main logo icon

Published on

September 25, 2026

|

17 min read

Best PCI DSS Penetration Testing Companies (2026): Payment Processors, PSPs and Merchants Compared

Ranked guide to the best PCI DSS penetration testing companies in 2026 for payment processors, PSPs and merchants in the US and Canada, with what Requirement 11.4, the card brands, the RPAA, NYDFS and the FTC Safeguards Rule require.

Arafat Afzalzada

Arafat Afzalzada

Founder

Web App SecurityNetwork Security

Summarize with AI

ChatGPTPerplexityGeminiGrokClaude

TL;DR

PCI DSS v4.0 added 64 new requirements, and the 51 that were future-dated became mandatory on 31 March 2025, so every assessment since has had to consider the payment page script controls in 6.4.3 and 11.6.1, multi-tenant testing support in 11.4.7 and the six-monthly tenant separation test in Appendix A1.1.4. Requirement 11.4 sets internal and external penetration testing at least every 12 months and after significant change, segmentation testing every 12 months for everyone and every six months for service providers, and a mandatory retest. The tester must be qualified and organizationally independent and is "not required to be a QSA or ASV". Mastercard classes every payment facilitator above 300,000 transactions a year as a Level 1 service provider. In Canada, the Retail Payment Activities Regulations have required a documented PSP testing methodology since 8 September 2025, and the Bank of Canada's guideline names penetration tests for the more interconnected PSPs. NYDFS 500.5(a)(1) reaches licensed money transmitters, and the FTC Safeguards Rule reaches non-bank companies that move consumer money. The best PCI DSS penetration testing companies in 2026 are Stingrai, Coalfire, Praetorian, VikingCloud, SecurityMetrics, NetSPI, TrustedSec, ControlCase, Schellman, A-LIGN, Bishop Fox and LevelBlue. Every vendor entry links to the vendor's own page, and every accreditation was checked on the CREST Marketplace or the PCI Security Standards Council's own listings on 25 September 2026.

PCI DSS v4.0 introduced 64 new requirements, and 51 of them were future-dated until 31 March 2025, according to the PCI Security Standards Council. Every assessment completed since has had to consider all of them, including the payment page script controls in Requirements 6.4.3 and 11.6.1, multi-tenant testing support in 11.4.7 and the six-monthly tenant separation test in Appendix A1.1.4. In Canada, the testing provisions of the Retail Payment Activities Regulations took effect on 8 September 2025. For a processor or PSP operating on both sides of the border, the penetration test is now evidence in two files at once.

Where Stingrai fits: Stingrai is a CREST-accredited penetration testing service provider at firm level, founded in 2021 and headquartered in Toronto with a London office. Two named penetration testers holding OSCE³, OSWE, OSEP, CREST CRT and CISSP run each engagement, reviewed by the team lead and an engagement partner, backed by 18 published CVEs across the team and bug bounty Hall of Fame listings at PaySafe, the US Federal Reserve, Apple, Google and the US Department of Defense. For a payments business that means payment APIs, webhooks and tokenization tested as every merchant, partner and admin role, internal testing that starts outside the cardholder data environment and tries to get in, and segmentation tested method by method on the six-monthly service provider clock, one-time or continuously through the PTaaS portal, with retesting and an attestation letter included. Published pricing is US$3,000 for an Autonomous Pentest and US$6,800 for a Hybrid Pentest covering one web application and its APIs (pricing); cardholder data environment scopes are quoted.

This is the buyer's ranking for processors, PSPs and payment facilitators, acquirers and issuer-processors, Level 1 and Level 2 merchants, and SaaS platforms that embed payments, in the United States and Canada. The clause-by-clause treatment of Requirement 11.4 lives in the PCI DSS penetration testing requirements guide. Every vendor page cited was checked on 25 September 2026.

Quick answer: who are the best PCI DSS penetration testing companies in 2026?

The best PCI DSS penetration testing companies in 2026 are Stingrai, Coalfire, Praetorian, VikingCloud, SecurityMetrics, NetSPI, TrustedSec, ControlCase, Schellman, A-LIGN, Bishop Fox and LevelBlue. Stingrai ranks first: firm-level CREST accreditation, two named penetration testers per engagement holding OSCE³, OSWE, OSEP, CREST CRT and CISSP, and payment APIs, webhooks, tokenization, internal networks and every segmentation method tested one-time or continuously, with retesting and an attestation letter included. Coalfire follows for CREST accreditation alongside QSA, forensic investigator, 3DS, P2PE and PIN assessor roles, Praetorian for a payment-gateway testing practice with retesting at no additional cost, and VikingCloud for a payments-native assessor with an in-house testing practice.

Comparison chart of what PCI DSS, the card brands, PCI 3DS, the RPAA, NYDFS and the FTC Safeguards Rule each ask of a penetration test in 2026

What payment companies are actually required to test

Seven regimes show up in payments procurement. Four name penetration testing outright: PCI DSS, PCI 3DS, NYDFS and the FTC Safeguards Rule. The card brands decide who reads the evidence, Canada's retail payments law asks for testing without naming the technique, and PCI PIN shapes the scope.

What does PCI DSS Requirement 11.4 require of a payment company?

Requirement 11.4 of PCI DSS v4.0.1 reads: "External and internal penetration testing is regularly performed, and exploitable vulnerabilities and security weaknesses are corrected."

  • 11.4.1 requires a documented nine-element methodology covering the entire cardholder data environment (CDE) perimeter and critical systems, segmentation validation and application-layer testing to 6.2.4. Internal testing means testing "from both inside the CDE and into the CDE from trusted and untrusted internal networks."

  • 11.4.2 and 11.4.3 require internal and external testing "at least once every 12 months" and "after any significant infrastructure or application upgrade or change."

  • 11.4.4 requires exploitable findings to be corrected, and "penetration testing is repeated to verify the corrections."

  • 11.4.5 requires segmentation testing every 12 months and after any segmentation change, "covering all segmentation controls/methods in use." 11.4.6 makes it "at least once every six months" for service providers.

  • 11.4.7 requires multi-tenant service providers to support customers' external testing, with redacted evidence or prompt access. Appendix A1.1.4 adds a separate tenant separation test "at least once every six months."

The glossary settles who carries the service provider clock: a service provider "includes payment gateways, payment service providers (PSPs), and independent sales organizations (ISOs)," and multi-tenant service providers include SaaS platforms and "connections to payment gateways and processors."

Timeline of a PCI DSS service provider's testing year, showing annual penetration tests, six-monthly segmentation and tenant separation tests, quarterly scans and weekly payment page checks

What do Requirements 6.4.3 and 11.6.1 require of a payment page?

Requirement 6.4.3 requires every payment page script to be authorized, integrity-assured and inventoried "with written business or technical justification." Requirement 11.6.1 requires a change- and tamper-detection mechanism alerting on unauthorized modification to "the security-impacting HTTP headers and the script contents of payment pages as received by the consumer browser," at least weekly or at a frequency set by targeted risk analysis. Both were best practice until 31 March 2025.

For processors, the applicability notes matter most: scripts in a processor's embedded payment form "are the responsibility of the TPSP/payment processor to manage," and merchants "should expect the TPSP/payment processor to provide evidence." On 30 January 2025 the Council removed 6.4.3 and 11.6.1 from SAQ A, adding an eligibility criterion that merchants "confirm their site is not susceptible to attacks from scripts," while the underlying requirements stay in force. Neither is a penetration test. A good test attacks both: enumerate what loads on checkout, try to inject a script through the tag manager, and see whether the alert fires.

Does a PCI penetration tester have to be a QSA?

No. Requirements 11.4.2, 11.4.3, 11.4.5 and 11.4.6 each require organizational independence of the tester, "(not required to be a QSA or ASV)." The Council's Penetration Testing Guidance says "the penetration tester must be organizationally separate from the management of the target systems," and that an assessing firm "cannot perform the penetration test if they were involved in the installation, maintenance, or support of target systems." It adds that "the PCI SSC does not validate or endorse" certifications, and that qualifications "cannot be met by certifications alone."

Role

What it does in a PCI program

Needed for the 11.4 test?

Qualified Security Assessor (QSA)

Assesses the entity and signs the Report on Compliance

No

Approved Scanning Vendor (ASV)

Runs the quarterly external scans under 11.3.2

No

Penetration tester

Performs 11.4.2 to 11.4.7 testing as a qualified, independent party

Yes

Qualified PIN Assessor (QPA)

Assesses against the PCI PIN Security Requirements

No

PCI 3DS assessor

Assesses 3DS Server, ACS and Directory Server environments

No

PCI Forensic Investigator (PFI)

Investigates a suspected account data compromise

No

A QSA firm may test your environment, and several firms below hold both roles; settle independence in writing. Where the tester is an offensive security firm outside the assessment, such as Stingrai, Praetorian or NetSPI, independence from the assessment is structural.

What do Visa and Mastercard require of processors, PSPs and merchants?

The card brands do not add a test. They decide who reads yours. Visa's Account Information Security Program sets merchant level by "total Visa transaction volume over a 12-month period" and requires issuers and acquirers to "ensure all their service providers demonstrate PCI DSS compliance at least every 12 months."

Mastercard's Site Data Protection program names payments companies directly. Every third-party processor, token service provider, 3-D Secure service provider and merchant payment gateway is a Level 1 service provider, as is every payment facilitator with "more than 300,000 total combined Mastercard and Maestro transactions annually." Level 1 service providers validate annually through a Report on Compliance by a QSA, and 3-D Secure service providers validate against PCI 3DS every two years. Level 2 merchants completing SAQ A, A-EP or D must also engage a QSA or Internal Security Assessor. In Canada, Moneris applies the same four merchant levels. At Level 1 an assessor reads your 11.4 evidence line by line, so the scope of work, segmentation results by method and retest records must exist as separate artifacts.

Do PCI 3DS and PCI PIN require penetration testing?

PCI 3DS does. Part 1 of the PCI 3DS Core Security Standard, reproduced in the Council's 3DS reporting template, states "Penetration tests are performed at least annually" (P1-4.2.5) by "qualified personnel" (P1-4.2.6), with high-risk findings "addressed within one month" (P1-4.2.7). A 3DS entity can leverage its PCI DSS assessment for Part 1.

The PCI PIN Security Requirements, version 3.1 since March 2021, cover "the secure management, processing, and transmission of PIN data" at ATMs and POS terminals and are assessed by a QPA. Their relevance to the test is scope: hardware security modules and PIN translation paths sit inside or beside the CDE, so the 11.4 methodology must reach the networks around them without touching live keys.

What does Canada's Retail Payment Activities Act require of a PSP?

Section 17 of the Retail Payment Activities Act requires a payment service provider to maintain "a risk management and incident response framework." Section 9 of the Regulations requires a testing methodology "for the purpose of identifying gaps in the effectiveness of, and vulnerabilities in" that framework: proportionate to the PSP's impact, covering high-likelihood and high-impact risks and third-party reliance, setting out "the frequency and scope of testing," and testing before material change, with a record of each test. Section 10 adds an independent review every three years for PSPs with an auditor. The registration provisions took effect on 1 November 2024, and sections 5 to 23 on 8 September 2025.

The Regulations never name penetration testing. The Bank of Canada's guideline, Operational risk and incident response, does: more "ubiquitous or interconnected PSPs could adopt additional testing for cyber and information technology risks, including penetration tests," and "qualified parties should conduct specialized testing, such as penetration testing." Testing "conducted for other purposes" can count if it meets the section 9 objectives, so one well-scoped PCI engagement can serve both files. Bank-owned acquirers also answer to OSFI Guideline B-13, covered in the banking and credit union ranking.

Does NYDFS Part 500 apply to money transmitters?

Yes, if they are licensed in New York. 23 NYCRR 500 covers anyone operating under a license "under the Banking Law, the Insurance Law or the Financial Services Law," and money transmitters are licensed under Article 13-B of the Banking Law. Section 500.5(a)(1) requires "penetration testing of their information systems from both inside and outside the information systems' boundaries by a qualified internal or external party at least annually." Entities under the 500.19(a) limited exemption, based on headcount, revenue or assets, are exempt from 500.5. The NYDFS penetration testing guide covers the rest.

Does the FTC Safeguards Rule require penetration testing for payment companies?

Yes, for non-bank financial institutions under FTC jurisdiction without effective continuous monitoring. 16 CFR 314.4(d)(2) requires "annual penetration testing of your information systems," plus vulnerability assessments every six months. The definitions bring payments in: "a business that regularly wires money to and from consumers is a financial institution." A merchant is not one merely because it accepts cards it did not issue, and section 314.6 exempts institutions holding data on fewer than 5,000 consumers from the testing paragraph.

Regime

Names penetration testing?

Clock

Who reads the evidence

PCI DSS 11.4.2 and 11.4.3

Yes

12 months and after significant change

A QSA in a Report on Compliance, or the entity in an SAQ

PCI DSS 11.4.5, 11.4.6 and A1.1.4

Yes, segmentation and tenant separation

12 months for all; six months for service providers

Same

PCI DSS 6.4.3 and 11.6.1

No, testable controls

Tamper checks weekly or per risk analysis

Same, and merchants ask their processor

Visa AIS and Mastercard SDP

No, validation programs

Annual; 3DS service providers every two years

Acquirers and the card brands

PCI 3DS Part 1

Yes

At least annually

A PCI 3DS assessor

RPAA and RPAR

Only in the Bank's guideline

Set by the PSP; independent review every three years

The Bank of Canada

NYDFS 500.5(a)(1)

Yes

Annually, inside and outside

NYDFS

FTC Safeguards Rule 314.4(d)(2)

Yes, absent continuous monitoring

Annual; scans every six months

The FTC

The payments attack surface a PCI scope has to cover

A payments test is mostly an authorization test: the boundary between one merchant's transactions and another's matters more than the perimeter host count.

  • Payment APIs. Merchant, transaction, refund and payout identifiers are where broken object level authorization lives, the first entry in the OWASP API Security Top 10 2023. The Council's supplement asks for testing "from the perspective of the defined roles of the application."

  • Webhooks and callbacks. Signature verification, replayed events, spoofed payment status updates, and server-side request forgery through merchant-configurable callback URLs.

  • Tokenization and vault services. Who can detokenize, and whether a token issued for one merchant resolves for another.

  • Hosted payment pages and 3DS scripts. The script inventory, content security policy and subresource integrity behind 6.4.3, and whether the 11.6.1 alert fires.

  • Merchant and partner portals. Onboarding, sub-merchant hierarchies, API key issuance, and the tenant separation Appendix A1.1.4 asks to be proven.

  • Refund, payout and fraud logic. Concurrent refund races, negative and rounding amounts, velocity limit bypass and card testing through unthrottled authorization endpoints.

  • CDE segmentation and cloud. Every method in use, tested from corporate, cloud and third-party networks, plus identity paths and CI/CD pipelines that deploy into CDE accounts.

  • Card-present estates. Store networks, Wi-Fi and terminal management, and the segmentation keeping a compromised store away from the CDE.

  • Admin consoles and support staff. People who can issue refunds or view card data are phishing and vishing targets, and their tooling rarely gets checkout-level scrutiny.

The API penetration testing ranking goes deeper on the API layer.

How we ranked them

Twelve firms were scored against ten payments-specific criteria. Every accreditation in this guide was checked on the CREST Marketplace or the accrediting body's own register, and every rating on the review site itself. PCI roles come from the PCI Security Standards Council's QSA and ASV listings, abbreviated below as QSA, ASV, 3DS, P2PE, QPA, PFI and SSF (Secure Software Framework).

  1. Requirement 11.4 as a whole: internal testing from outside the CDE inward, external, segmentation by method, application layer and retest.

  2. Service provider readiness: the six-monthly 11.4.6 clock, 11.4.7 customer evidence and A1.1.4 tenant separation.

  3. Payments application depth: APIs, webhooks, tokenization, refunds, payouts and hosted payment pages.

  4. Independence: whether testing is separable from assessment work, and documented.

  5. Named testers and credentials, weighed against the supplement's point that certifications alone do not qualify.

  6. Verified accreditation and PCI roles, read from registers rather than marketing pages.

  7. Retest policy: included or billed per cycle.

  8. Delivery and evidence: portal, ticketing, findings as confirmed, reports shaped to the supplement's outline.

  9. One-time and continuous options, because the significant-change trigger breaks annual-only programs.

  10. Pricing transparency and North American coverage.

Where a vendor does not publish a detail, this guide says "not stated" rather than inferring it.

The 12 companies at a glance

#

Company

HQ

Accreditations verified

Delivery model

Named testers

Retest

Published pricing

Best for

1

Stingrai

Toronto, Canada

CREST Penetration Testing, firm level

Human-led, hybrid or autonomous; one-time or continuous PTaaS

Yes, two per engagement

Included

Yes, US$3,000 and US$6,800

11.4 evidence from named, credentialed penetration testers

2

Coalfire

Chicago, IL

CREST; QSA, 3DS, P2PE, QPA, PFI, SSF

Assessment-led, DivisionHex offensive team

Not stated

Not stated

No

Level 1 PSPs consolidating assessment and testing

3

Praetorian

Austin, TX

CREST

Engineer-led, Praetorian Guard platform

Not stated

Included

No

Gateways wanting all four PCI test types in one engagement

4

VikingCloud

Dublin and Chicago

QSA, ASV, 3DS, P2PE, QPA, SSF; CREST Pathway+

Payments-native assessor with testing practice

Not stated

Not stated

No

Assessment, scanning and testing from one firm

5

SecurityMetrics

Orem, UT

QSA, ASV, 3DS, P2PE, PFI, SSF

Assessor and ASV with project testing

Not stated

Free retesting

Partial, typical range

Level 2 to 4 merchants and smaller providers

6

NetSPI

Minneapolis, MN

CREST, Threat Led Penetration Testing

PTaaS, 350+ employed penetration testers

Not stated

Not stated

No

Large acquirers and processors

7

TrustedSec

Fairlawn, OH

CREST; QSA

Consultant-led beside a QSA practice

Not stated

Validation testing

No

Manual depth plus an in-house QSA practice

8

ControlCase

Fairfax, VA

QSA, ASV, 3DS, P2PE, QPA, SSF; CREST via affiliate

Continuous compliance platform

Not stated

Not stated

No

Service providers wanting year-round compliance

9

Schellman

Tampa, FL

CREST; QSA, 3DS, P2PE, QPA, SSF

Consultancy inside a certification firm

Not stated

Not stated

No

Payment software and P2PE vendors

10

A-LIGN

Tampa, FL

QSA, 3DS, QPA, SSF

Packaged tiers plus RADAR platform

Not stated

Not stated

No

PSPs carrying PCI, SOC 2 and ISO 27001

11

Bishop Fox

Tempe, AZ

CREST; ASV

Consultancy plus Cosmos platform

Not stated

Not stated

No

Offensive depth first

12

LevelBlue

Plano, TX

QSA; CREST via UK entity

Consultancy and managed security, PTaaS

Not stated

Included

No

Existing LevelBlue managed security clients

"Not stated" means the vendor does not publish the detail on the pages reviewed, not that it lacks the capability.


1. Stingrai

Stingrai is a global CREST-accredited penetration testing services company founded in Toronto, Canada in 2021, trusted by companies from startups to enterprises to meet audit requirements for SOC 2, ISO 27001, CMMC, PCI DSS and HIPAA. OSCE³, OSWE, OSEP, CREST CRT certified pentesters, who are also world-class security researchers and bug bounty hunters. Choose from fully human-led or hybrid (AI agents plus human penetration testers) engagements across web, API, mobile, AI and LLM, cloud, network, Active Directory and social engineering penetration tests and red team engagements.

For a payments business, web and API testing is black, grey or white box and authenticated across every merchant, partner, support and admin role, hunting broken authorization on transaction and refund endpoints, payout logic, and webhook and token handling. Network engagements test the perimeter, then start from corporate, cloud and store networks and try to reach the CDE, covering every segmentation method on the six-monthly service provider clock. Cloud and Active Directory work follows the paths toward systems that administer the CDE, and phishing and vishing target the staff who can issue refunds.

Two named penetration testers run each engagement, reviewed by the team lead and an engagement partner. Findings post to the PTaaS portal as they are confirmed, with a working proof of concept, live chat to the testers, and Jira and Slack integration. Retesting is included, as 11.4.4 requires, and every report ships with an attestation letter and a verified badge. Reports are redactable, so a multi-tenant service provider can hand customers 11.4.7 evidence without exposing other tenants. Stingrai delivers both one-time annual penetration tests and continuous programs that test every release, and its penetration testing supports PCI DSS 4.0.1 compliance programs with the scope of work, methodology, results and retest records Requirement 11.4 calls for.

The claims are checkable: the firm-level listing on the CREST Marketplace, separate from the CREST CRT certifications individual testers hold; 5.0 out of 5 across 19 Clutch reviews and 4.9 out of 5 on G2; 18 published CVEs across the team, including CVE-2025-50674, a local path to root in OpenMediaVault, and CVE-2024-32136, an SQL injection in a WordPress plugin; and founder Arafat Afzalzada, with 11 years leading offensive engagements in financial services, healthcare and government.

Where a merchant portal or payment API is in scope, Snipe, Stingrai's AI agent for web applications and their APIs, hunts broken authorization, IDOR and business logic and opens AutoFix pull requests. The Autonomous tier is Snipe alone. In a Hybrid engagement, Snipe and the penetration testers test together throughout, with the testers directing where it digs. Network, segmentation, cloud and store network scopes are tested by the penetration testers.

  • HQ: Toronto, Ontario, with a London, UK office.

  • Delivery model: human-led, hybrid or autonomous; one-time or continuous.

  • Named testers: yes, two per engagement. Retest: included. Portal: PTaaS portal with live tester chat, Jira and Slack.

  • Pricing: published, US$3,000 Autonomous or US$6,800 Hybrid per assessment for one web application and its APIs, or US$650 and US$1,275 per month on 12-month plans; everything else is quoted.

  • Accreditations verified: CREST Penetration Testing, firm level.

  • Strength: every claim has a public source, from the CREST listing to the CVE records.

  • Limitation: headquartered in Toronto rather than the US, so contracts requiring US-person testers need that agreed in scoping.

  • Best for: processors, PSPs, payment facilitators and merchants that want Requirement 11.4 evidence from named, credentialed penetration testers, annually or continuously.

2. Coalfire

Coalfire's PCI DSS page calls the firm "one of the largest PCI QSAC (Qualified Security Assessor Company) organizations globally," reports "1000+ PCI DSS assessments delivered annually," names payment service providers among the organizations it assesses, and says its penetration testing "can help your organization achieve compliance with PCI DSS v4.0.1 Requirement 11.4." Offensive work runs under the DivisionHex brand, which publishes payment fraud and card skimming research.

  • HQ: Chicago, Illinois. Delivery model: assessment-led, with a DivisionHex OnDemand program.

  • Named testers, retest, portal: not stated. Pricing: not published.

  • Accreditations verified: CREST Penetration Testing; QSA, 3DS, P2PE, QPA, PFI and SSF.

  • Strength: the only firm here pairing CREST accreditation with PCI Forensic Investigator status, alongside 3DS, P2PE and PIN roles, so those questions stay in one relationship.

  • Limitation: where one firm assesses and tests, independence and the handling of findings against accepted controls must be documented.

  • Best for: Level 1 PSPs and merchants consolidating assessment, PIN, P2PE and testing.

3. Praetorian

Praetorian's PCI DSS penetration testing page names "web applications, payment gateways, e-commerce platforms, and any public-facing APIs" as targets and bundles external, internal, segmentation and application testing into one engagement, with "QSA-ready penetration testing reports" and "retesting at no additional cost."

  • HQ: Austin, Texas. Delivery model: engineer-led, with continuous penetration testing on the Praetorian Guard platform.

  • Named testers: not stated. Retest: included at no additional cost. Portal: Praetorian Guard. Pricing: not published.

  • Accreditations verified: CREST Penetration Testing.

  • Strength: the most payments-specific page among the offensive specialists, with the 11.4.4 retest in the price.

  • Limitation: the page does not address the six-monthly 11.4.6 clock or multi-tenant evidence, so put both in the statement of work.

  • Best for: gateways and processors that want all four PCI test types in one engagement.

4. VikingCloud

VikingCloud calls itself "the global leader in PCI compliance" with "100+ QSAs in 16 countries." Its penetration testing page covers external, internal, segmentation, PCI, web application, API, mobile and wireless testing, and describes the firm as "a CREST Pathway+ organization on the CREST Accreditation Pathway."

  • HQ: Dublin, Ireland and Chicago, Illinois, both listed as headquarters. Delivery model: payments-native assessor with an in-house testing practice.

  • Named testers, retest, portal: not stated. Pricing: not published; the page cites a general market range of "$5,000 to over $100,000."

  • Accreditations verified: QSA, ASV, 3DS, P2PE, QPA and SSF; not yet on the CREST Marketplace.

  • Strength: assessment, ASV scanning and testing from one payments-native firm.

  • Limitation: firm-level CREST accreditation is still in progress, and retest terms are unpublished.

  • Best for: multi-entity payment businesses wanting assessment, scanning and testing under one contract.

5. SecurityMetrics

SecurityMetrics, "headquartered in Orem, Utah," publishes a penetration testing page covering external, internal, application and API, mobile and network testing plus segmentation checks, with "free retesting to ensure proper remediation and patching." It is one of the few firms here to publish a number: tests "usually range from $15,000 to $30,000."

  • HQ: Orem, Utah. Delivery model: assessor and scanning vendor with project-based testing.

  • Named testers: not stated; testers hold CISSP, OSCP and BSCP. Retest: free. Portal: not stated. Pricing: partial, a published range.

  • Accreditations verified: QSA, ASV, 3DS, P2PE, PFI and SSF.

  • Strength: pricing and retest terms visible before a sales call.

  • Limitation: no CREST Marketplace listing, so lean on tester bios and a redacted sample report.

  • Best for: Level 2 to Level 4 merchants and smaller service providers wanting testing, scanning and validation from one firm.

6. NetSPI

NetSPI's internal network testing page lists "segmentation testing for PCI DSS compliance" and a bench of more than 350 penetration testers, "employed, not outsourced." Its financial services brief names PCI DSS alongside GLBA, DORA and SOX and covers web, API, mobile, cloud, network and mainframe testing.

  • HQ: Minneapolis, Minnesota, with a Toronto office. Delivery model: PTaaS platform, annual or continuous.

  • Named testers, retest: not stated on the pages reviewed. Portal: PTaaS platform. Pricing: not published.

  • Accreditations verified: CREST Penetration Testing and Threat Led Penetration Testing, ten years of membership.

  • Strength: scale and breadth, including mainframe testing for issuer-processors.

  • Limitation: payments detail is published only at brief level, so confirm tokenization and card-flow depth in scoping.

  • Best for: large acquirers, issuers and processors running multi-scope programs.

7. TrustedSec

TrustedSec's PCI services page says it "is a Qualified Security Assessor Company (QSAC)" employing "many QSAs," issues Reports on Compliance, and runs PCI penetration testing that "employs blended threat scenarios to test the effectiveness of your cardholder environment." Its methodology ends in validation testing after remediation.

  • HQ: Fairlawn, Ohio. Delivery model: consultant-led testing beside a QSA practice.

  • Named testers, portal: not stated. Retest: validation testing stated. Pricing: not published.

  • Accreditations verified: CREST Penetration Testing; QSA.

  • Strength: deep manual and Active Directory testing from a firm that knows what an assessor will ask.

  • Limitation: the PCI page offers ASV scans, but TrustedSec is not on the Council's ASV list, so ask which ASV issues the report.

  • Best for: buyers who want manual depth and an in-house QSA practice, with independence documented.

8. ControlCase

ControlCase, headquartered in Fairfax, publishes a penetration testing page covering network and application-layer external testing "verified manually by security experts," with findings on "a centralized IT GRC portal." Its CREST listing, held by ControlCase International Private Limited for Asia Pacific and Europe, adds internal testing and segmentation testing.

  • HQ: Fairfax, Virginia. Delivery model: continuous compliance platform with periodic and continuous testing.

  • Named testers, retest: not stated. Portal: centralized IT GRC portal. Pricing: not published.

  • Accreditations verified: QSA, ASV, 3DS, P2PE, QPA and SSF; CREST Penetration Testing held by its Indian affiliate.

  • Strength: testing, scanning and evidence in one platform carrying PCI alongside other frameworks.

  • Limitation: the US testing page is narrower than others here, so confirm internal and API depth.

  • Best for: service providers wanting testing inside a year-round, multi-framework compliance program.

9. Schellman

Schellman publishes a broad penetration testing portfolio spanning application and API, network including "network segmentation testing," mobile, cloud, physical, hardware and IoT, and red teaming, and its PCI practice covers DSS validation, P2PE, PIN, 3DS and the Secure Software Framework.

  • HQ: Tampa, Florida. Delivery model: consultancy inside a certification firm.

  • Named testers, retest, portal: not stated. Pricing: not published.

  • Accreditations verified: CREST Penetration Testing; QSA, 3DS, P2PE, QPA and SSF.

  • Strength: payment software, P2PE and PIN certification beside a testing bench that includes hardware.

  • Limitation: certification-first, so document which team tests and how independence is kept.

  • Best for: payment software and P2PE solution vendors consolidating certification and testing.

10. A-LIGN

A-LIGN reports "2k+ PCI assessments" on its PCI DSS page, and its penetration testing page cites "OSCP/OSCE/OSEE-certified testers," "4,600+ completed engagements" and a RADAR platform for "continuous monitoring between annual tests."

  • HQ: Tampa, Florida. Delivery model: packaged testing tiers inside an assessment firm.

  • Named testers, retest: not stated. Portal: RADAR platform. Pricing: not published.

  • Accreditations verified: QSA, 3DS, QPA and SSF; no CREST Marketplace listing.

  • Strength: one assessor across PCI, SOC 2 and ISO 27001.

  • Limitation: the testing page does not reference Requirement 11.4 or segmentation, so ask for a PCI-scoped methodology.

  • Best for: growth-stage PSPs and SaaS platforms that embed payments.

11. Bishop Fox

Bishop Fox's compliance page states "PCI DSS requires penetration testing at least annually and upon any significant environment changes" and that the firm "is a PCI DSS approved scanning vendor (ASV)," with scanning as an add-on. Its Cosmos platform provides continuous offensive testing.

  • HQ: Tempe, Arizona. Delivery model: consultancy plus the Cosmos platform.

  • Named testers, retest: not stated. Portal: Cosmos. Pricing: not published.

  • Accreditations verified: CREST Penetration Testing; ASV.

  • Strength: offensive research depth, with ASV scanning from the same firm.

  • Limitation: the page still cites the ASV scan as requirement 11.2.2, the v3.2.1 number, now 11.3.2.

  • Best for: payment platforms that want offensive depth first.

12. LevelBlue

LevelBlue's penetration testing page covers "IT, OT/IoT, Physical, People," offers "retesting services at no additional cost," and sells testing on demand as a service. Its SpiderLabs team came with Trustwave, whose website now redirects to LevelBlue.

  • HQ: Plano, Texas. Delivery model: consultancy and managed security, with PTaaS.

  • Named testers: not stated. Retest: included at no additional cost. Portal: PTaaS. Pricing: not published.

  • Accreditations verified: QSA; CREST Penetration Testing, Threat Led Penetration Testing and further accreditations held by LevelBlue Cyber Solutions Ltd.

  • Strength: retesting in the price, with a QSA practice and CREST-accredited testing in the same group.

  • Limitation: no PCI-specific copy on the testing page, so agree requirement mapping in scoping.

  • Best for: payment businesses already buying managed security from LevelBlue.


How much does PCI DSS penetration testing cost in 2026?

PCI engagements price above a generic application test because scope spans internal and external networks, every segmentation method, the payment application and reporting an assessor reads line by line. The bands below are indicative: US figures from our penetration testing cost guide, Canadian figures from our Canadian cost analysis.

Scope

Indicative US band

Indicative Canadian band

PCI DSS-scoped engagement, CDE internal, external and segmentation

US$12,000 to US$25,000

Built from the network rows

Payment portal or web application

US$5,000 to US$30,000+

C$5,000 to C$40,000+

Payment API

US$6,000 to US$30,000

C$8,000 to C$40,000

External network

US$5,000 to US$40,000+

C$8,000 to C$50,000+

Internal network, into the CDE

US$5,000 to US$40,000+

C$12,000 to C$50,000+

Mobile app and backend, per platform

US$7,000 to US$35,000

C$10,000 to C$45,000

Cloud payment infrastructure

US$10,000 to US$50,000+

C$13,000 to C$65,000+

Annual continuous program

Scoped to the estate

C$40,000 to C$120,000+

Three things move a PCI quote most: the number of segmentation methods, because 11.4.5 requires all of them; service provider status, which doubles the segmentation cadence and may add A1.1.4 testing; and retest cycles, which 11.4.4 does not cap.

Stingrai's only fixed prices cover one web application and its APIs: an Autonomous Pentest at US$3,000, Snipe only with no penetration testers, and a Hybrid Pentest at US$6,800, where Snipe and penetration testers test together throughout, or US$650 and US$1,275 per month on 12-month continuous plans. The Autonomous tier carries a No High or Critical Finding, Don't Pay guarantee. Every CDE, network and segmentation scope is quoted through get a quote; current figures are on the pricing page.

Buyer's checklist: what to ask every PCI penetration testing vendor

  1. Who will test, and what do they hold? Names, certifications and engagement history in the statement of work.

  2. Does the internal test start outside the CDE? 11.4.1 requires testing into the CDE from trusted and untrusted networks.

  3. Is segmentation scoped by method, and is the six-monthly 11.4.6 clock priced in?

  4. Is retesting included? 11.4.4 makes it mandatory and uncapped.

  5. How is independence documented where the firm also assesses, operates or advises?

  6. Will you test our payment APIs from every role, including refund and payout flows?

  7. How do you handle the payment page? Script enumeration, tag manager access, and whether the 11.6.1 alert is tested.

  8. Is the scope of work a separate artifact? Assessors examine it alongside the results.

  9. Can we give customers redacted evidence for 11.4.7?

  10. Can one vendor run the annual test and continuous coverage? Weekly releases against a 12-month clock leave most changes untested.

The pentest and red team RFP question bank turns these into tender language.


Frequently Asked Questions

Who are the best penetration testing companies for PCI DSS and payment providers in 2026?

The best PCI DSS penetration testing companies in 2026 are Stingrai, Coalfire, Praetorian, VikingCloud, SecurityMetrics, NetSPI, TrustedSec, ControlCase, Schellman, A-LIGN, Bishop Fox and LevelBlue. Stingrai ranks first as a CREST-accredited penetration testing service provider at firm level, with two named penetration testers per engagement holding OSCE³, OSWE, OSEP, CREST CRT and CISSP, testing payment APIs, webhooks, tokenization, internal networks and every segmentation method, one-time or continuously, with retesting and an attestation letter included.

Does a PCI penetration tester have to be a QSA?

No. Requirements 11.4.2, 11.4.3, 11.4.5 and 11.4.6 require a qualified internal resource or qualified external third party with organizational independence, "not required to be a QSA or ASV." The Council's Penetration Testing Guidance says the tester must be organizationally separate from the management of the target systems, and an assessing firm cannot test systems it installed, maintained or supported.

What does PCI DSS Requirement 11.4 require of a payment company?

Internal and external penetration testing at least every 12 months and after significant change, a documented nine-element methodology, correction of exploitable findings followed by repeat testing, and segmentation testing every 12 months. Service providers, which include payment gateways, PSPs and ISOs, test segmentation every six months, and multi-tenant service providers also test the separation between customer environments every six months under Appendix A1.1.4.

What do Requirements 6.4.3 and 11.6.1 require of a payment page?

Requirement 6.4.3 requires every payment page script to be authorized, integrity-assured and inventoried with a written justification. Requirement 11.6.1 requires a mechanism that alerts on unauthorized changes to security-impacting HTTP headers and script contents as received by the browser, at least weekly or per a targeted risk analysis. Both have been mandatory since 31 March 2025, and scripts in a processor's embedded payment form are the processor's responsibility.

What does Canada's Retail Payment Activities Act require of a PSP?

A risk management and incident response framework, and under section 9 of the Regulations a documented testing methodology that sets its own frequency and scope, reflects the PSP's impact and third-party reliance, and tests before material change. Section 10 adds an independent review every three years for PSPs with an auditor. The Regulations do not name penetration testing, but the Bank of Canada's guideline does for more interconnected PSPs. These provisions took effect on 8 September 2025.

Does NYDFS Part 500 apply to money transmitters?

Yes, for money transmitters licensed in New York under Article 13-B of the Banking Law, because Part 500 covers anyone operating under a Banking Law license. Section 500.5(a)(1) requires penetration testing from both inside and outside the information systems' boundaries by a qualified internal or external party at least annually. Entities under the 500.19(a) limited exemption are exempt from section 500.5.

Does the FTC Safeguards Rule require penetration testing for payment companies?

Yes, for non-bank financial institutions under FTC jurisdiction without effective continuous monitoring: 16 CFR 314.4(d)(2) requires annual penetration testing and vulnerability assessments every six months. A business that regularly wires money to and from consumers is a financial institution under the rule; a merchant is not one merely because it accepts cards it did not issue. Institutions holding data on fewer than 5,000 consumers are exempt from the testing paragraph.

How much does PCI DSS penetration testing cost in 2026?

Our cost guides give indicative bands: US$12,000 to US$25,000 for a PCI DSS-scoped engagement in the United States, and in Canada C$8,000 to C$50,000 or more for an external network test and C$12,000 to C$50,000 or more for an internal one. Segmentation methods, service provider status and retest cycles move the number most. Stingrai publishes fixed prices for one web application and its APIs, US$3,000 Autonomous or US$6,800 Hybrid per assessment, or US$650 and US$1,275 per month on 12-month plans, and quotes every other scope.



References

  1. PCI Security Standards Council. Now is the Time for Organizations to Adopt the Future-Dated Requirements of PCI DSS v4.x, 20 August 2024. https://blog.pcisecuritystandards.org/now-is-the-time-for-organizations-to-adopt-the-future-dated-requirements-of-pci-dss-v4-x

  2. PCI Security Standards Council. PCI DSS v4.0.1, June 2024: 6.4.3, 11.3, 11.4, 11.6.1, A1.1.4 and glossary. https://www.pcisecuritystandards.org/document_library/

  3. PCI Security Standards Council. Information Supplement: Penetration Testing Guidance, v1.1, September 2017. https://www.pcisecuritystandards.org/documents/Penetration-Testing-Guidance-v1_1.pdf

  4. PCI Security Standards Council. SAQ A updates, 30 January 2025. https://blog.pcisecuritystandards.org/important-updates-announced-for-merchants-validating-to-self-assessment-questionnaire-a

  5. PCI Security Standards Council. PCI 3DS ROC Reporting Template, v1.0, December 2017. https://listings.pcisecuritystandards.org/documents/PCI-3DS-Core-v1-ROC-Reporting-Template.pdf

  6. PCI Security Standards Council. PCI PIN Security Standard v3.1, 12 March 2021. https://blog.pcisecuritystandards.org/just-released-version-3-1-of-the-pci-pin-security-standard

  7. PCI Security Standards Council. QSA and ASV listings, checked 25 September 2026. https://www.pcisecuritystandards.org/assessors_and_solutions/qualified_security_assessors/

  8. Visa. Account Information Security Program. https://corporate.visa.com/en/resources/security-compliance.html

  9. Mastercard. Site Data Protection Program. https://www.mastercard.com/global/en/business/cybersecurity-fraud-prevention/site-data-protection-pci.html

  10. Moneris. PCI Data Security. https://www.moneris.com/en/support/compliance-and-security/pci-data-security

  11. Government of Canada. Retail Payment Activities Act, section 17. https://laws-lois.justice.gc.ca/eng/acts/R-7.36/

  12. Government of Canada. Retail Payment Activities Regulations, SOR/2023-229, sections 9, 10 and 55. https://laws-lois.justice.gc.ca/eng/regulations/SOR-2023-229/FullText.html

  13. Bank of Canada. Operational risk and incident response, section 10 and Appendix G. https://www.bankofcanada.ca/wp-content/uploads/2024/02/operational-risk-and-incident-response.pdf

  14. New York State Department of Financial Services. 23 NYCRR 500, second amendment. https://www.dfs.ny.gov/system/files/documents/2023/10/rf_fs_2amend23NYCRR500_text_20231101.pdf

  15. New York State Department of Financial Services. Money Transmitters. https://www.dfs.ny.gov/apps_and_licensing/money_transmitters

  16. Federal Trade Commission. 16 CFR 314.2, 314.4(d)(2) and 314.6. https://www.law.cornell.edu/cfr/text/16/314.4

  17. OWASP Foundation. API Security Top 10 2023. https://owasp.org/API-Security/editions/2023/en/0x11-t10/

  18. CREST. CREST Marketplace, checked 25 September 2026. https://marketplace.crest.org/

  19. Stingrai. Pricing. https://www.stingrai.io/pricing


Ready to scope a PCI DSS penetration test?

The finding that becomes a card data breach is rarely a missing patch. It is a refund endpoint that trusts a merchant identifier, or a segmentation rule that stopped isolating the CDE after last quarter's network change. Stingrai's CREST-accredited penetration testing supports PCI DSS 4.0.1, SOC 2 and ISO 27001 compliance programs with the scope of work, report and retest evidence they consume, one-time or continuously. Book a free scoping call, get a quote for a CDE or service provider scope, or read the pricing page.

0 views

0

X

Related reading

Best Penetration Testing Companies for Crypto Exchanges and Digital Asset Platforms (2026)
Web App SecurityNetwork Security

Best Penetration Testing Companies for Crypto Exchanges and Digital Asset Platforms (2026)

The best penetration testing companies for crypto exchanges, custodians and stablecoin issuers in 2026, ranked, with what NYDFS and CSA rules require.

19 min read

Best Penetration Testing Companies for Government and the Public Sector (2026): State, Local, Provincial and Municipal
Network SecurityWeb App Security

Best Penetration Testing Companies for Government and the Public Sector (2026): State, Local, Provincial and Municipal

Best penetration testing companies for state, local, provincial and municipal government in 2026, ranked, with what CJIS, IRS 1075 and GovRAMP require.

25 min read

Best Healthcare Penetration Testing Companies in Canada (2026): PHIPA, Hospitals and Digital Health
Web App SecurityNetwork Security

Best Healthcare Penetration Testing Companies in Canada (2026): PHIPA, Hospitals and Digital Health

Canada's best healthcare penetration testing companies for 2026, ranked, with what PHIPA, Ontario Health, O. Reg. 51/26 and Quebec's TGV really require.

25 min read

Contents

X