Pentr maps every Section 11 requirement to a phase in the agent's seven-phase PTES pipeline. External and internal pen tests produce control-mapped evidence — ready for your QSA, sealed in a signed locker.
Each row is a PCI requirement, the phase in the agent that satisfies it, and the artifacts the locker holds for your QSA.
Locks the CDE scope and seals a signed consent attestation.
Identifies in-scope perimeter, DNS, certificate boundaries.
Maps APIs and admin paths exposed beyond the CDE boundary.
Cross-references against KEV + ENISA + NIST NVD.
Screenshot at success and full command log sealed to the locker.
Internal pivot and escalation from inside the CDE, captured.
sha-256 chain signed at seal time. QSA verifier-ready.
Plug in a CDE scope. The agent runs Sections 11.3 and 11.4. The locker is sealed and signed, ready for the QSA before the call is over.