Precursor Security
Avoid £5K–£100K Monthly Non-Compliance Fees | CREST-Accredited | PCI DSS v4.0.1

PCI DSS Compliance Testing

PCI DSS compliance testing is the independent technical assessment of security controls protecting cardholder data environments (CDE), required by the Payment Card Industry Data Security Standard for any organisation that stores, processes, or transmits payment card data. Required testing includes: annual penetration testing of CDE segmentation under Requirement 11.3/11.4, quarterly external vulnerability scanning by an Approved Scanning Vendor (ASV) under Requirement 11.2, and validation of access controls, encryption, and network segmentation controls. UK merchants failing compliance testing face acquiring bank non-compliance fees of £5,000-£100,000 per month, card brand penalties of up to £500,000 following a breach, and potential card processing suspension. Precursor Security provides CREST-accredited PCI DSS compliance testing for Level 1-4 merchants across the UK.

Precursor Security provides CREST-accredited PCI DSS compliance testing for UK Level 1-4 merchants: annual penetration testing satisfying Requirement 11.3/11.4, quarterly ASV scanning under Requirement 11.2, network segmentation validation, PCI DSS v4.0.1 gap analysis, and SAQ validation to prevent QSA audit failures. Our testing team is 100% UK-based. Reports are formatted to satisfy QSA evidence requirements and are accepted by UK acquiring banks.

CREST Accredited
PCI DSS v4.0.1
Req 11.3 Testing
ASV Scanning
Scroll
3,000+ Assessments DeliveredTriple-CREST Accredited24/7 UK SOC in NewcastleReports Accepted by Insurers & RegulatorsEst. 2018
Non-Compliance Financial Exposure

Any UK merchant storing, processing, or transmitting payment card data is subject to PCI DSS, and non-compliance carries a specific financial structure.

  • Acquiring banks impose monthly non-compliance fees of £5,000–£100,000 (Merchant Level dependent).
  • Card brands (Visa, Mastercard) levy penalties of up to £500,000 following a confirmed breach.
  • Breach remediation costs run £200–£500 per compromised card record.
  • Card processing suspension follows sustained non-compliance. For e-commerce businesses, that is a total revenue stop.
Max monthly bank fee
£100K
Per month, per merchant
Card brand breach penalty
£500K
Visa / Mastercard
Per compromised record
£500
Breach remediation cost
PCI DSS Testing

Your QSA needs evidence. Not a self-assessment.

SAQ self-certification addresses the checkbox. CREST-accredited technical testing produces the evidence that satisfies QSA auditors, acquiring banks, and card brands when compliance is actually challenged.

Book a Scoping Call
SAQ Self-Assessment
Self-certified compliance status
No external technical validation
QSA audit failure risk
SAQ misclassification exposure
Precursor PCI DSS Testing
CREST-accredited evidence package
QSA-accepted testing reports
Guided ASV scan remediation
UK acquiring bank accepted
Non-Compliance Risk

The Cost of PCI Non-Compliance

PCI DSS non-compliance fees and penalties carry a specific financial structure that escalates over time. A single month of acquiring bank fines typically exceeds an entire year of testing investment.

Monthly
£5K-£100K

Non-Compliance Fee

Monthly acquiring bank fines begin immediately when marked non-compliant and continue until compliance is demonstrated.

Breach Risk
£500K

Card Brand Penalty

Visa and Mastercard penalties up to £500,000 following a confirmed breach in a non-compliant environment.

Investment
£5K-£25K

Annual Testing

Comprehensive annual assessment. Most organisations recover testing cost within the first month of avoided fees.

Mapped
Controls
PCI DSSReq 11.3/11.4
ASV ScanningReq 11.2
Access ControlReq 7 & 8
Gap AnalysisAll 12 Reqs
Methodology

PCI DSS Compliance Testing:
How Testing Eliminates Risk

Preventing acquiring bank fines, card brand penalties, and processing suspension through CREST-accredited technical testing against every applicable PCI DSS requirement.

Requirement 11.3

CDE Penetration Testing

Annual penetration testing satisfying PCI DSS Requirement 11.3 and 11.4: validating network segmentation controls separating the Cardholder Data Environment (CDE) from other networks, attempting to bypass firewall rules and VLANs, testing for lateral movement paths into the CDE, and identifying vulnerabilities allowing unauthorised access to cardholder data. Testing covers both external attacker perspective (internet-facing CDE) and internal threat perspective (assumed breach within corporate network), satisfying Requirement 11.4.6 and 11.4.7 for service provider environments. Output includes a technical report formatted to satisfy QSA Requirement 11.4 evidence standards, with findings mapped to specific CDE components and remediation priorities.

Requirement 11.2

Quarterly ASV Scanning

Quarterly PCI compliance scanning of external-facing CDE systems by our Approved Scanning Vendor (ASV) team, satisfying Requirement 11.2. Our ASV scanning service covers external IP ranges and internet-facing components within your CDE scope, providing CVSS-scored vulnerability reports against the PCI DSS clean scan threshold. Critically, we do not stop at the scan result: we triage flagged vulnerabilities by PCI DSS compliance impact, identify false positives eligible for dispute, and provide prioritised remediation guidance to achieve a clean scan attestation within your required timeframe.

Requirements 7 & 8

Access Control & MFA Testing

Testing PCI DSS access control requirements: validating multi-factor authentication for remote access to CDE (Requirement 8.3), testing password policies and complexity (Requirement 8.2), identifying excessive user privileges violating least privilege (Requirement 7), and testing authentication bypass vulnerabilities in payment applications.

CDE Isolation

Network Segmentation Validation

Attempting to access CDE from out-of-scope networks: testing firewall rules for bypasses, attempting VLAN hopping attacks, identifying misconfigured routing allowing unauthorised access, testing wireless network isolation, and validating that application-layer controls prevent CDE access. Failed segmentation means the entire network is in-scope for PCI DSS, significantly expanding compliance burden. Our segmentation testing reports are formatted to satisfy QSA evidence requirements under Requirement 11.3.

PCI DSS v4.0.1

Compliance Gap Analysis

Comprehensive assessment against PCI DSS v4.0.1 requirements: evaluating all 12 requirements and sub-requirements, identifying compliance gaps, testing customized approach implementations, and providing detailed compliance roadmap. We validate logging and monitoring (Requirement 10), incident response procedures (Requirement 12), and security awareness programs with documentation review and technical testing.

Engagement Pipeline

Engagement Workflow

Structured to minimise operational friction and maximise the value of the testing window.

Step 01

CDE Scoping & Discovery

Defining cardholder data environment scope: identifying all systems storing, processing, or transmitting cardholder data, mapping payment card data flows, documenting network segmentation architecture, and understanding connected-to and security-impacting systems. We have scoped CDE environments for UK Level 1 retailers, payment processors, and hospitality groups, and we regularly identify systems initially excluded from scope that are in fact connected-to or security-impacting systems requiring inclusion under PCI DSS v4.0.1.

Step 02

PCI DSS Technical Testing

Comprehensive technical assessment: penetration testing to validate segmentation (Requirement 11.3), vulnerability scanning of CDE systems (Requirement 11.2), testing encryption implementations (Requirements 3 and 4), validating access controls and MFA (Requirements 7 and 8), and testing wireless security where applicable (Requirement 2). Testing covers both external attacker perspective (internet-facing CDE) and internal threat perspective (assumed breach within corporate network), satisfying Requirement 11.4.6 and 11.4.7 for service provider environments.

Step 03

Compliance Validation & Gap Analysis

Assessing compliance with all PCI DSS requirements: reviewing security policies and procedures (Requirement 12), validating vendor management processes (Requirement 12.8), testing incident response capabilities (Requirement 12.10), and evaluating security awareness training programs. We identify gaps between current state and PCI DSS v4.0.1 requirements.

Step 04

Reporting & Remediation Roadmap

Detailed PCI DSS compliance report: technical findings from penetration testing and vulnerability scanning, compliance gap analysis mapped to specific PCI DSS requirements, prioritised remediation roadmap with timelines, and support for QSA assessment preparation. We provide evidence documentation and Attestation of Compliance (AOC) support for Level 1-4 merchants. Our reports are structured to meet QSA evidence requirements under PCI DSS v4.0.1.

Pricing

PCI DSS Testing Pricing

PCI DSS compliance testing cost depends on your merchant level and CDE complexity. All engagements are fixed-price, quoted after a free scoping call, with no hidden day rates.

Level 3-4 Merchants

SAQ-eligible, lower transaction volumes

Annual pen testing, ASV scanning, segmentation validation, gap analysis

£5,000 – £12,000+

per year

Level 2 Merchants

SAQ or QSA-validated, 1-6M transactions

Full assessment plus formal gap analysis for acquiring bank submission

£10,000 – £20,000+

per year

Level 1 Merchants

Mandatory RoC by QSA, 6M+ transactions

Comprehensive technical evidence package supporting QSA assessment

£15,000 – £25,000+

per year

Compare to monthly non-compliance fees of £5,000-£100,000. Most organisations recover testing cost within the first month of avoided fees.

Get a Quote
Ecosystem

Beyond Compliance.
Close the Loop.

PCI DSS Requirements 6 and 11.3 mandate penetration testing and web application security assessment. Our CREST-accredited testers deliver Requirement 11.3 compliant testing, and our 24/7 Managed SOC continuously monitors your CDE between annual assessments.

Explore Penetration Testing
Service Catalogue

Full Penetration Testing Catalogue

Comprehensive penetration testing services tailored to your environment.

Free Scoping Call

Ready to eliminate your PCI compliance gap?

Book a free scoping call. We confirm your merchant level and CDE scope, identify which testing requirements apply, and provide a fixed-price quote. No obligation. No day-rate surprises.

CREST Accredited
Fixed Pricing
UK-Based Team

PCI DSS Compliance Testing: Common Questions

Pricing, merchant levels, testing requirements, and how our compliance testing compares to SAQ self-assessment.

Because an SAQ is self-certified and unvalidated. Misclassification, unchecked controls, and Requirement 11.3 ambiguity all create audit and penalty exposure that external testing removes.

  • SAQ eligibility misclassification is common (unaggregated transaction volume, wrong SAQ type) and, when caught in an acquiring-bank audit, triggers £5K-£50K monthly penalties backdated to the misclassification date plus a mandatory £15K-£50K QSA assessment.
  • Self-assessed controls (segmentation, encryption, access) go externally unvalidated. Banks increasingly run spot-check audits that fail these, forcing immediate non-compliance status with penalties until remediation.
  • Requirement 11.3 penetration-testing applicability is genuinely ambiguous under SAQ guidance; many SAQ-C/D merchants skip it assuming attestation suffices, then discover the gap at audit.

The ROI is stark: external testing is £5K-£15K for a Level 3-4 merchant, versus £5K-£10K monthly penalties if an audit fails SAQ validation (£60K-£120K a year), £50K-£500K in card-brand fines after a breach, and the business-continuity risk of processing suspension.

PCI DSS compliance testing is the independent technical assessment of security controls protecting cardholder data environments (CDE), required by the Payment Card Industry Data Security Standard for any organisation that stores, processes, or transmits payment card data. Required testing includes: annual penetration testing of CDE segmentation under Requirement 11.3/11.4, quarterly external vulnerability scanning by an Approved Scanning Vendor (ASV) under Requirement 11.2, and validation of access controls, encryption, and network segmentation controls. UK merchants failing compliance testing face acquiring bank non-compliance fees of £5,000-£100,000 per month, card brand penalties of up to £500,000 following a breach, and potential card processing suspension. Precursor Security provides CREST-accredited PCI DSS compliance testing for Level 1-4 merchants across the UK.

Any organisation storing, processing, or transmitting payment card data must comply with PCI DSS: merchants (e-commerce sites, retail stores, restaurants), payment processors and gateways, payment service providers, and hosting providers with CDE access. Compliance level (1-4) depends on annual transaction volume. All levels require vulnerability scanning; Level 1 merchants require annual penetration testing. Fully outsourcing card processing to a third-party payment service provider (PSP) reduces but does not eliminate your PCI DSS obligations. SAQ-A applies only if you use a fully outsourced, PCI DSS-compliant payment page and store no cardholder data. If your checkout redirects to a third-party page but your server executes any part of the payment flow, you fall under SAQ-A-EP or higher, requiring penetration testing. We confirm your actual scope before testing begins.

Requirement 11.3 mandates annual penetration testing of CDE and segmentation controls. Testing includes: network layer testing (firewall rule validation, VLAN segmentation), application layer testing (web app and payment application vulnerabilities), attempting to access cardholder data from untrusted networks, and validating that segmentation prevents lateral movement into CDE. Testing must follow the PCI DSS-defined penetration testing methodology, covering both external attacker and internal threat perspectives. PCI DSS v4.0.1 also introduced Requirement 11.4 enhancements including Requirement 11.4.7 for service providers, requiring penetration testing to include multi-tenant separation validation. A test carried out before your current QSA assessment period does not satisfy the requirement for the new period.

ASV (Approved Scanning Vendor) scanning is quarterly automated vulnerability scanning of external-facing CDE systems to identify known CVEs and misconfigurations (Requirement 11.2). Penetration testing is annual manual testing attempting to exploit vulnerabilities and bypass segmentation (Requirement 11.3). ASV scanning is continuous monitoring; penetration testing validates real-world exploitability and segmentation effectiveness. Most Approved Scanning Vendors provide scan results without remediation support, leaving your team to interpret CVSS scores and prioritise fixes without PCI DSS context. Our ASV service includes guided remediation: we triage flagged vulnerabilities by PCI DSS impact, identify false positives eligible for dispute with supporting documentation, and provide fix-first guidance to achieve a clean scan within your 30-90 day remediation window.

We test segmentation by attempting to access CDE from out-of-scope networks: testing firewall rules for bypasses, attempting VLAN hopping attacks, identifying misconfigured routing allowing unauthorised access, testing wireless network isolation, and validating that application-layer controls prevent CDE access. Failed segmentation means the entire network is in-scope for PCI DSS, significantly expanding compliance burden. We also perform internal network segmentation testing from an assumed-breach position to validate that lateral movement into the CDE is blocked. Our segmentation testing reports are formatted to satisfy QSA evidence requirements under Requirement 11.3.

Yes. PCI DSS v4.0.1 is now the current standard, with all organisations required to be fully compliant. We provide comprehensive PCI DSS v4.0.1 compliance support: gap analysis against current requirements, technical testing validating new requirements (customized approach implementations, enhanced MFA), penetration testing satisfying Requirement 11.3/11.4, ASV vulnerability scanning (Requirement 11.2), and compliance roadmaps for maintaining ongoing PCI DSS v4.0.1 compliance. Our reports reference v4.0.1 requirements by number throughout, ensuring your QSA has the evidence documentation they need.

You receive: comprehensive PCI DSS technical assessment report with findings mapped to specific requirements, penetration testing report (Requirement 11.3 evidence), ASV scan results (Requirement 11.2 evidence), compliance gap analysis against PCI DSS v4.0.1, prioritised remediation roadmap with timelines, and documentation supporting QSA assessment. We provide evidence packages suitable for submission to acquiring banks and card brands. Our reports are structured to meet QSA evidence requirements and have been accepted by UK acquiring bank compliance teams.

PCI non-compliance fees are levied by your acquiring bank and the card brands, not a single central authority, which is why they vary widely and are often poorly understood.

  • Acquiring-bank fees: typically £5,000/month (smaller Level 3-4 merchants) up to £100,000/month (Level 1 or elevated-risk), starting when you're marked non-compliant after a failed ASV scan, overdue pen test, or declined RoC, and continuing until compliance is demonstrated.
  • Card-brand penalties: £50,000-£500,000 after a confirmed breach in a non-compliant environment, depending on records compromised. These are separate from acquiring-bank fees and can apply simultaneously.
  • Processing suspension: sustained non-compliance (typically 6-12 months) can lead your bank to suspend or terminate card processing, an immediate revenue stop for e-commerce.

Compliance testing at £5,000-£25,000 annually eliminates the monthly fee exposure and the far larger breach-penalty risk. Most organisations recover the cost within the first month of avoided fees.

PCI DSS compliance testing cost in the UK depends primarily on your merchant level and the scope of services required. Level 3-4 merchants (SAQ-eligible, lower transaction volumes): £5,000-£12,000 for a comprehensive annual assessment including penetration testing, ASV scanning, segmentation validation, and gap analysis documentation. Level 2 merchants (SAQ or QSA-validated): £10,000-£20,000 depending on CDE complexity, number of external IP ranges, and whether a formal gap analysis report is required for acquiring bank submission. Level 1 merchants (mandatory RoC by QSA): Penetration testing and ASV scanning as standalone technical components are £15,000-£25,000 annually. The QSA engagement itself (not our service) adds £20,000-£60,000 depending on the QSA firm. We provide the technical testing evidence that supports the QSA's assessment. These figures cover external and internal penetration testing of the CDE, quarterly ASV scanning (four scan cycles), network segmentation validation, and a compliance evidence package formatted for QSA submission. Our scoping call establishes your exact requirement before any commercial commitment. Compare testing cost to the alternative: a single month of acquiring bank non-compliance fees (£5,000-£100,000) typically exceeds an entire year of compliance testing investment.

PCI merchant levels are set by annual card transaction volume, and they determine both how you validate compliance and what testing you need.

  • Level 1 (over 6M transactions, or any merchant post-breach): mandatory annual Report on Compliance by a QSA, annual penetration testing (11.3/11.4), and quarterly ASV plus internal scans. Self-assessment is not permitted.
  • Level 2 (1-6M): annual SAQ or QSA-conducted RoC at the bank's discretion; penetration testing typically required for SAQ-D or segmented CDE; quarterly ASV scanning.
  • Level 3 (20,000-1M e-commerce): annual SAQ and quarterly ASV; penetration testing required if the CDE is segmented from the corporate network (common for SAQ-C/D).
  • Level 4 (under 20,000 e-commerce): annual SAQ and quarterly ASV; requirements vary by SAQ type, and many underestimate their obligations.

Transaction volumes aggregate across all merchant IDs, subsidiaries, and brands; reclassification from Level 2 to Level 1 forces an immediate move to RoC-based compliance. We confirm your correct level during scoping.

PCI DSS Requirement 11.4 mandates penetration testing at least annually and after any significant infrastructure or application change. Annual requirement: At minimum, a full penetration test of the CDE and its segmentation controls must be completed within each 12-month assessment period. The test must cover both external (internet-facing) and internal (within the network perimeter) perspectives. After significant changes: If you deploy new payment systems, reconfigure network segmentation, migrate to a new hosting provider, add new payment channels, or make significant changes to your CDE architecture, penetration testing is required before returning to production, regardless of where you are in the annual cycle. PCI DSS v4.0.1 change: Requirement 11.4.7 for service providers specifically requires penetration testing to include multi-tenant separation validation. If you are a payment service provider or hosting provider, this adds scope to your testing requirement. Testing performed outside your current QSA assessment period does not carry forward. If your last test was completed 14 months ago, even if it was thorough and you have not changed your infrastructure, you are overdue and technically out of compliance with Requirement 11.4. We regularly see this as an undetected compliance gap during scoping calls.

A PCI DSS audit is the formal review validating that your controls protecting cardholder data meet the standard. The form it takes depends on your merchant level.

  • Level 1: a formal Report on Compliance (RoC) by a QSA, an independent firm accredited by the PCI SSC, who reviews documentation, interviews staff, and validates all 12 requirements. Submitted to the acquiring bank annually.
  • Level 2-4: usually a Self-Assessment Questionnaire (SAQ) completed internally, though banks may run spot-check audits (often after industry breaches) that require external technical validation of your claims.
  • Technical testing (penetration testing, ASV scanning) is evidence within the audit, not the audit itself, submitted to a QSA or alongside your SAQ for Requirements 11.2 and 11.4.

Precursor produces that technical evidence, penetration testing reports, ASV scan results, segmentation validation, and v4.0.1 gap analysis, accepted by major UK acquiring banks. We work alongside QSA firms but do not act as a QSA.