days

DAY 0

Scope

A 15-minute call. Your CDE boundary, assets and date. Testing starts that week.

DAY 1-10

Test

External, internal, cloud and network. No agents, no downtime.

DAY 14

Report

Findings by CVSS, with proof, laid out against 11.4.1 to 11.4.7.

AFTER FIXES

Retest

Included. Each fix verified, ledger closed, package regenerated.

One scoping call a year. Everything else runs on the calendar you already have.

[SECURE & COMPLIANT]

Security first design

built for enterprises

Security first design

built for enterprises

Security first design

built for enterprises

AICPA

SOC2

TYPE 2

AICPA

SOC2

TYPE 2

SOC 2 Type II

COOL
VENDOR
2026

COOL
VENDOR
2026

Gartner Cool Vendor 2026

HIPAA Compliant

[FAQ]

Frequently Asked
Questions

Will my QSA accept your report?

Is this a pentest or a scan?

Our assessor already does our pentest.

Do you test production?

We're a merchant, not a service provider.

What about significant changes mid-year?

[GET STARTED]

Your date is public.
So is our calendar.

Put your hardest security questions
to the test.

Report in 14 Days

Book a Call