UK e-commerce teams hear “we’re SAQ-A, we don’t need a pentest.” Sometimes that is true. Sometimes the way the shop was built quietly pulled the card data environment back onto the storefront. PCI DSS v4 is less patient with that confusion than v3.2.1 was.

Requirement 11.4 in one paragraph

If you are in scope for a pentest, you need an external one, and if you have an internal CDE you need that too, by a qualified tester, with segmentation checks if you rely on segmentation, at least annually and after significant change. Your QSA’s reading wins over a blog post — including this one.

The UK shop pattern that surprises founders

Custom checkout talking to a processor, plus an admin pane on the same origin, plus a staging site with production credentials, plus a mobile app with a stored card token flow. The pentest scope is not “the React app.” It is every component that can become CDE by accident.

What we will not do

We will not sign a ROC. We will not pretend to be a QSA. We will run the application and network test your QSA asked the merchant to commission, with a scope statement the QSA can read in five minutes.

Bring this to the scoping call

Your current SAQ or ROC type, a diagram, whether you store PAN, and last year’s pentest if you have one. We will tell you if we are the right tester or if you need a CHECK/CREST-named supplier for that particular contract.

Need this as an engagement, not an article?

UK hours. GBP quote. Written CMA 1990 authorisation.

Request a pentest