Scope clarification

Pen testing vs. vulnerability assessment

Both appear in PCI DSS testing requirements — and they are not the same engagement. Secure Assess provides PCI DSS 11.3 vulnerability assessment. It does not provide PCI 11.4 penetration testing.

Vulnerability assessment (PCI DSS 11.3)

A vulnerability assessment identifies and ranks technical weaknesses on systems you authorize — typically via scanning (external and, when credentials are supplied, credentialed). Deliverables are findings, advice, and a written report. For Secure Assess that includes PCI 11.3 mapping and ASV-readiness PASS or FAIL.

  • Defensive: report and advise; do not exploit.
  • Repeatable on a schedule against the same scope.
  • Useful for ongoing 11.3 readiness and internal review.

Penetration testing (PCI DSS 11.4)

Penetration testing is a separate activity: authorized attempts to exploit weaknesses, often with manual techniques, to demonstrate impact. It is not a substitute for regular vulnerability assessment, and vulnerability assessment is not a substitute for pen testing.

  • May involve exploitation within an agreed rules of engagement.
  • Typically project-shaped rather than a continuous scan cadence.
  • Out of scope for Secure Assess.

What Secure Assess does — and does not

  • Does: defensive external + credentialed VA, scheduled scans, AI-triaged findings, PDF with 11.3 mapping, ASV-readiness PASS/FAIL.
  • Does not: PCI 11.4 pen testing, exploitation, payloads, red teaming, or “proving” a path by running it.
  • Does not: official ASV attestation, card-brand filing, or a full PCI DSS 4.0 compliance program.

If you need a pen test, engage a provider that sells that service. If you need a defensive 11.3 assessment with a clear readiness result, Secure Assess is built for that.

Related: PCI DSS 11.3 & ASV-readiness · vulnerability assessment · what it does · open the app.

Choose the assessment, not the attack

Start a defensive PCI 11.3 vulnerability assessment in the app. We scan and advise. We never attack.