The Direct Answer
Auditors performing PCI DSS 4.0 assessments require documented evidence that network segmentation properly isolates cardholder data environments (CDE) from out-of-scope systems. This means penetration testing reports demonstrating failed connection attempts from untrusted networks to CDE systems, network diagrams showing segmentation boundaries, firewall rule reviews confirming deny-by-default configurations, and annual testing that validates controls remain effective. The testing must be performed by qualified internal staff or third-party penetration testers and repeated annually or after significant infrastructure changes.
Why Segmentation Testing Matters More in 2026
The threat landscape makes proper segmentation critical. This week alone, CISA added CVE-2026-73570 affecting Zimbra Collaboration Suite to the Known Exploited Vulnerabilities catalog due to active exploitation. When attackers compromise a single system, segmentation is the control that prevents lateral movement into payment systems.
Network segmentation reduces PCI DSS scope by creating defensible boundaries. Fewer in-scope systems mean lower compliance costs, simplified audits, and reduced risk exposure. But auditors have seen too many organizations claim segmentation without proving it works—which is why testing requirements have become more rigorous under PCI DSS 4.0.
What Auditors Verify During Segmentation Testing Review
Penetration Testing Reports
Your Qualified Security Assessor (QSA) will request penetration testing reports that specifically target segmentation controls. These reports must document:
- Source and destination systems tested: Clear identification of untrusted networks (guest WiFi, corporate workstations, vendor access points) and CDE targets (payment applications, databases storing cardholder data, payment gateways)
- Test methodology: Manual testing techniques, not just automated vulnerability scans. Auditors want evidence of actual connection attempts, not theoretical vulnerability findings
- Failed connection attempts: Screenshots, packet captures, or detailed logs showing that segmentation controls blocked unauthorized access
- Successful attacks that shouldn't have worked: Any breach of segmentation boundaries must be documented, remediated, and retested
The recent disclosure of Microsoft Defender's driver being weaponized to delete security software illustrates why testing must go beyond configuration reviews. Sophisticated attackers find unexpected paths—your segmentation testing should too.
Network Diagrams and Data Flow Documentation
Auditors need current network diagrams showing:
- All connections between CDE and non-CDE networks
- Segmentation controls (firewalls, VLANs, access control lists) at each boundary
- System classifications (in-scope, out-of-scope, connected-to)
- Data flows including payment authorization, settlement, and reporting
These diagrams must match your actual infrastructure. Auditors frequently cross-reference diagrams against firewall configurations and penetration test findings. Inconsistencies raise red flags and extend audit timelines.
Firewall and Access Control Rule Reviews
QSAs examine firewall rules governing CDE access to verify:
- Deny-by-default configuration: All traffic blocked except explicitly permitted flows
- Justified business need: Each allow rule documented with business purpose and approval
- Minimal necessary access: Rules limited to specific protocols, ports, and IP addresses
- Regular review process: Evidence that rules are reviewed at least every six months
With hundreds of leaked AWS keys giving full control over corporate accounts, cloud security group policies and network ACLs receive the same scrutiny as traditional firewalls.
Common Segmentation Testing Failures
Testing Only From One Direction
Many organizations test inbound connections to the CDE but forget outbound restrictions. Compromised CDE systems shouldn't reach arbitrary internet destinations or internal development networks. Bidirectional testing is required.
Using Only Automated Scanning Tools
Vulnerability scanners verify patch levels but don't test segmentation effectiveness. Auditors want evidence of manual testing attempts: Can you SSH from a marketing workstation to the payment database? Can you RDP from guest WiFi to a POS terminal?
Outdated Testing After Infrastructure Changes
Segmentation testing must occur annually and after significant changes. Migrating payment processing to AWS, adding a new payment channel, or implementing SD-WAN all trigger retesting requirements. Auditors check change management records against testing dates.
Insufficient Documentation of Compensating Controls
When proper segmentation isn't technically feasible, PCI DSS allows compensating controls—but documentation requirements are stringent. You must demonstrate the control addresses the original requirement's intent, provides similar protection, and is monitored for effectiveness.
Step-by-Step: Preparing for Segmentation Testing Review
1. Update network documentation (2-3 weeks before audit): Create or refresh network diagrams showing current segmentation architecture. Include cloud environments, remote access paths, and third-party connections.
2. Conduct penetration testing (4-6 weeks before audit): Engage qualified penetration testers to attempt bypassing segmentation controls from multiple untrusted networks. Budget $8,000-$25,000 depending on environment complexity.
3. Remediate findings and retest (2-4 weeks): Address any segmentation bypasses discovered during testing. Retest to confirm remediation effectiveness before the audit.
4. Review firewall rules (1-2 weeks before audit): Document business justification for each rule permitting CDE access. Remove unnecessary rules. Ensure review and approval records are current.
5. Prepare evidence package: Compile penetration test reports, network diagrams, firewall rule reviews, change management records, and compensating control documentation in a format QSAs can easily review.
6. Conduct internal pre-assessment: Have your IT team walk through the evidence package as if they were auditors. Identify gaps before the QSA does.
What Testing Frequency Is Actually Required
PCI DSS 4.0 requires segmentation testing:
- At least annually
- After significant changes to network architecture or segmentation controls
- After adding new connections to the CDE
- Following any suspected or confirmed compromise
Many organizations schedule testing 6-8 weeks before their annual assessment to allow remediation time. Others perform testing quarterly to catch issues early and spread effort throughout the year.
How Penetration Testing Firms Approach Segmentation
Professional penetration testing for PCI DSS segmentation follows a structured methodology:
- Scoping workshop: Identify all segmentation boundaries, untrusted networks, and CDE assets
- Passive reconnaissance: Map network topology and identify potential bypass paths
- Active testing: Attempt connections using various protocols, exploitation techniques, and social engineering
- Evasion testing: Try bypassing controls using tunneling, protocol manipulation, and misuse of legitimate services
- Documentation: Provide detailed reports with evidence suitable for QSA review
The discovery of 14 trojanized npm packages delivering AI-assisted backdoors demonstrates why testing must include software supply chain attack vectors—malicious code in legitimate applications can bypass network segmentation entirely.
The Real Cost of Failed Segmentation
Organizations with ineffective segmentation face:
- Expanded PCI scope: More systems requiring security controls, logging, and quarterly scanning
- Failed audits: Segmentation is a core requirement; failures can result in certification delays or denials
- Increased breach impact: Compromised systems provide attackers access to payment data
- Higher ongoing costs: More in-scope systems mean more security controls to implement and maintain
Proper segmentation testing is an investment that pays dividends through reduced scope, faster audits, and genuine security improvement.
Vici Tech Solutions performs PCI DSS segmentation testing for merchants and service providers across the NYC metro area, delivering audit-ready reports that QSAs accept without question. Contact our team to discuss your segmentation testing needs and ensure your next assessment goes smoothly.