Read time:00:03
Release date:7.27.2026
A payment gateway captures card details at the point of payment (the merchant’s checkout) and passes them to a bank for authorization.
PCA Cyber Security provides PCI DSS-compliant penetration testing for payment gateways.
Payment gateways such as Stripe, PayPal, J.P. Morgan, and Adyen capture and transmit the authorization request needed to enable the transfer of funds from a bank to a merchant. Hundreds of millions of transactions each day involve payment gateways.
Under PCI DSS, payment gateways are treated as service providers. Thus, they are subject to PCI DSS testing as per PCI DSS v4.0.1. With good reason: payment gateways capture extremely sensitive information and are very attractive targets for cybercriminals.
Attackers attempt to hijack the card payment flow at various points within the gateway. In 2024, for example, payment gateway provider Slim CD disclosed a breach of its network that ran undetected from August 2023 to June 2024 and exposed the names, addresses, card numbers, and expiry dates of about 1.7 million people.
This article provides a high-level view of PCI DSS testing requirements, processes, and types for payment gateways.
Is PCI DSS Testing Needed for Payment Gateways?
Yes, PCI DSS testing is required for payment gateways.
Because it transmits cardholder data on behalf of merchants, a payment gateway is classed as a PCI DSS service provider. The gateway operator must therefore carry out PCI DSS-compliant testing, including:
- Quarterly external scans.
- Internal scans every three months
- Annual penetration testing.
- Segmentation testing every six months under the stricter service-provider cadence.
For a Level 1 provider, annual validation must also be signed off by a PCI QSA.
Acquiring banks and merchants will expect evidence of this testing when they integrate with the gateway, as they inherit its risk and compliance scope. In practice, they request a current Attestation of Compliance.
Who Does PCI DSS-Compliant Testing for Payment Gateways?
PCI DSS-compliant testing is usually carried out by a third-party testing firm, such as PCA Cyber Security, which follows PCI DSS Penetration Testing Guidance v1.1.
PCA Cyber Security provides PCI DSS v4.0.1-compliant penetration testing that secures cardholder data environments (CDEs) by identifying application and network vulnerabilities, validating segmentation controls, and meeting the required PCI DSS testing frequencies. Where clients use segmentation, CDE isolation is verified to confirm the separation holds.
This testing also includes vulnerability assessment, remediation, and retesting, helping organizations achieve and maintain compliance.
Which PCI DSS Requirements Map to Payment Gateways In 2026?
The list below maps the latest standard, PCI DSS v4.0.1, to the requirements that apply to payment gateways.
- Requirement 11.3.2, External vulnerability scans. PCI DSS requires external scans of payment gateways to be performed at least once every 3 months by a PCI SSC-approved scanning vendor (ASV).
- Requirement 11.3.1, Internal vulnerability scans. Internal scans must be performed at least once every three months.
- Requirement 11.4, Penetration testing. This has two subcomponents, internal penetration testing (11.4.2) and external penetration testing (11.4.3), each required under the entity's defined methodology at least once every 12 months, and after any significant infrastructure or application change.
- Requirement 11.4.6, Segmentation testing. This must be carried out at least once every six months and after changes to segmentation controls.
- Multi-tenant gateways fall under A1.1.4, which requires the effectiveness of logical separation between customer environments to be confirmed at least once every six months via penetration testing.
- Requirements 6.4.3 and 11.6.1. 6.4.3, Payment page integrity. All payment page scripts loaded and executed in the consumer's browser must be managed, including a method to confirm each script is authorized, plus integrity assurance and an inventory.
- 11.6.1 requires a change- and tamper-detection mechanism that alerts personnel to unauthorized modification of the security-impacting HTTP headers and script contents of payment pages as received by the consumer browser.
Note: An annual assessment, QSA validation, and Attestation of Compliance are also required, though these do not map to a single numbered requirement.
Testing Payment Gateways with PCA Cyber Security
Payment gateways handle hundreds of millions of transactions a day, which puts them among the most attractive targets in the payment chain.
PCA Cyber Security provides PCI DSS-compliant penetration testing. Our team can identify and mitigate security vulnerabilities in payment systems, POS terminals, ATMs, and Cardholder Data Environments (CDEs) by simulating real attack scenarios to assess network, application, and segmentation controls to ensure compliance with PCI DSS 4.0.1 requirements.
The gateways that stay secure are the ones whose operators treat testing as continuous assurance, not a once-a-year certificate.
Article tags
pci dss
pci pts
payment device security
penetration testing of payment devices
payment gateway security
Latest Posts
June 30, 2026
Popular tags
pci pts
payment device security
automotive threat intelligence
automotive cybersecurity
pci dss
pcautomotive
pcacybersecurity
payment security
cra
pts device security

