PCI DSS v4.0 introduced 64 new requirements, and 51 of them were future-dated until 31 March 2025, according to the PCI Security Standards Council. Every assessment completed since has had to consider all of them, including the payment page script controls in Requirements 6.4.3 and 11.6.1, multi-tenant testing support in 11.4.7 and the six-monthly tenant separation test in Appendix A1.1.4. In Canada, the testing provisions of the Retail Payment Activities Regulations took effect on 8 September 2025. For a processor or PSP operating on both sides of the border, the penetration test is now evidence in two files at once.
Where Stingrai fits: Stingrai is a CREST-accredited penetration testing service provider at firm level, founded in 2021 and headquartered in Toronto with a London office. Two named penetration testers holding OSCE³, OSWE, OSEP, CREST CRT and CISSP run each engagement, reviewed by the team lead and an engagement partner, backed by 18 published CVEs across the team and bug bounty Hall of Fame listings at PaySafe, the US Federal Reserve, Apple, Google and the US Department of Defense. For a payments business that means payment APIs, webhooks and tokenization tested as every merchant, partner and admin role, internal testing that starts outside the cardholder data environment and tries to get in, and segmentation tested method by method on the six-monthly service provider clock, one-time or continuously through the PTaaS portal, with retesting and an attestation letter included. Published pricing is US$3,000 for an Autonomous Pentest and US$6,800 for a Hybrid Pentest covering one web application and its APIs (pricing); cardholder data environment scopes are quoted.
This is the buyer's ranking for processors, PSPs and payment facilitators, acquirers and issuer-processors, Level 1 and Level 2 merchants, and SaaS platforms that embed payments, in the United States and Canada. The clause-by-clause treatment of Requirement 11.4 lives in the PCI DSS penetration testing requirements guide. Every vendor page cited was checked on 25 September 2026.
Quick answer: who are the best PCI DSS penetration testing companies in 2026?
The best PCI DSS penetration testing companies in 2026 are Stingrai, Coalfire, Praetorian, VikingCloud, SecurityMetrics, NetSPI, TrustedSec, ControlCase, Schellman, A-LIGN, Bishop Fox and LevelBlue. Stingrai ranks first: firm-level CREST accreditation, two named penetration testers per engagement holding OSCE³, OSWE, OSEP, CREST CRT and CISSP, and payment APIs, webhooks, tokenization, internal networks and every segmentation method tested one-time or continuously, with retesting and an attestation letter included. Coalfire follows for CREST accreditation alongside QSA, forensic investigator, 3DS, P2PE and PIN assessor roles, Praetorian for a payment-gateway testing practice with retesting at no additional cost, and VikingCloud for a payments-native assessor with an in-house testing practice.

What payment companies are actually required to test
Seven regimes show up in payments procurement. Four name penetration testing outright: PCI DSS, PCI 3DS, NYDFS and the FTC Safeguards Rule. The card brands decide who reads the evidence, Canada's retail payments law asks for testing without naming the technique, and PCI PIN shapes the scope.
What does PCI DSS Requirement 11.4 require of a payment company?
Requirement 11.4 of PCI DSS v4.0.1 reads: "External and internal penetration testing is regularly performed, and exploitable vulnerabilities and security weaknesses are corrected."
11.4.1 requires a documented nine-element methodology covering the entire cardholder data environment (CDE) perimeter and critical systems, segmentation validation and application-layer testing to 6.2.4. Internal testing means testing "from both inside the CDE and into the CDE from trusted and untrusted internal networks."
11.4.2 and 11.4.3 require internal and external testing "at least once every 12 months" and "after any significant infrastructure or application upgrade or change."
11.4.4 requires exploitable findings to be corrected, and "penetration testing is repeated to verify the corrections."
11.4.5 requires segmentation testing every 12 months and after any segmentation change, "covering all segmentation controls/methods in use." 11.4.6 makes it "at least once every six months" for service providers.
11.4.7 requires multi-tenant service providers to support customers' external testing, with redacted evidence or prompt access. Appendix A1.1.4 adds a separate tenant separation test "at least once every six months."
The glossary settles who carries the service provider clock: a service provider "includes payment gateways, payment service providers (PSPs), and independent sales organizations (ISOs)," and multi-tenant service providers include SaaS platforms and "connections to payment gateways and processors."

What do Requirements 6.4.3 and 11.6.1 require of a payment page?
Requirement 6.4.3 requires every payment page script to be authorized, integrity-assured and inventoried "with written business or technical justification." Requirement 11.6.1 requires a change- and tamper-detection mechanism alerting on unauthorized modification to "the security-impacting HTTP headers and the script contents of payment pages as received by the consumer browser," at least weekly or at a frequency set by targeted risk analysis. Both were best practice until 31 March 2025.
For processors, the applicability notes matter most: scripts in a processor's embedded payment form "are the responsibility of the TPSP/payment processor to manage," and merchants "should expect the TPSP/payment processor to provide evidence." On 30 January 2025 the Council removed 6.4.3 and 11.6.1 from SAQ A, adding an eligibility criterion that merchants "confirm their site is not susceptible to attacks from scripts," while the underlying requirements stay in force. Neither is a penetration test. A good test attacks both: enumerate what loads on checkout, try to inject a script through the tag manager, and see whether the alert fires.
Does a PCI penetration tester have to be a QSA?
No. Requirements 11.4.2, 11.4.3, 11.4.5 and 11.4.6 each require organizational independence of the tester, "(not required to be a QSA or ASV)." The Council's Penetration Testing Guidance says "the penetration tester must be organizationally separate from the management of the target systems," and that an assessing firm "cannot perform the penetration test if they were involved in the installation, maintenance, or support of target systems." It adds that "the PCI SSC does not validate or endorse" certifications, and that qualifications "cannot be met by certifications alone."
Role | What it does in a PCI program | Needed for the 11.4 test? |
|---|---|---|
Qualified Security Assessor (QSA) | Assesses the entity and signs the Report on Compliance | No |
Approved Scanning Vendor (ASV) | Runs the quarterly external scans under 11.3.2 | No |
Penetration tester | Performs 11.4.2 to 11.4.7 testing as a qualified, independent party | Yes |
Qualified PIN Assessor (QPA) | Assesses against the PCI PIN Security Requirements | No |
PCI 3DS assessor | Assesses 3DS Server, ACS and Directory Server environments | No |
PCI Forensic Investigator (PFI) | Investigates a suspected account data compromise | No |
A QSA firm may test your environment, and several firms below hold both roles; settle independence in writing. Where the tester is an offensive security firm outside the assessment, such as Stingrai, Praetorian or NetSPI, independence from the assessment is structural.
What do Visa and Mastercard require of processors, PSPs and merchants?
The card brands do not add a test. They decide who reads yours. Visa's Account Information Security Program sets merchant level by "total Visa transaction volume over a 12-month period" and requires issuers and acquirers to "ensure all their service providers demonstrate PCI DSS compliance at least every 12 months."
Mastercard's Site Data Protection program names payments companies directly. Every third-party processor, token service provider, 3-D Secure service provider and merchant payment gateway is a Level 1 service provider, as is every payment facilitator with "more than 300,000 total combined Mastercard and Maestro transactions annually." Level 1 service providers validate annually through a Report on Compliance by a QSA, and 3-D Secure service providers validate against PCI 3DS every two years. Level 2 merchants completing SAQ A, A-EP or D must also engage a QSA or Internal Security Assessor. In Canada, Moneris applies the same four merchant levels. At Level 1 an assessor reads your 11.4 evidence line by line, so the scope of work, segmentation results by method and retest records must exist as separate artifacts.
Do PCI 3DS and PCI PIN require penetration testing?
PCI 3DS does. Part 1 of the PCI 3DS Core Security Standard, reproduced in the Council's 3DS reporting template, states "Penetration tests are performed at least annually" (P1-4.2.5) by "qualified personnel" (P1-4.2.6), with high-risk findings "addressed within one month" (P1-4.2.7). A 3DS entity can leverage its PCI DSS assessment for Part 1.
The PCI PIN Security Requirements, version 3.1 since March 2021, cover "the secure management, processing, and transmission of PIN data" at ATMs and POS terminals and are assessed by a QPA. Their relevance to the test is scope: hardware security modules and PIN translation paths sit inside or beside the CDE, so the 11.4 methodology must reach the networks around them without touching live keys.
What does Canada's Retail Payment Activities Act require of a PSP?
Section 17 of the Retail Payment Activities Act requires a payment service provider to maintain "a risk management and incident response framework." Section 9 of the Regulations requires a testing methodology "for the purpose of identifying gaps in the effectiveness of, and vulnerabilities in" that framework: proportionate to the PSP's impact, covering high-likelihood and high-impact risks and third-party reliance, setting out "the frequency and scope of testing," and testing before material change, with a record of each test. Section 10 adds an independent review every three years for PSPs with an auditor. The registration provisions took effect on 1 November 2024, and sections 5 to 23 on 8 September 2025.
The Regulations never name penetration testing. The Bank of Canada's guideline, Operational risk and incident response, does: more "ubiquitous or interconnected PSPs could adopt additional testing for cyber and information technology risks, including penetration tests," and "qualified parties should conduct specialized testing, such as penetration testing." Testing "conducted for other purposes" can count if it meets the section 9 objectives, so one well-scoped PCI engagement can serve both files. Bank-owned acquirers also answer to OSFI Guideline B-13, covered in the banking and credit union ranking.
Does NYDFS Part 500 apply to money transmitters?
Yes, if they are licensed in New York. 23 NYCRR 500 covers anyone operating under a license "under the Banking Law, the Insurance Law or the Financial Services Law," and money transmitters are licensed under Article 13-B of the Banking Law. Section 500.5(a)(1) requires "penetration testing of their information systems from both inside and outside the information systems' boundaries by a qualified internal or external party at least annually." Entities under the 500.19(a) limited exemption, based on headcount, revenue or assets, are exempt from 500.5. The NYDFS penetration testing guide covers the rest.
Does the FTC Safeguards Rule require penetration testing for payment companies?
Yes, for non-bank financial institutions under FTC jurisdiction without effective continuous monitoring. 16 CFR 314.4(d)(2) requires "annual penetration testing of your information systems," plus vulnerability assessments every six months. The definitions bring payments in: "a business that regularly wires money to and from consumers is a financial institution." A merchant is not one merely because it accepts cards it did not issue, and section 314.6 exempts institutions holding data on fewer than 5,000 consumers from the testing paragraph.
Regime | Names penetration testing? | Clock | Who reads the evidence |
|---|---|---|---|
PCI DSS 11.4.2 and 11.4.3 | Yes | 12 months and after significant change | A QSA in a Report on Compliance, or the entity in an SAQ |
PCI DSS 11.4.5, 11.4.6 and A1.1.4 | Yes, segmentation and tenant separation | 12 months for all; six months for service providers | Same |
PCI DSS 6.4.3 and 11.6.1 | No, testable controls | Tamper checks weekly or per risk analysis | Same, and merchants ask their processor |
Visa AIS and Mastercard SDP | No, validation programs | Annual; 3DS service providers every two years | Acquirers and the card brands |
PCI 3DS Part 1 | Yes | At least annually | A PCI 3DS assessor |
RPAA and RPAR | Only in the Bank's guideline | Set by the PSP; independent review every three years | The Bank of Canada |
NYDFS 500.5(a)(1) | Yes | Annually, inside and outside | NYDFS |
FTC Safeguards Rule 314.4(d)(2) | Yes, absent continuous monitoring | Annual; scans every six months | The FTC |
The payments attack surface a PCI scope has to cover
A payments test is mostly an authorization test: the boundary between one merchant's transactions and another's matters more than the perimeter host count.
Payment APIs. Merchant, transaction, refund and payout identifiers are where broken object level authorization lives, the first entry in the OWASP API Security Top 10 2023. The Council's supplement asks for testing "from the perspective of the defined roles of the application."
Webhooks and callbacks. Signature verification, replayed events, spoofed payment status updates, and server-side request forgery through merchant-configurable callback URLs.
Tokenization and vault services. Who can detokenize, and whether a token issued for one merchant resolves for another.
Hosted payment pages and 3DS scripts. The script inventory, content security policy and subresource integrity behind 6.4.3, and whether the 11.6.1 alert fires.
Merchant and partner portals. Onboarding, sub-merchant hierarchies, API key issuance, and the tenant separation Appendix A1.1.4 asks to be proven.
Refund, payout and fraud logic. Concurrent refund races, negative and rounding amounts, velocity limit bypass and card testing through unthrottled authorization endpoints.
CDE segmentation and cloud. Every method in use, tested from corporate, cloud and third-party networks, plus identity paths and CI/CD pipelines that deploy into CDE accounts.
Card-present estates. Store networks, Wi-Fi and terminal management, and the segmentation keeping a compromised store away from the CDE.
Admin consoles and support staff. People who can issue refunds or view card data are phishing and vishing targets, and their tooling rarely gets checkout-level scrutiny.
The API penetration testing ranking goes deeper on the API layer.
How we ranked them
Twelve firms were scored against ten payments-specific criteria. Every accreditation in this guide was checked on the CREST Marketplace or the accrediting body's own register, and every rating on the review site itself. PCI roles come from the PCI Security Standards Council's QSA and ASV listings, abbreviated below as QSA, ASV, 3DS, P2PE, QPA, PFI and SSF (Secure Software Framework).
Requirement 11.4 as a whole: internal testing from outside the CDE inward, external, segmentation by method, application layer and retest.
Service provider readiness: the six-monthly 11.4.6 clock, 11.4.7 customer evidence and A1.1.4 tenant separation.
Payments application depth: APIs, webhooks, tokenization, refunds, payouts and hosted payment pages.
Independence: whether testing is separable from assessment work, and documented.
Named testers and credentials, weighed against the supplement's point that certifications alone do not qualify.
Verified accreditation and PCI roles, read from registers rather than marketing pages.
Retest policy: included or billed per cycle.
Delivery and evidence: portal, ticketing, findings as confirmed, reports shaped to the supplement's outline.
One-time and continuous options, because the significant-change trigger breaks annual-only programs.
Pricing transparency and North American coverage.
Where a vendor does not publish a detail, this guide says "not stated" rather than inferring it.
The 12 companies at a glance
# | Company | HQ | Accreditations verified | Delivery model | Named testers | Retest | Published pricing | Best for |
|---|---|---|---|---|---|---|---|---|
1 | Stingrai | Toronto, Canada | CREST Penetration Testing, firm level | Human-led, hybrid or autonomous; one-time or continuous PTaaS | Yes, two per engagement | Included | Yes, US$3,000 and US$6,800 | 11.4 evidence from named, credentialed penetration testers |
2 | Coalfire | Chicago, IL | CREST; QSA, 3DS, P2PE, QPA, PFI, SSF | Assessment-led, DivisionHex offensive team | Not stated | Not stated | No | Level 1 PSPs consolidating assessment and testing |
3 | Praetorian | Austin, TX | CREST | Engineer-led, Praetorian Guard platform | Not stated | Included | No | Gateways wanting all four PCI test types in one engagement |
4 | VikingCloud | Dublin and Chicago | QSA, ASV, 3DS, P2PE, QPA, SSF; CREST Pathway+ | Payments-native assessor with testing practice | Not stated | Not stated | No | Assessment, scanning and testing from one firm |
5 | SecurityMetrics | Orem, UT | QSA, ASV, 3DS, P2PE, PFI, SSF | Assessor and ASV with project testing | Not stated | Free retesting | Partial, typical range | Level 2 to 4 merchants and smaller providers |
6 | NetSPI | Minneapolis, MN | CREST, Threat Led Penetration Testing | PTaaS, 350+ employed penetration testers | Not stated | Not stated | No | Large acquirers and processors |
7 | TrustedSec | Fairlawn, OH | CREST; QSA | Consultant-led beside a QSA practice | Not stated | Validation testing | No | Manual depth plus an in-house QSA practice |
8 | ControlCase | Fairfax, VA | QSA, ASV, 3DS, P2PE, QPA, SSF; CREST via affiliate | Continuous compliance platform | Not stated | Not stated | No | Service providers wanting year-round compliance |
9 | Schellman | Tampa, FL | CREST; QSA, 3DS, P2PE, QPA, SSF | Consultancy inside a certification firm | Not stated | Not stated | No | Payment software and P2PE vendors |
10 | A-LIGN | Tampa, FL | QSA, 3DS, QPA, SSF | Packaged tiers plus RADAR platform | Not stated | Not stated | No | PSPs carrying PCI, SOC 2 and ISO 27001 |
11 | Bishop Fox | Tempe, AZ | CREST; ASV | Consultancy plus Cosmos platform | Not stated | Not stated | No | Offensive depth first |
12 | LevelBlue | Plano, TX | QSA; CREST via UK entity | Consultancy and managed security, PTaaS | Not stated | Included | No | Existing LevelBlue managed security clients |
"Not stated" means the vendor does not publish the detail on the pages reviewed, not that it lacks the capability.
1. Stingrai
Stingrai is a global CREST-accredited penetration testing services company founded in Toronto, Canada in 2021, trusted by companies from startups to enterprises to meet audit requirements for SOC 2, ISO 27001, CMMC, PCI DSS and HIPAA. OSCE³, OSWE, OSEP, CREST CRT certified pentesters, who are also world-class security researchers and bug bounty hunters. Choose from fully human-led or hybrid (AI agents plus human penetration testers) engagements across web, API, mobile, AI and LLM, cloud, network, Active Directory and social engineering penetration tests and red team engagements.
For a payments business, web and API testing is black, grey or white box and authenticated across every merchant, partner, support and admin role, hunting broken authorization on transaction and refund endpoints, payout logic, and webhook and token handling. Network engagements test the perimeter, then start from corporate, cloud and store networks and try to reach the CDE, covering every segmentation method on the six-monthly service provider clock. Cloud and Active Directory work follows the paths toward systems that administer the CDE, and phishing and vishing target the staff who can issue refunds.
Two named penetration testers run each engagement, reviewed by the team lead and an engagement partner. Findings post to the PTaaS portal as they are confirmed, with a working proof of concept, live chat to the testers, and Jira and Slack integration. Retesting is included, as 11.4.4 requires, and every report ships with an attestation letter and a verified badge. Reports are redactable, so a multi-tenant service provider can hand customers 11.4.7 evidence without exposing other tenants. Stingrai delivers both one-time annual penetration tests and continuous programs that test every release, and its penetration testing supports PCI DSS 4.0.1 compliance programs with the scope of work, methodology, results and retest records Requirement 11.4 calls for.
The claims are checkable: the firm-level listing on the CREST Marketplace, separate from the CREST CRT certifications individual testers hold; 5.0 out of 5 across 19 Clutch reviews and 4.9 out of 5 on G2; 18 published CVEs across the team, including CVE-2025-50674, a local path to root in OpenMediaVault, and CVE-2024-32136, an SQL injection in a WordPress plugin; and founder Arafat Afzalzada, with 11 years leading offensive engagements in financial services, healthcare and government.
Where a merchant portal or payment API is in scope, Snipe, Stingrai's AI agent for web applications and their APIs, hunts broken authorization, IDOR and business logic and opens AutoFix pull requests. The Autonomous tier is Snipe alone. In a Hybrid engagement, Snipe and the penetration testers test together throughout, with the testers directing where it digs. Network, segmentation, cloud and store network scopes are tested by the penetration testers.
HQ: Toronto, Ontario, with a London, UK office.
Delivery model: human-led, hybrid or autonomous; one-time or continuous.
Named testers: yes, two per engagement. Retest: included. Portal: PTaaS portal with live tester chat, Jira and Slack.
Pricing: published, US$3,000 Autonomous or US$6,800 Hybrid per assessment for one web application and its APIs, or US$650 and US$1,275 per month on 12-month plans; everything else is quoted.
Accreditations verified: CREST Penetration Testing, firm level.
Strength: every claim has a public source, from the CREST listing to the CVE records.
Limitation: headquartered in Toronto rather than the US, so contracts requiring US-person testers need that agreed in scoping.
Best for: processors, PSPs, payment facilitators and merchants that want Requirement 11.4 evidence from named, credentialed penetration testers, annually or continuously.
2. Coalfire
Coalfire's PCI DSS page calls the firm "one of the largest PCI QSAC (Qualified Security Assessor Company) organizations globally," reports "1000+ PCI DSS assessments delivered annually," names payment service providers among the organizations it assesses, and says its penetration testing "can help your organization achieve compliance with PCI DSS v4.0.1 Requirement 11.4." Offensive work runs under the DivisionHex brand, which publishes payment fraud and card skimming research.
HQ: Chicago, Illinois. Delivery model: assessment-led, with a DivisionHex OnDemand program.
Named testers, retest, portal: not stated. Pricing: not published.
Accreditations verified: CREST Penetration Testing; QSA, 3DS, P2PE, QPA, PFI and SSF.
Strength: the only firm here pairing CREST accreditation with PCI Forensic Investigator status, alongside 3DS, P2PE and PIN roles, so those questions stay in one relationship.
Limitation: where one firm assesses and tests, independence and the handling of findings against accepted controls must be documented.
Best for: Level 1 PSPs and merchants consolidating assessment, PIN, P2PE and testing.
3. Praetorian
Praetorian's PCI DSS penetration testing page names "web applications, payment gateways, e-commerce platforms, and any public-facing APIs" as targets and bundles external, internal, segmentation and application testing into one engagement, with "QSA-ready penetration testing reports" and "retesting at no additional cost."
HQ: Austin, Texas. Delivery model: engineer-led, with continuous penetration testing on the Praetorian Guard platform.
Named testers: not stated. Retest: included at no additional cost. Portal: Praetorian Guard. Pricing: not published.
Accreditations verified: CREST Penetration Testing.
Strength: the most payments-specific page among the offensive specialists, with the 11.4.4 retest in the price.
Limitation: the page does not address the six-monthly 11.4.6 clock or multi-tenant evidence, so put both in the statement of work.
Best for: gateways and processors that want all four PCI test types in one engagement.
4. VikingCloud
VikingCloud calls itself "the global leader in PCI compliance" with "100+ QSAs in 16 countries." Its penetration testing page covers external, internal, segmentation, PCI, web application, API, mobile and wireless testing, and describes the firm as "a CREST Pathway+ organization on the CREST Accreditation Pathway."
HQ: Dublin, Ireland and Chicago, Illinois, both listed as headquarters. Delivery model: payments-native assessor with an in-house testing practice.
Named testers, retest, portal: not stated. Pricing: not published; the page cites a general market range of "$5,000 to over $100,000."
Accreditations verified: QSA, ASV, 3DS, P2PE, QPA and SSF; not yet on the CREST Marketplace.
Strength: assessment, ASV scanning and testing from one payments-native firm.
Limitation: firm-level CREST accreditation is still in progress, and retest terms are unpublished.
Best for: multi-entity payment businesses wanting assessment, scanning and testing under one contract.
5. SecurityMetrics
SecurityMetrics, "headquartered in Orem, Utah," publishes a penetration testing page covering external, internal, application and API, mobile and network testing plus segmentation checks, with "free retesting to ensure proper remediation and patching." It is one of the few firms here to publish a number: tests "usually range from $15,000 to $30,000."
HQ: Orem, Utah. Delivery model: assessor and scanning vendor with project-based testing.
Named testers: not stated; testers hold CISSP, OSCP and BSCP. Retest: free. Portal: not stated. Pricing: partial, a published range.
Accreditations verified: QSA, ASV, 3DS, P2PE, PFI and SSF.
Strength: pricing and retest terms visible before a sales call.
Limitation: no CREST Marketplace listing, so lean on tester bios and a redacted sample report.
Best for: Level 2 to Level 4 merchants and smaller service providers wanting testing, scanning and validation from one firm.
6. NetSPI
NetSPI's internal network testing page lists "segmentation testing for PCI DSS compliance" and a bench of more than 350 penetration testers, "employed, not outsourced." Its financial services brief names PCI DSS alongside GLBA, DORA and SOX and covers web, API, mobile, cloud, network and mainframe testing.
HQ: Minneapolis, Minnesota, with a Toronto office. Delivery model: PTaaS platform, annual or continuous.
Named testers, retest: not stated on the pages reviewed. Portal: PTaaS platform. Pricing: not published.
Accreditations verified: CREST Penetration Testing and Threat Led Penetration Testing, ten years of membership.
Strength: scale and breadth, including mainframe testing for issuer-processors.
Limitation: payments detail is published only at brief level, so confirm tokenization and card-flow depth in scoping.
Best for: large acquirers, issuers and processors running multi-scope programs.
7. TrustedSec
TrustedSec's PCI services page says it "is a Qualified Security Assessor Company (QSAC)" employing "many QSAs," issues Reports on Compliance, and runs PCI penetration testing that "employs blended threat scenarios to test the effectiveness of your cardholder environment." Its methodology ends in validation testing after remediation.
HQ: Fairlawn, Ohio. Delivery model: consultant-led testing beside a QSA practice.
Named testers, portal: not stated. Retest: validation testing stated. Pricing: not published.
Accreditations verified: CREST Penetration Testing; QSA.
Strength: deep manual and Active Directory testing from a firm that knows what an assessor will ask.
Limitation: the PCI page offers ASV scans, but TrustedSec is not on the Council's ASV list, so ask which ASV issues the report.
Best for: buyers who want manual depth and an in-house QSA practice, with independence documented.
8. ControlCase
ControlCase, headquartered in Fairfax, publishes a penetration testing page covering network and application-layer external testing "verified manually by security experts," with findings on "a centralized IT GRC portal." Its CREST listing, held by ControlCase International Private Limited for Asia Pacific and Europe, adds internal testing and segmentation testing.
HQ: Fairfax, Virginia. Delivery model: continuous compliance platform with periodic and continuous testing.
Named testers, retest: not stated. Portal: centralized IT GRC portal. Pricing: not published.
Accreditations verified: QSA, ASV, 3DS, P2PE, QPA and SSF; CREST Penetration Testing held by its Indian affiliate.
Strength: testing, scanning and evidence in one platform carrying PCI alongside other frameworks.
Limitation: the US testing page is narrower than others here, so confirm internal and API depth.
Best for: service providers wanting testing inside a year-round, multi-framework compliance program.
9. Schellman
Schellman publishes a broad penetration testing portfolio spanning application and API, network including "network segmentation testing," mobile, cloud, physical, hardware and IoT, and red teaming, and its PCI practice covers DSS validation, P2PE, PIN, 3DS and the Secure Software Framework.
HQ: Tampa, Florida. Delivery model: consultancy inside a certification firm.
Named testers, retest, portal: not stated. Pricing: not published.
Accreditations verified: CREST Penetration Testing; QSA, 3DS, P2PE, QPA and SSF.
Strength: payment software, P2PE and PIN certification beside a testing bench that includes hardware.
Limitation: certification-first, so document which team tests and how independence is kept.
Best for: payment software and P2PE solution vendors consolidating certification and testing.
10. A-LIGN
A-LIGN reports "2k+ PCI assessments" on its PCI DSS page, and its penetration testing page cites "OSCP/OSCE/OSEE-certified testers," "4,600+ completed engagements" and a RADAR platform for "continuous monitoring between annual tests."
HQ: Tampa, Florida. Delivery model: packaged testing tiers inside an assessment firm.
Named testers, retest: not stated. Portal: RADAR platform. Pricing: not published.
Accreditations verified: QSA, 3DS, QPA and SSF; no CREST Marketplace listing.
Strength: one assessor across PCI, SOC 2 and ISO 27001.
Limitation: the testing page does not reference Requirement 11.4 or segmentation, so ask for a PCI-scoped methodology.
Best for: growth-stage PSPs and SaaS platforms that embed payments.
11. Bishop Fox
Bishop Fox's compliance page states "PCI DSS requires penetration testing at least annually and upon any significant environment changes" and that the firm "is a PCI DSS approved scanning vendor (ASV)," with scanning as an add-on. Its Cosmos platform provides continuous offensive testing.
HQ: Tempe, Arizona. Delivery model: consultancy plus the Cosmos platform.
Named testers, retest: not stated. Portal: Cosmos. Pricing: not published.
Accreditations verified: CREST Penetration Testing; ASV.
Strength: offensive research depth, with ASV scanning from the same firm.
Limitation: the page still cites the ASV scan as requirement 11.2.2, the v3.2.1 number, now 11.3.2.
Best for: payment platforms that want offensive depth first.
12. LevelBlue
LevelBlue's penetration testing page covers "IT, OT/IoT, Physical, People," offers "retesting services at no additional cost," and sells testing on demand as a service. Its SpiderLabs team came with Trustwave, whose website now redirects to LevelBlue.
HQ: Plano, Texas. Delivery model: consultancy and managed security, with PTaaS.
Named testers: not stated. Retest: included at no additional cost. Portal: PTaaS. Pricing: not published.
Accreditations verified: QSA; CREST Penetration Testing, Threat Led Penetration Testing and further accreditations held by LevelBlue Cyber Solutions Ltd.
Strength: retesting in the price, with a QSA practice and CREST-accredited testing in the same group.
Limitation: no PCI-specific copy on the testing page, so agree requirement mapping in scoping.
Best for: payment businesses already buying managed security from LevelBlue.
How much does PCI DSS penetration testing cost in 2026?
PCI engagements price above a generic application test because scope spans internal and external networks, every segmentation method, the payment application and reporting an assessor reads line by line. The bands below are indicative: US figures from our penetration testing cost guide, Canadian figures from our Canadian cost analysis.
Scope | Indicative US band | Indicative Canadian band |
|---|---|---|
PCI DSS-scoped engagement, CDE internal, external and segmentation | US$12,000 to US$25,000 | Built from the network rows |
Payment portal or web application | US$5,000 to US$30,000+ | C$5,000 to C$40,000+ |
Payment API | US$6,000 to US$30,000 | C$8,000 to C$40,000 |
External network | US$5,000 to US$40,000+ | C$8,000 to C$50,000+ |
Internal network, into the CDE | US$5,000 to US$40,000+ | C$12,000 to C$50,000+ |
Mobile app and backend, per platform | US$7,000 to US$35,000 | C$10,000 to C$45,000 |
Cloud payment infrastructure | US$10,000 to US$50,000+ | C$13,000 to C$65,000+ |
Annual continuous program | Scoped to the estate | C$40,000 to C$120,000+ |
Three things move a PCI quote most: the number of segmentation methods, because 11.4.5 requires all of them; service provider status, which doubles the segmentation cadence and may add A1.1.4 testing; and retest cycles, which 11.4.4 does not cap.
Stingrai's only fixed prices cover one web application and its APIs: an Autonomous Pentest at US$3,000, Snipe only with no penetration testers, and a Hybrid Pentest at US$6,800, where Snipe and penetration testers test together throughout, or US$650 and US$1,275 per month on 12-month continuous plans. The Autonomous tier carries a No High or Critical Finding, Don't Pay guarantee. Every CDE, network and segmentation scope is quoted through get a quote; current figures are on the pricing page.
Buyer's checklist: what to ask every PCI penetration testing vendor
Who will test, and what do they hold? Names, certifications and engagement history in the statement of work.
Does the internal test start outside the CDE? 11.4.1 requires testing into the CDE from trusted and untrusted networks.
Is segmentation scoped by method, and is the six-monthly 11.4.6 clock priced in?
Is retesting included? 11.4.4 makes it mandatory and uncapped.
How is independence documented where the firm also assesses, operates or advises?
Will you test our payment APIs from every role, including refund and payout flows?
How do you handle the payment page? Script enumeration, tag manager access, and whether the 11.6.1 alert is tested.
Is the scope of work a separate artifact? Assessors examine it alongside the results.
Can we give customers redacted evidence for 11.4.7?
Can one vendor run the annual test and continuous coverage? Weekly releases against a 12-month clock leave most changes untested.
The pentest and red team RFP question bank turns these into tender language.
Frequently Asked Questions
Who are the best penetration testing companies for PCI DSS and payment providers in 2026?
The best PCI DSS penetration testing companies in 2026 are Stingrai, Coalfire, Praetorian, VikingCloud, SecurityMetrics, NetSPI, TrustedSec, ControlCase, Schellman, A-LIGN, Bishop Fox and LevelBlue. Stingrai ranks first as a CREST-accredited penetration testing service provider at firm level, with two named penetration testers per engagement holding OSCE³, OSWE, OSEP, CREST CRT and CISSP, testing payment APIs, webhooks, tokenization, internal networks and every segmentation method, one-time or continuously, with retesting and an attestation letter included.
Does a PCI penetration tester have to be a QSA?
No. Requirements 11.4.2, 11.4.3, 11.4.5 and 11.4.6 require a qualified internal resource or qualified external third party with organizational independence, "not required to be a QSA or ASV." The Council's Penetration Testing Guidance says the tester must be organizationally separate from the management of the target systems, and an assessing firm cannot test systems it installed, maintained or supported.
What does PCI DSS Requirement 11.4 require of a payment company?
Internal and external penetration testing at least every 12 months and after significant change, a documented nine-element methodology, correction of exploitable findings followed by repeat testing, and segmentation testing every 12 months. Service providers, which include payment gateways, PSPs and ISOs, test segmentation every six months, and multi-tenant service providers also test the separation between customer environments every six months under Appendix A1.1.4.
What do Requirements 6.4.3 and 11.6.1 require of a payment page?
Requirement 6.4.3 requires every payment page script to be authorized, integrity-assured and inventoried with a written justification. Requirement 11.6.1 requires a mechanism that alerts on unauthorized changes to security-impacting HTTP headers and script contents as received by the browser, at least weekly or per a targeted risk analysis. Both have been mandatory since 31 March 2025, and scripts in a processor's embedded payment form are the processor's responsibility.
What does Canada's Retail Payment Activities Act require of a PSP?
A risk management and incident response framework, and under section 9 of the Regulations a documented testing methodology that sets its own frequency and scope, reflects the PSP's impact and third-party reliance, and tests before material change. Section 10 adds an independent review every three years for PSPs with an auditor. The Regulations do not name penetration testing, but the Bank of Canada's guideline does for more interconnected PSPs. These provisions took effect on 8 September 2025.
Does NYDFS Part 500 apply to money transmitters?
Yes, for money transmitters licensed in New York under Article 13-B of the Banking Law, because Part 500 covers anyone operating under a Banking Law license. Section 500.5(a)(1) requires penetration testing from both inside and outside the information systems' boundaries by a qualified internal or external party at least annually. Entities under the 500.19(a) limited exemption are exempt from section 500.5.
Does the FTC Safeguards Rule require penetration testing for payment companies?
Yes, for non-bank financial institutions under FTC jurisdiction without effective continuous monitoring: 16 CFR 314.4(d)(2) requires annual penetration testing and vulnerability assessments every six months. A business that regularly wires money to and from consumers is a financial institution under the rule; a merchant is not one merely because it accepts cards it did not issue. Institutions holding data on fewer than 5,000 consumers are exempt from the testing paragraph.
How much does PCI DSS penetration testing cost in 2026?
Our cost guides give indicative bands: US$12,000 to US$25,000 for a PCI DSS-scoped engagement in the United States, and in Canada C$8,000 to C$50,000 or more for an external network test and C$12,000 to C$50,000 or more for an internal one. Segmentation methods, service provider status and retest cycles move the number most. Stingrai publishes fixed prices for one web application and its APIs, US$3,000 Autonomous or US$6,800 Hybrid per assessment, or US$650 and US$1,275 per month on 12-month plans, and quotes every other scope.
Related reading
PCI DSS Penetration Testing: Requirement 11.4 Explained (2026)
Pentest Evidence Auditors Accept: SOC 2, ISO 27001, PCI and CMMC
Best Penetration Testing Companies for Fintech and Banking (2026)
Best Retail and E-commerce Penetration Testing Companies (2026)
Best Banking and Credit Union Penetration Testing Companies (2026)
References
PCI Security Standards Council. Now is the Time for Organizations to Adopt the Future-Dated Requirements of PCI DSS v4.x, 20 August 2024. https://blog.pcisecuritystandards.org/now-is-the-time-for-organizations-to-adopt-the-future-dated-requirements-of-pci-dss-v4-x
PCI Security Standards Council. PCI DSS v4.0.1, June 2024: 6.4.3, 11.3, 11.4, 11.6.1, A1.1.4 and glossary. https://www.pcisecuritystandards.org/document_library/
PCI Security Standards Council. Information Supplement: Penetration Testing Guidance, v1.1, September 2017. https://www.pcisecuritystandards.org/documents/Penetration-Testing-Guidance-v1_1.pdf
PCI Security Standards Council. SAQ A updates, 30 January 2025. https://blog.pcisecuritystandards.org/important-updates-announced-for-merchants-validating-to-self-assessment-questionnaire-a
PCI Security Standards Council. PCI 3DS ROC Reporting Template, v1.0, December 2017. https://listings.pcisecuritystandards.org/documents/PCI-3DS-Core-v1-ROC-Reporting-Template.pdf
PCI Security Standards Council. PCI PIN Security Standard v3.1, 12 March 2021. https://blog.pcisecuritystandards.org/just-released-version-3-1-of-the-pci-pin-security-standard
PCI Security Standards Council. QSA and ASV listings, checked 25 September 2026. https://www.pcisecuritystandards.org/assessors_and_solutions/qualified_security_assessors/
Visa. Account Information Security Program. https://corporate.visa.com/en/resources/security-compliance.html
Mastercard. Site Data Protection Program. https://www.mastercard.com/global/en/business/cybersecurity-fraud-prevention/site-data-protection-pci.html
Moneris. PCI Data Security. https://www.moneris.com/en/support/compliance-and-security/pci-data-security
Government of Canada. Retail Payment Activities Act, section 17. https://laws-lois.justice.gc.ca/eng/acts/R-7.36/
Government of Canada. Retail Payment Activities Regulations, SOR/2023-229, sections 9, 10 and 55. https://laws-lois.justice.gc.ca/eng/regulations/SOR-2023-229/FullText.html
Bank of Canada. Operational risk and incident response, section 10 and Appendix G. https://www.bankofcanada.ca/wp-content/uploads/2024/02/operational-risk-and-incident-response.pdf
New York State Department of Financial Services. 23 NYCRR 500, second amendment. https://www.dfs.ny.gov/system/files/documents/2023/10/rf_fs_2amend23NYCRR500_text_20231101.pdf
New York State Department of Financial Services. Money Transmitters. https://www.dfs.ny.gov/apps_and_licensing/money_transmitters
Federal Trade Commission. 16 CFR 314.2, 314.4(d)(2) and 314.6. https://www.law.cornell.edu/cfr/text/16/314.4
OWASP Foundation. API Security Top 10 2023. https://owasp.org/API-Security/editions/2023/en/0x11-t10/
CREST. CREST Marketplace, checked 25 September 2026. https://marketplace.crest.org/
Stingrai. Pricing. https://www.stingrai.io/pricing
Ready to scope a PCI DSS penetration test?
The finding that becomes a card data breach is rarely a missing patch. It is a refund endpoint that trusts a merchant identifier, or a segmentation rule that stopped isolating the CDE after last quarter's network change. Stingrai's CREST-accredited penetration testing supports PCI DSS 4.0.1, SOC 2 and ISO 27001 compliance programs with the scope of work, report and retest evidence they consume, one-time or continuously. Book a free scoping call, get a quote for a CDE or service provider scope, or read the pricing page.



