A yearly pen test is not change detection

Requirement 11.6.1 is continuous by construction. An annual test can find a hole that was there on the day. It cannot notice a script that was swapped and swapped back inside a week.

Last reviewed against PCI DSS v4.0.1 in September 2026.

Yearly pen test versus continuous change detection
Yearly penetration testWhat 11.6.1 asks for
How oftenOnce, on a booked dateAt least every seven days
What it looks atWhatever the tester can reach that weekThe payment page as the customer's browser received it
A script added on Tuesday and removed on Thursdaymisseda dated change record
Headers as deliveredSometimes, if the tester thought to record themPart of the requirement
Skimmer that sleeps for automated browsersOften served the clean pageNeeds a reading from a real visitor's browser
Evidence an assessor can fileA report for that engagementA baseline, weekly checks, change records, and who was alerted

Where a yearly test is the better instrument

A penetration test is better at finding a logic flaw, an open admin path, or a misconfigured origin. Tagnovo does not do that work and will not pretend to. If your acquirer asked for a pen test, you still need the pen test.

What it is not: a substitute forrequirement 11.6.1. The wording is about unauthorized change to payment pages, detected at least weekly, as received. That is a different job.

The usual mistake

Filing last year's pen-test PDF against 11.6.1 because both mention "security" and "payment pages". An assessor who has read the clause will ask for the weekly record.

We are not a QSA and this is not advice. Ask your acquirer what evidence they want to see for 11.6.1. Three sentences that get that answer in writing.

See what payment-page monitoring produces

A baseline of authorized scripts, timestamped checks, every change, and who reviewed it. Tagnovo is not a QSA and does not certify compliance.

Payment page monitoring