Segmentation Testing
Segmentation testing is a set of checks used to confirm that network controls meant to separate one part of a network from another are actually working as intended. In payment security, it helps verify that systems outside the sensitive cardholder data environment cannot reach systems inside it. This supports the practice of narrowing which systems fall under compliance requirements.
Segmentation testing is the validation activity that confirms the effectiveness of network segmentation controls used to isolate an in-scope environment (such as the cardholder data environment) from out-of-scope networks. The same technologies used to segment networks are often also used to manage access between in-scope systems or networks, so testing verifies that these controls actually prevent connectivity between segments as designed rather than merely being configured. In a PCI DSS context, segmentation testing is a component of validating scope reduction; practitioners should confirm the specific testing frequency, method, and requirement wording against the current published version of PCI DSS, as these differ between versions. Note that segmentation testing validates isolation controls and is distinct from broader penetration testing of in-scope systems, though the two are frequently performed together.
Why it matters
Network segmentation is one of the most common ways organizations reduce the number of systems that fall under PCI DSS requirements. By isolating the cardholder data environment (CDE) from the rest of the network, a business can narrow the scope of what must be assessed and secured. However, segmentation only provides that benefit if the controls actually work. A firewall rule, access control list, or VLAN configuration that looks correct on paper may still permit unintended connectivity in practice. Segmentation testing exists to close that gap between intended design and actual behavior.
This matters because the technologies used to separate networks are frequently the same ones used to manage access between in-scope systems. A misconfiguration can quietly place out-of-scope systems within reach of the CDE, expanding the true attack surface and potentially the compliance scope without anyone realizing it. If segmentation fails and cannot be demonstrated as effective, systems assumed to be out of scope may in fact need to be treated as in scope, which can undermine the scope reduction the organization relied upon.
For these reasons, segmentation testing supports both security and compliance objectives. It helps confirm that isolation controls prevent connectivity between segments as designed rather than merely being configured, and it provides evidence that scope reduction claims are defensible. Practitioners should confirm the required testing frequency, method, and specific requirement wording against the current published version of PCI DSS, as these details differ between versions.
Who it's relevant to
Inside Segmentation Testing
Common questions
Answers to the questions practitioners most commonly ask about Segmentation Testing.