Get Demo
↑

PCI DSS Network Segmentation and Segmentation Penetration Testing

PCI DSS segmentation guidance - scope reduction is optional; if used, validate controls with penetration tests under Requirements 11.4.5 and 11.4.6.

Published: September 2026 Compliance · PCI DSS 8-12 min read

Segmentation can shrink PCI DSS scope and risk - but it is not itself a PCI DSS requirement. If you rely on it, you must prove with technical testing that out-of-scope systems cannot reach or impact the cardholder data environment (CDE).

Related: Requirement 11 · Requirement 1 · ASV scans · PCI hub.

Gotcha: Segmentation testing is not an ASV scan and is not satisfied by application pentesting alone. Penetration Testing Guidance expects each unique segmentation methodology to be tested. Large claims that networks are "out of scope" fail if any path into the CDE exists - then fix controls or expand scope.

What Official Guidance Says

Network segmentation (isolating the CDE from the rest of the network) is not a PCI DSS requirement, but is strongly recommended to reduce assessment scope, cost, control burden, and risk. Without adequate segmentation (a "flat network"), the entire network is in scope. Adequate segmentation means an out-of-scope system could not impact CHD/SAD security even if compromised.

Requirement 11.4.5 (If Segmentation Is Used)

Penetration tests on segmentation controls must be performed:

Requirement 11.4.6 (Service Providers Only)

Same segmentation penetration-testing expectations on a six-month cadence (and after changes) for service providers.

Assessor Verification

If segmentation is used to reduce the scope of the PCI DSS assessment, the assessor must verify that segmentation is adequate to reduce scope.

How CyberSilo Helps

Map PCI DSS v4.0.1 Controls to Continuous Evidence

CyberSilo CSA and ThreatHawk SIEM help US merchants and service providers collect QSA-ready evidence across SAQ and ROC validation paths.

Frequently Asked Questions

Is segmentation mandatory?

No - but without it, expect a much larger CDE and assessment scope.

How often must we test segmentation?

At least annually under 11.4.5; service providers at least every six months under 11.4.6; and after segmentation changes.

Does a passing ASV scan prove segmentation?

No. ASV is external vulnerability scanning (11.3.2). Segmentation proof is penetration testing of isolation controls (11.4.5 / 11.4.6).

Requirement 11 · Requirement 1 · ASV scans · QSA vs ISA vs ASV · PCI hub

📰 More from CyberSilo

Latest Articles

Stay ahead of evolving cyber threats with our expert insights

✅ Link copied!