Cardholder Data Environment
Systems, networks and applications that store, process or transmit card data, assessed as the core of the regulatory scope.
Penetration testing aligned to the PCI DSS testing requirement (11.3 in v3.2.1, now 11.4 in v4.0), covering the cardholder data environment and a recurring test cycle.

PCI DSS treats vulnerability scanning and penetration testing as distinct controls. The ASV (Approved Scanning Vendor) scan covers the external surface on a quarterly cycle; the penetration test, with its own methodology, has to validate the network and application layers, inside and outside the Cardholder Data Environment (CDE), run annually and after any significant change to the payment infrastructure.
Annual certification or SAQ renewal
Significant change to the card environment
Validating CDE segmentation
Acquirer or card brand requirement
The exact composition depends on your PCI DSS level, your card processing model and how the CDE is segmented from the rest of the network.
Systems, networks and applications that store, process or transmit card data, assessed as the core of the regulatory scope.
Confirmation that the controls used to reduce CDE scope really do isolate the card environment from the rest of the corporate network.
Internal and external testing covering network infrastructure as well as the applications that process card transactions.
Recurring execution every 12 months and whenever there is a significant change to CDE topology, applications or controls.
From technical alignment to delivery, the work has to leave context, evidence and next steps visible to everyone involved.




The timeline is designed to fit the window between assessment and delivery to the QSA or acquirer.
Together with your team we map which systems store, process or transmit card data and where the segmented environment ends.
We run the required internal and external tests, including segmentation validation when it is used to reduce scope.
Exploitable vulnerabilities inside the CDE are prioritized so they can be fixed before the certification cycle closes.
We deliver scope, methodology and findings documented in the format assessors and acquirers normally ask for.

The report has to hold up both in the conversation with the QSA and in internal technical prioritization.
Scope, methodology and finding status documented in the format assessors and acquirers expect.
Clarity on whether current controls really isolate the CDE, or whether the compliance scope is larger than assumed.
Findings inside the card environment take priority because of their direct impact on regulated data.
If your question isn't here, talk to the team directly.
Ask on WhatsAppNo. It satisfies one of the standard's technical requirements, but certification also depends on other controls, processes and the full assessment carried out by the QSA or the self-assessment process (SAQ).
No. The ASV scan is a quarterly automated sweep of the external surface performed by an approved vendor. The penetration test is a deeper assessment with its own methodology, run at least annually and after significant changes.
When segmentation is used to reduce CDE scope, PCI DSS requires specific validation that the isolation controls work. That can be part of the same project or a dedicated test.
The standard requires it at least once a year and whenever there is a significant change to the infrastructure, applications or controls that make up the card environment.
Tell us your PCI DSS level, how the CDE is segmented and the timeline of your assessment cycle.
Ready to assess your company's risk?