As a Qualified Security Assessor Company (QSAC) we often get asked by our clients if they are able to fulfil their ongoing PCI penetration testing requirements in-house. The short answer is it depends.PCI DSS requirement 11.3 covers an organisations r…