Get Demo
↑

PCI DSS Requirement 11: Vulnerability Scans, ASV, Penetration Testing, and Change Detection (11.6.1)

PCI DSS v4.0.1 Requirement 11 - quarterly internal/ASV scans, authenticated internal scans (11.3.1.2), annual pentests.

Published: September 2026 Compliance · PCI DSS 8-12 min read

PCI DSS Requirement 11 in v4.0.1 is titled Test Security of Systems and Networks Regularly. It covers wireless rogue-AP checks, vulnerability management, penetration testing (including segmentation), intrusion detection, file change detection, and payment-page change-and-tamper detection (11.6.1), which pairs with Requirement 6.4.3 script control.

Related: Requirement 6 · VAPT for PCI DSS · 12 requirements hub.

Gotcha: 11.6.1 (change-and-tamper detection of payment pages as received by the consumer browser) is not the same as 6.4.3 (authorize, assure integrity, and inventory payment page scripts). You typically need both. ASV scans apply to external vulnerability scanning (11.3.2); internal scans do not require an ASV.

Requirement Structure

Clause
Focus
11.1
Processes and roles for regular security testing
11.2
Wireless AP inventory and quarterly unauthorized AP detection
11.3
Internal and external vulnerability identification and remediation
11.4
External and internal penetration testing plus segmentation tests
11.5
IDS/IPS and change-detection (FIM) on critical files
11.6
Unauthorized changes on payment pages detected and responded to

Deep Dives

How CyberSilo Helps

Map PCI DSS v4.0.1 Controls to Continuous Evidence

CyberSilo CSA and ThreatHawk SIEM help US merchants and service providers collect QSA-ready evidence across the 12 requirements.

Frequently Asked Questions

What is the difference between 6.4.3 and 11.6.1?

6.4.3 manages authorization, integrity, and inventory of payment page scripts loaded in the consumer browser. 11.6.1 adds change-and-tamper detection for payment pages (HTTP headers and contents) as received by the consumer browser.

Do internal vulnerability scans need an ASV?

No. A PCI SSC Approved Scanning Vendor is required for external vulnerability scans under 11.3.2. Internal scans under 11.3.1 need qualified personnel with organizational independence.

Is authenticated internal scanning required?

Yes under 11.3.1.2 for systems that accept credentials (mandatory since 31 March 2025). Systems that cannot accept credentials must be documented. Authenticated scanning is not required for post-significant-change scans under 11.3.1.3.

PCI DSS hub · 12 requirements explained · Requirement 6 · Requirement 10

📰 More from CyberSilo

Latest Articles

Stay ahead of evolving cyber threats with our expert insights

✅ Link copied!