Services

PCI DSS, penetration testing and ASV scanning

QSA-led PCI DSS v4.0.1 assessments, penetration testing and managed ASV scanning, for service providers and merchants at their required validation level.

PCI DSS v4.0.1

PCI DSS compliance

From your first assessment to each one after, including a move from another QSA company.

PCI DSS applies to any business that stores, processes or transmits account data, and to the systems, people and processes that could affect its security, even when payment processing is outsourced. How you validate depends on your acquirer and the payment brands, and on how your business handles payments:

  • Service providers usually need a Report on Compliance (ROC) from a QSA company, or SAQ D for Service Providers where a payment brand allows it.
  • Merchants mostly complete the Self-Assessment Questionnaire (SAQ) that matches how they accept payments, on their own or with help from a QSA. The largest need a ROC from a QSA company.

Either way, you sign an Attestation of Compliance (AOC).

Start here Free consultation. Tell us about your environment and where you are today. We explain which requirements apply and how validation works for your business. Request a free consultation →

How it works

New to PCI DSS? Start at Scope. Already validated? Join at Assess.

New to PCI DSS? Start at Scope.
Already validated? Join at Assess.
1

Scope

We help you identify or confirm your scope, validate it at each assessment, and review any segmentation that keeps systems out of scope. Req 12.5.2

2

Readiness

We compare your controls with the requirements that apply and help you identify where the gaps are, if there are any. You'll know what each requirement expects, and what it will take, before your assessment begins.

3

Remediate

Your team closes the gaps. We answer questions on what each requirement expects along the way.

4

Assess

The core of the engagement. We give you a clear list of the evidence we need, review and validate what you provide, and interview your team.

5

Attest

We write your ROC, or help you finalize your SAQ. Then you sign your Attestation of Compliance (AOC), the document your acquirer, payment brands and customers ask for.

6

Maintain

The partnership continues all year: guidance whenever your scope or business changes, compliance roadmap assistance, and recurring scan and testing services.

Repeats annually

Req 11.4

Penetration testing for PCI DSS compliance

Testing that meets PCI DSS requirements, where your validation requires it.

Where it applies, PCI DSS requires internal and external penetration testing at least once every 12 months and after any significant infrastructure or application upgrade or change. Testing follows a documented methodology that covers the entire CDE perimeter and critical systems at both the network and application layers, and testers must be qualified and organizationally independent. You receive risk-ranked findings, an executive summary and statement of scope, reporting ready for your PCI DSS assessment, and a retest to verify corrections.

Our methodology aligns with NIST SP 800-115, the Penetration Testing Execution Standard (PTES) and OWASP guidance, including the OWASP Top 10:2025 and the OWASP API Security Top 10.

Internal and external network-layer testing

Tests of the network devices, servers and operating systems that support the CDE: from inside the CDE, into it from trusted and untrusted networks, including wireless, and across the exposed external perimeter.

Web application and API testing

Web applications and APIs in or connected to the CDE, tested for, at a minimum, the vulnerabilities listed in Req 6.2.4, the OWASP Top 10 and the OWASP API Security Top 10.

Cloud testing

Security controls, configurations and access for CDE components hosted in AWS, Azure, GCP, hybrid and multi-cloud environments.

Segmentation testing

Confirms that segmentation controls are operational and effective and isolate the CDE from all out-of-scope systems. Required only if you use segmentation to reduce scope.

Gray-box and white-box testing

We test with partial or full knowledge of your environment, such as credentials, network diagrams and documentation, so the time goes to real exposure. PCI SSC guidance notes that PCI DSS penetration tests are typically gray-box or white-box.

Multi-tenant service providers

Evidence for your customers' external testing and testing of the logical separation between customer environments every six months. Req 11.4.7, A1.1.4

Compliance and assurance

Penetration testing for other compliance

Testing for SOC 2 Type II, customers, partners and internal assurance.

Simulated real-world attacks that show how an attacker could get in, move through your environment and reach critical systems and data, so you can fix weaknesses before they are exploited. The results provide evidence for SOC 2 Type II and other compliance frameworks, cyber insurance requirements, customer and partner due diligence, and internal risk management.

Our testing follows NIST SP 800-115, PTES and OWASP guidance, with risk-ranked findings, an executive summary, reporting ready for your management, auditors, customers and partners, and a retest to verify fixes. We agree scope and rules of engagement with you, and test in gray-box or white-box mode, with the credentials and documentation that make the most of your testing time.

Internal network testing

Testing from inside your network, as an attacker with a foothold or a malicious insider would, to find paths to sensitive systems and data.

External network testing

Testing of your Internet-facing systems and services to find what an outside attacker could reach and exploit.

Web application and API testing

Testing of your web applications and APIs against the OWASP Top 10:2025 and the OWASP API Security Top 10.

Mobile application testing

Testing of your iOS and Android apps and the services behind them.

Cloud testing

Review and testing of security controls, configurations and access in AWS, Azure, GCP, hybrid and multi-cloud environments.

Wireless testing

Testing of your wireless networks for weak encryption and authentication, rogue access points, and paths from wireless into your internal network.

Req 11.3.2

ASV scanning

Managed quarterly ASV scans, where your PCI DSS validation requires them.

Going direct to a scanning vendor leaves your team to handle scoping, scheduling, false-positive disputes and rescans. With Ascend, the scanning life cycle is managed for you.

Where it applies, PCI DSS requires passing external vulnerability scans by a PCI SSC Approved Scanning Vendor (ASV) at least once every three months. We manage the program through the Ascend ASV Scanning Portal: the ASV performs and attests the scans, and our team coordinates scope, reviews findings and helps your team prioritize fixes. Scope covers the Internet-facing system components in your CDE or that provide a path into it.

A passing ASV scan satisfies the external scanning requirement. Together with penetration testing and the rest of your PCI DSS validation, it completes the picture.

Quarterly scans

External scans of the licensed IP addresses and domains in scope, scheduled and tracked so each quarter is covered.

Rescans until passing

A scan fails if any component has a vulnerability scored 4.0 or higher by CVSS, or an automatic failure. We rescan licensed targets until you pass, with no cap on rescan cycles.

Findings review

We review the results, manage false-positive disputes, and help your team prioritize fixes.

Scan reports and attestation

The ASV scan report, including the Attestation of Scan Compliance, for your acquirer, assessor or customers.

Internal vulnerability scans

We run your quarterly internal scans too, so both PCI DSS scanning requirements are covered. Req 11.3.1

Need SOC, ISO or HIPAA work? Our affiliated firm, Ascend Audit & Advisory, provides attestation and audit services with the same consultative approach.

Visit Ascend Audit & Advisory

Start with a free consultation.

Tell us about your compliance objectives, whether PCI DSS, penetration testing or ASV scanning. We'll consult with you on the requirements that apply and how to meet your objectives.

Request a consultation