PCI DSS 4.0 Compliance
Meet Requirement 11 with validated network testing
PCI DSS 4.0 requires annual external and internal penetration testing with a documented methodology covering your full CDE perimeter. DDactic delivers all of it, with OPI Validated scores as QSA-ready evidence.
What PCI DSS 4.0 Requires
PCI DSS 4.0 (effective March 31, 2024) tightens penetration testing requirements for any organization that stores, processes, or transmits cardholder data. Requirement 11 covers security testing of systems and networks.
"External penetration testing is performed: At least once every 12 months. After any significant infrastructure or application upgrade or change. By a qualified internal resource or qualified external third party. Organizational independence of the tester exists."
"Internal penetration testing is performed at least once every 12 months and after any significant infrastructure or application upgrade or change."
"A penetration testing methodology is documented, implemented, and includes: industry-accepted penetration testing approaches; coverage for the entire CDE perimeter and critical systems; testing from both inside and outside the network; network-layer penetration tests that encompass all components that support network functions as well as operating systems; includes review and consideration of threats and vulnerabilities experienced in the last 12 months; specifies retention of penetration testing results and remediation activities results for at least 12 months."
DDoS attacks are a primary availability threat for payment infrastructure. A CDN or WAF that has not been validated under simulated attack conditions provides no assurance to your QSA. PCI DSS 4.0 now explicitly requires a documented methodology, not just a point-in-time test.
How DDactic Maps to Requirement 11
Every DDactic assessment runs against an open, documented methodology (OPI v1.3.0, Apache 2.0 licensed) and produces structured artifacts your QSA can review.
| PCI DSS Requirement | Section | DDactic Feature |
|---|---|---|
| Annual external penetration test | 11.3.1 | DDoS simulation from 24-cloud-provider external fleet, repeatable on demand |
| Independent tester | 11.3.1 | DDactic operates independently from your network; no credentials or agents required |
| Internal exposure discovery | 11.3.2 | Passive recon discovers origin IPs exposed despite CDN/WAF (internal infrastructure visible externally) |
| Documented methodology | 11.4.1 | OPI v1.3.0 specification, Apache 2.0 licensed, published at github.com/DDactic/opi-standard |
| Full CDE perimeter coverage | 11.4.1 | Attack surface discovery maps all externally exposed SLDs and subdomains, not just declared targets |
| Network-layer penetration tests | 11.4.1 | L3/L4 simulation: SYN floods, UDP floods, ICMP amplification, DNS amplification, NTP reflection |
| Application-layer penetration tests | 11.4.1 | L7 simulation: HTTP floods, Slowloris, cache bypass, API abuse, HTTP/2 Rapid Reset, QUIC vectors |
| 12-month artifact retention | 11.4.1 | OPI Validated PDF report and scan artifacts retained in DDactic platform for download at any time |
| Remediation documentation | 11.4.1 | Vendor-specific hardening commands (Cloudflare, Akamai, AWS Shield, Imperva) with before/after OPI delta |
| Threats from last 12 months | 11.4.1 | Attack library updated continuously; HTTP/2 Rapid Reset (CVE-2023-44487), QUIC amplification, BoT evasion variants included |
Evidence DDactic Produces
Every completed assessment generates a structured evidence package your QSA can review without requiring DDactic involvement.
OPI Validated Score
A 0-100 score calculated across six weighted components under the open OPI standard. Includes the methodology version, assessment tier, and date. Suitable for inclusion in your risk register and SAQ/ROC documentation.
PDF Assessment Report
Structured PDF containing: scope (all tested SLDs and IPs), methodology reference (OPI v1.3.0), attack vectors executed, findings per component, and hardening recommendations. Formatted for QSA submission.
Hardening Evidence
Vendor-specific remediation steps with before and after OPI delta tracking. Demonstrates that identified issues were addressed, satisfying the "remediation activities results" retention requirement in 11.4.1.
Scan Artifacts
Raw scan data including discovered SLDs, CDN/WAF fingerprint results, origin IP exposure findings, and per-vector test results. Retained for 12 months minimum, downloadable at any time.
Who Must Comply
PCI DSS applies to any organization involved in payment card processing.
DDoS attacks against payment infrastructure are a significant source of availability incidents that can trigger PCI DSS Requirement 12.10 (incident response) and affect your compliance standing. Demonstrating tested resilience before an incident is far preferable to explaining an outage after one.
What Your QSA Sees
- A named, versioned, publicly documented testing methodology (OPI v1.3.0, Apache 2.0)
- External testing performed from an independent 24-provider fleet, not your own infrastructure
- Coverage across the full discovered perimeter including origin IPs not declared by the assessor
- L3, L4, and L7 network-layer test results with per-vector findings
- PDF report with scope, methodology, findings, and hardening steps
- Dated OPI score suitable for risk register entry
- Artifact retention satisfying the 12-month documentation requirement
See all compliance frameworks: DDactic Compliance Coverage