External and internal, annually and on change
Requirement 11.4 calls for penetration testing from outside and inside the network at least annually and after any significant infrastructure or application change. We scope both perspectives against your cardholder data environment and run on your change cadence, not just a calendar.