PCI DSS PENETRATION TESTING
PCI DSS penetration testing, and staying ready between tests
PCI DSS Requirement 11.4 asks for internal and external penetration tests at least every 12 months and after significant changes. Nurbak doesn't replace that test. It reviews the code of your payment app continuously, so exploitable flaws get fixed long before the tester shows up.
Create account and connect GitHubWe never store your code. We only write when you ask for a fix PR.
Catch application-layer flaws early
Our own AI model looks for the classes Requirement 6.2.4 names, such as injection, broken access control and business logic flaws, in the code your team writes.
Findings with CWE, file and line
Each finding comes with its CWE and a plain-language explanation, so it is easy to track, fix and show as remediated.
An auditable trail
Analysis runs on Nurbak's self-hosted model on ephemeral infrastructure, not on OpenAI or Anthropic, and every step lands in a hash-chained audit trail.
Daily re-scans on paid plans
Code changes between your annual tests get reviewed too, and fixes arrive as pull requests with a security regression test.
What PCI DSS v4.0.1 says about penetration testing
11.4.1: a documented methodology
Based on an industry-accepted approach, covering the whole CDE perimeter and critical systems, with network-layer and application-layer tests. The application layer must cover at least the vulnerabilities listed in Requirement 6.2.4.
11.4.2: internal testing
At least once every 12 months and after any significant infrastructure or application upgrade or change, by a qualified internal resource or qualified external third party with organizational independence.
11.4.3: external testing
The same frequency and tester rules, applied from outside the network. The tester does not have to be a QSA or an ASV.
11.4.4: fix and retest
Exploitable vulnerabilities and security weaknesses found in the test are corrected according to your risk ranking, and the test is repeated to verify the fixes.
11.4.5 and 11.4.6: segmentation
If you use segmentation to reduce PCI scope, its controls are tested at least every 12 months, and every 6 months for service providers.
Requirement 6: secure code
6.2.3 asks for custom software to be reviewed before release to find and correct coding vulnerabilities, and 6.2.4 lists attacks your code must prevent. Code security audit.
How Nurbak fits into your PCI program
Connect GitHub and pick the repos of the apps that touch card data. Public and private repos both work.
Nurbak's own model analyzes the code on ephemeral infrastructure and records each step in the audit trail.
Get a 0 to 100 security score and findings with file, line, CWE and a plain-language explanation.
Fix in one click with a pull request that includes a security regression test.
On a paid plan the repo is rescanned daily, so you reach the formal pentest with fewer surprises.
PCI DSS penetration testing FAQ
What does PCI DSS require for penetration testing?
Requirement 11.4 of PCI DSS v4.0.1 asks for a documented methodology, internal and external penetration tests at least every 12 months and after significant changes, correction and retesting of exploitable findings, and segmentation testing if you use segmentation to reduce scope. The application-layer part must cover at least the vulnerabilities in Requirement 6.2.4. If you are new to the topic, start with what penetration testing is.
How often is a PCI penetration test required?
Internal and external tests are required at least once every 12 months and after any significant infrastructure or application upgrade or change. Segmentation controls are tested at least every 12 months, or every 6 months for service providers.
Who can perform a PCI DSS penetration test?
A qualified internal resource or a qualified external third party, as long as there is organizational independence. The tester does not need to be a QSA or an ASV. Note that the quarterly external vulnerability scans by an ASV (Requirement 11.3.2) are a separate requirement and do not replace the penetration test.
Does Nurbak replace the PCI-required penetration test?
No. Nurbak is not a QSA or an ASV and does not certify PCI DSS compliance. It analyzes source code, so it does not test your network layer, segmentation or live systems. What it does is review your code continuously between formal tests, so injection, access control and other code-level flaws are found and fixed early. For how continuous testing compares with a yearly test, see penetration testing as a service.
Can Nurbak help with Requirement 6 code reviews?
It can be part of an automated review of custom code before release: it reports findings with CWE, file and line, and the vulnerability classes from the OWASP Top 10 2025 it looks for overlap with the attacks listed in 6.2.4. Whether it satisfies a specific requirement depends on your process and your assessor. More in automated penetration testing.
Is my code sent to a third-party AI?
The analysis runs on Nurbak's own self-hosted model on ephemeral infrastructure, so your code is not sent to OpenAI or Anthropic to be analyzed, and every step is recorded in a hash-chained audit trail. Only if you ask for a fix pull request and give explicit consent is the fix generated with Claude.
How much does it cost?
The first scan is free and shows the 3 most important findings in full, plus 1 free fix PR. Plans are USD 79 per month for 1 repo and USD 199 per month for up to 5 repos, with daily scans. Above 5 repos there is an Enterprise plan. We charge per repo, not per developer. See pricing.
Get your payment code ready before the next pentest
Connect GitHub and get your security score and your 3 most important findings free.
Scan my repoPCI DSS is a standard of the PCI Security Standards Council. This page summarizes PCI DSS v4.0.1 as of September 2026 and is not legal or compliance advice. Confirm your scope and requirements with your QSA or acquirer. Nurbak is not a QSA or ASV and does not certify compliance.