Ask Secure Assess a question. Answers come from this site's docs only. I will cite a page. I will not invent a product claim.
Pen testing vs. vulnerability assessment
Both appear in PCI DSS testing requirements — and they are not the same engagement. Secure Assess provides PCI DSS 11.3 vulnerability assessment. It does not provide PCI 11.4 penetration testing.
Vulnerability assessment (PCI DSS 11.3)
A vulnerability assessment identifies and ranks technical weaknesses on systems you authorize — typically via scanning (external and, when credentials are supplied, credentialed). Deliverables are findings, advice, and a written report. For Secure Assess that includes PCI 11.3 mapping and ASV-readiness PASS or FAIL.
- Defensive: report and advise; do not exploit.
- Repeatable on a schedule against the same scope.
- Useful for ongoing 11.3 readiness and internal review.
Penetration testing (PCI DSS 11.4)
Penetration testing is a separate activity: authorized attempts to exploit weaknesses, often with manual techniques, to demonstrate impact. It is not a substitute for regular vulnerability assessment, and vulnerability assessment is not a substitute for pen testing.
- May involve exploitation within an agreed rules of engagement.
- Typically project-shaped rather than a continuous scan cadence.
- Out of scope for Secure Assess.
What Secure Assess does — and does not
- Does: defensive external + credentialed VA, scheduled scans, AI-triaged findings, PDF with 11.3 mapping, ASV-readiness PASS/FAIL.
- Does not: PCI 11.4 pen testing, exploitation, payloads, red teaming, or “proving” a path by running it.
- Does not: official ASV attestation, card-brand filing, or a full PCI DSS 4.0 compliance program.
If you need a pen test, engage a provider that sells that service. If you need a defensive 11.3 assessment with a clear readiness result, Secure Assess is built for that.
Related: PCI DSS 11.3 & ASV-readiness · vulnerability assessment · what it does · open the app.
Choose the assessment, not the attack
Start a defensive PCI 11.3 vulnerability assessment in the app. We scan and advise. We never attack.