SchellmanCON is back! Join us for our virtual conference on March 6 & 7, 2025

Contact Us
Services
Services
Crypto and Digital Trust
Crypto and Digital Trust
Schellman Training
Schellman Training
Sustainability Services
Sustainability Services
AI Services
AI Services
About Us
About Us
Leadership Team
Leadership Team
Corporate Social Responsibility
Corporate Social Responsibility
Careers
Careers
Strategic Partnerships
Strategic Partnerships

Why Schellman is Able to Perform Both PCI DSS and Penetration Testing Services for Your Organization

Payment Card Assessments

Hi, I'm Matt Crane. I'm a leader in the payment security practice here at Schellman.

We're often asked if we're able to do both PCI assessments and penetration testing for the same client. In this video, we'll explain how we're able to provide both and why it's not an independence issue.

First and foremost, I want to cover what the PCI Council says about this. While they don't specifically state that it is or is not an independence issue, if you look at Requirement 11.4 of PCI DSS v4.0, it talks about penetration testing services methodologies. The two main criteria that you have to have as a penetration tester to meet that requirement are:

  • You have organizational independence, which means that the individual performing the test cannot be ultimately responsible for securing that system.
    • (It goes on to say that organizational independence doesn't mean it has to be an ASV or approved scanning vendor or even a QSA, but so long that that individual doesn't have control over the systems they're testing, it's fine. So, if you have an internal resource that's qualified, you can move forward with them.) 
  • The organization or the individual conducting the penetration test must be qualified to do so.
    •  Schellman's penetration testing team, with many of its members holding multiple certifications is, in fact, qualified to do so.
So, from the Council's perspective, it's perfectly fine to have your QSA company performing both the pen test as well as the QSA services for the PCI assessment so long as they meet those two criteria.

At Schellman, we go a little bit further to make sure we don't have independence issues. Our payment security team—which is ultimately comprised of PCI QSAs—and penetration test teams are separate, and they each have different management structures.

We do that really for a couple of different reasonsprimarily because a QSA and a penetration tester have very different skill sets, but also so there's no perceived bias for a QSA who's also doing penetration testing services for the same client.

Now that we've covered why Schellman can do both your pen testing as well as PCI assessments, feel free to reach out to us if you are using us for one of the services but not the other, or if you're looking for a new QSA company or a penetration tester. 

About Schellman

Schellman is a leading provider of attestation and compliance services. We are the only company in the world that is a CPA firm, a globally licensed PCI Qualified Security Assessor, an ISO Certification Body, HITRUST CSF Assessor, a FedRAMP 3PAO, and most recently, an APEC Accountability Agent. Renowned for expertise tempered by practical experience, Schellman's professionals provide superior client service balanced by steadfast independence. Our approach builds successful, long-term relationships and allows our clients to achieve multiple compliance objectives through a single third-party assessor.