[For PCI DSS 4.0 Requirement 11.4]
External, internal and segmentation testing with the retest included. One report, written against 11.4.1 to 11.4.7, by a tester with nothing to attest.


Insurers, fintechs, payment processors and US defense contractors renew with us because the second year needs no procurement.
Your PCI date is public.
Before your validation date, PCI DSS 4.0 asks for four things.
None of them is a scan.
11.4.3
External Pentest
Every 12 months, and after any significant change.
11.4.2
Internal pentest
An internal penetration test on the same cadence
11.4.4
Fix and retest
Every exploitable finding closed before the report goes in.
11.4.5–6
Segmentation
Every 12 months. Every 6 for service providers.
Where it usually breaks
The report misses the brief.
No scope statement, no methodology, no tester credentials.
Retest isn't in the contract.
You fixed the findings. Nobody came back to prove it.
April arrives.
The six-month segmentation test is nobody's job until it's late.
11.4.1 Testing method and independent testers
11.4.2 Internal test every year and after major changes
11.4.3 External test every year and after major changes
11.4.4 Fix and retest exploitable findings
11.4.5 Test network segmentation yearly
11.4.6 Service providers: test segmentation every six months
Method, qualifications, and independence statement
Dated internal test report
Dated external test report
Proof of retesting
Segmentation test results
Two dated tests per year
What we provide
All documented in the report
All documented in the report
Testing beyond scanner results
Verified fixes, logged by finding
Included in every engagement
Scheduled twice a year
What we test
External network
The perimeter, as an attacker sees it
Internal network
Inside the CDE and what touches it
Segmentation
Proof the CDE is isolated
Cloud
Accounts and services in scope
Web and API
Anything that touches card data
Mobile
Apps in scope
[CUSTOMER STORIES]
Teams trust CodeAnt
to prevent breaches
[SINGLE ENGAGEMENT]
One external penetration test
Internal and segmentation testing, if your scope needs them
Retest included
Report mapped to 11.4.1 to 11.4.7
Two weeks from scope to report
Four penetration tests, one each quarter
Segmentation testing, including the six-month test
Retests, always included
365-day attack-surface monitoring
One report format your assessor already knows

[HOW IT WORKS]
Scope to Report in 14 Days
DAY 0
Scope
A 15-minute call. Your CDE boundary, assets and date. Testing starts that week.
DAY 1-10
Test
External, internal, cloud and network. No agents, no downtime.
DAY 14
Report
Findings by CVSS, with proof, laid out against 11.4.1 to 11.4.7.
AFTER FIXES
Retest
Included. Each fix verified, ledger closed, package regenerated.

One scoping call a year. Everything else runs on the calendar you already have.
SOC 2 Type II
Gartner Cool Vendor 2026
HIPAA Compliant
[FAQ]
Frequently Asked
Questions
Will my QSA accept your report?
Is this a pentest or a scan?
Our assessor already does our pentest.
Do you test production?
We're a merchant, not a service provider.
What about significant changes mid-year?
[GET STARTED]

Report in 14 Days
Book a Call







