Frameworks · PCI DSS v4.0

Cardholder data, verified.

Pentr maps every Section 11 requirement to a phase in the agent's seven-phase PTES pipeline. External and internal pen tests produce control-mapped evidence — ready for your QSA, sealed in a signed locker.

Controls covered
42 / 42
Cadence
Quarterly + on change
Evidence retention
12 months
QSA-tested
14 firms
Controls covered

Section 11 — tested and sealed.

Each row is a PCI requirement, the phase in the agent that satisfies it, and the artifacts the locker holds for your QSA.

ID
Requirement
Phase
Artifacts
11.3.1
External pen tests on perimeter and critical systems
At least annually and after any significant change.
05 · exploitation
14 sealed
11.3.2
Internal pen tests
From inside the CDE; lateral movement attempts captured.
06 · post-exploit
11 sealed
11.3.3
Exploitable vulnerabilities corrected and re-tested
Re-runs the failing phase only, against the same scope, signed.
05 + 07
6 sealed
11.3.4
Segmentation controls tested
Verifies CDE isolation from out-of-scope networks.
02 + 03
4 sealed
11.4.1
IDS / IPS detection of unauthorised activity
Captures detector alerts triggered by agent traffic.
02 · intelligence
3 sealed
11.5.1
Change-detection on critical files
File-integrity monitoring evidence cross-referenced with run timeline.
04 · vuln analysis
2 sealed
A.6.1
External pen tests for service providers
Quarterly externals against in-scope service-provider components.
05 · exploitation
2 sealed
Phase → control mapping

Where each phase earns its evidence.

01 · Pre-engagement

Scope & consent

Locks the CDE scope and seals a signed consent attestation.

11.3.4
02 · Intelligence

Surface mapping

Identifies in-scope perimeter, DNS, certificate boundaries.

11.4.1A.6
03 · Threat modeling

Attack surface

Maps APIs and admin paths exposed beyond the CDE boundary.

11.3.411.4
04 · Vuln analysis

Known-CVE matching

Cross-references against KEV + ENISA + NIST NVD.

11.3.111.5.1
05 · Exploitation

Confirmed exploit

Screenshot at success and full command log sealed to the locker.

11.3.111.3.3
06 · Post-exploitation

Lateral movement

Internal pivot and escalation from inside the CDE, captured.

11.3.2
07 · Reporting

Locker seal

sha-256 chain signed at seal time. QSA verifier-ready.

11.3.3A.6.1

Run your first PCI campaign.

Plug in a CDE scope. The agent runs Sections 11.3 and 11.4. The locker is sealed and signed, ready for the QSA before the call is over.