Conduct testing at least annually - Include both internal and external testing - Test all components of the in-scope system - Demonstrate that findings were tracked to remediation - Show that testing methodology aligns with recognized standards