PCI DSS 4.0 Compliance

Meet Requirement 11 with validated network testing

PCI DSS 4.0 requires annual external and internal penetration testing with a documented methodology covering your full CDE perimeter. DDactic delivers all of it, with OPI Validated scores as QSA-ready evidence.

What PCI DSS 4.0 Requires

PCI DSS 4.0 (effective March 31, 2024) tightens penetration testing requirements for any organization that stores, processes, or transmits cardholder data. Requirement 11 covers security testing of systems and networks.

Requirement 11.3.1
"External penetration testing is performed: At least once every 12 months. After any significant infrastructure or application upgrade or change. By a qualified internal resource or qualified external third party. Organizational independence of the tester exists."
PCI DSS v4.0, Requirement 11.3.1
Requirement 11.3.2
"Internal penetration testing is performed at least once every 12 months and after any significant infrastructure or application upgrade or change."
PCI DSS v4.0, Requirement 11.3.2
Requirement 11.4.1 (new in v4.0)
"A penetration testing methodology is documented, implemented, and includes: industry-accepted penetration testing approaches; coverage for the entire CDE perimeter and critical systems; testing from both inside and outside the network; network-layer penetration tests that encompass all components that support network functions as well as operating systems; includes review and consideration of threats and vulnerabilities experienced in the last 12 months; specifies retention of penetration testing results and remediation activities results for at least 12 months."
PCI DSS v4.0, Requirement 11.4.1

DDoS attacks are a primary availability threat for payment infrastructure. A CDN or WAF that has not been validated under simulated attack conditions provides no assurance to your QSA. PCI DSS 4.0 now explicitly requires a documented methodology, not just a point-in-time test.

How DDactic Maps to Requirement 11

Every DDactic assessment runs against an open, documented methodology (OPI v1.3.0, Apache 2.0 licensed) and produces structured artifacts your QSA can review.

PCI DSS Requirement Section DDactic Feature
Annual external penetration test 11.3.1 DDoS simulation from 24-cloud-provider external fleet, repeatable on demand
Independent tester 11.3.1 DDactic operates independently from your network; no credentials or agents required
Internal exposure discovery 11.3.2 Passive recon discovers origin IPs exposed despite CDN/WAF (internal infrastructure visible externally)
Documented methodology 11.4.1 OPI v1.3.0 specification, Apache 2.0 licensed, published at github.com/DDactic/opi-standard
Full CDE perimeter coverage 11.4.1 Attack surface discovery maps all externally exposed SLDs and subdomains, not just declared targets
Network-layer penetration tests 11.4.1 L3/L4 simulation: SYN floods, UDP floods, ICMP amplification, DNS amplification, NTP reflection
Application-layer penetration tests 11.4.1 L7 simulation: HTTP floods, Slowloris, cache bypass, API abuse, HTTP/2 Rapid Reset, QUIC vectors
12-month artifact retention 11.4.1 OPI Validated PDF report and scan artifacts retained in DDactic platform for download at any time
Remediation documentation 11.4.1 Vendor-specific hardening commands (Cloudflare, Akamai, AWS Shield, Imperva) with before/after OPI delta
Threats from last 12 months 11.4.1 Attack library updated continuously; HTTP/2 Rapid Reset (CVE-2023-44487), QUIC amplification, BoT evasion variants included

Evidence DDactic Produces

Every completed assessment generates a structured evidence package your QSA can review without requiring DDactic involvement.

OPI Validated Score

A 0-100 score calculated across six weighted components under the open OPI standard. Includes the methodology version, assessment tier, and date. Suitable for inclusion in your risk register and SAQ/ROC documentation.

74
OPI Validated
C
Adequate

PDF Assessment Report

Structured PDF containing: scope (all tested SLDs and IPs), methodology reference (OPI v1.3.0), attack vectors executed, findings per component, and hardening recommendations. Formatted for QSA submission.

Hardening Evidence

Vendor-specific remediation steps with before and after OPI delta tracking. Demonstrates that identified issues were addressed, satisfying the "remediation activities results" retention requirement in 11.4.1.

Scan Artifacts

Raw scan data including discovered SLDs, CDN/WAF fingerprint results, origin IP exposure findings, and per-vector test results. Retained for 12 months minimum, downloadable at any time.

Who Must Comply

PCI DSS applies to any organization involved in payment card processing.

Online retailers (e-commerce) Payment processors Banks and issuers Acquirers Hosting providers handling CHD SaaS platforms with payment flows Fintech companies Service providers to merchants

DDoS attacks against payment infrastructure are a significant source of availability incidents that can trigger PCI DSS Requirement 12.10 (incident response) and affect your compliance standing. Demonstrating tested resilience before an incident is far preferable to explaining an outage after one.

What Your QSA Sees

  • A named, versioned, publicly documented testing methodology (OPI v1.3.0, Apache 2.0)
  • External testing performed from an independent 24-provider fleet, not your own infrastructure
  • Coverage across the full discovered perimeter including origin IPs not declared by the assessor
  • L3, L4, and L7 network-layer test results with per-vector findings
  • PDF report with scope, methodology, findings, and hardening steps
  • Dated OPI score suitable for risk register entry
  • Artifact retention satisfying the 12-month documentation requirement

QSA-Ready Network Testing, Starting Free

Run a free passive scan to see your exposed attack surface. Upgrade to OPI Validated for a full PCI DSS Requirement 11 evidence package.

Run Free Scan

See all compliance frameworks: DDactic Compliance Coverage