[ PCI pentest ]
Pentests for PCI DSS 11.4,after every change.
Agents pentest your payment systems after every change and turn each run into an audit-ready 11.4 report. Fixes are re-tested and coverage never lapses, so you pass audits faster and prove security to customers.
See first findings in 24 hours
Built by the team that secured:
Built by the team that secured:
[ what PCI DSS asks ]
What Requirement 11.4 asks,and what a run gives you.
PCI DSS v4.0 is explicit about penetration testing, and explicit that the annual test comes from a qualified tester. Here is where each part lands.
3 covered by every run · 1 shared with your assessor · 2 not covered
11.4.1 · A defined methodology
A documented methodology, implemented, with results retained for at least 12 months. The same method applied identically on every run, and every run's report kept.
covered by every run
Evidence to keep: methodology, 12 months of reports
11.4.4 · Corrected and re-tested
Exploitable vulnerabilities and weaknesses corrected, then re-tested. Every finding exploited before it is reported, then re-tested on fix, in the same report.
covered by every run
Evidence to keep: finding, fix, re-test
11.4.2 and 11.4.3 · After significant change
Internal and external testing after any significant change. Every release is tested as it ships, so the test after a change has already happened, with its report.
covered by every run
Evidence to keep: report dated to the change
11.4.2 and 11.4.3 · The annual test
At least once every 12 months, by a qualified internal resource or a qualified, organizationally independent third party. Not required to be a QSA or ASV. Parameter gives that tester a current, proven baseline to start from.
shared with your assessor
Evidence to keep: the tester's report
11.4.5 and 11.4.6 · Segmentation
Segmentation controls tested at least annually and after changes, and every six months for service providers. Network work for your annual tester.
not covered
11.3 · Vulnerability scans
Quarterly internal scans and external scans by an Approved Scanning Vendor. Parameter is the exploit-proven layer above an ASV scan, not a replacement for it.
not covered
[ how it works ]
Connect
A repository, a URL with test accounts, or a read-only cloud role. Testing starts within hours. No scoping call, no engagement to book.
Test every release
Agents test the running app, the code behind it, the cloud it runs on, and the packages it depends on, as different users, every time you ship. Every finding is exploited before it is reported.
Hand over the run
Each run produces a report with scope, method, findings, proof, and remediation status. Re-tests happen on fix, so the evidence is never older than the last release.
[ definition ]
What PCI DSS asks of a pentest
PCI DSS v4.0 Requirement 11.4 asks for internal and external penetration testing at least every 12 months and after any significant change, performed by a qualified tester, with exploitable weaknesses corrected and re-tested. Parameter's agents supply the second half of that sentence on every release: the test after each change, the proof, and the re-test. A qualified tester performs the annual test and the segmentation testing, starting from those results.
[ FAQ ]
Frequently asked questionsabout PCI pentest
[ explore ]
Keep reading.The platform, and other frameworks.
AI penetration testing
How the agents work, what they cover, reports, and pricing.
Read more
SOC 2 penetration testing
What a SOC 2 auditor expects from penetration testing, clause by clause, and how a run on every release supplies it.
Read more
ISO 27001 penetration testing
What ISO 27001 controls expect from penetration testing, clause by clause, and how continuous runs supply the evidence.
Read more
FedRAMP penetration testing
What FedRAMP requires of penetration testing, the 3PAO's role, and how continuous testing supports continuous monitoring.
Read more
Not sure which fits?
Tell us what you are shipping and we will scope the test in minutes.
Book a call
Start testing today.
A URL and credentials is all it takes.
First findings land within 24 hours.
















