Pentest report — external and internal
Separate sections for 11.3.1 (external) and 11.3.2 (internal). Each finding includes CVSS 4.0 vector, risk narrative, reproduction steps, and remediation. Methodology section cites PTES and OWASP WSTG.
Segmentation validation report
Dedicated section or standalone report for 11.3.4. Documents what was tested, from what position, and the result of each segmentation test. Traffic captures and denial evidence included.
Retest report for 11.3.3
Each exploitable finding retested after remediation. Marked resolved, partially resolved, or accepted-risk with documented rationale. QSAs accept this as closure evidence without additional review cycles.
Tester qualification documentation
Named engineer, relevant certifications, confirmation of organizational independence from the CDE. PCI DSS v4.0 requires QSAs to verify tester qualifications — we provide this proactively.