Published in June 2024, PCI DSS 4.0.1 is a limited revision that clarifies requirements and introduces minor updates to the standard without introducing new mandates. In this article, Arcanum Cyber Security Consultant and PCI Qualified Security Assessor, Claire Greathead, outlines what the most recent version of the standard is all about and where organisations need to pay attention to the updates made in the last two years.
The original PCI DSS v4.0 has now been with us for several years, having been introduced in March 2022 to place more emphasis on client side threats, continuous security provision and updates to provide more flexibility as new technologies are introduced to the payment card industry.
As organisations have embraced cloud infrastructure, SaaS platforms, APIs, remote working, DevOps pipelines and increasingly complex e-commerce platforms, v3.2.1 was outdated and behind the times in many areas. It was also becoming obvious that attackers had increasingly focused efforts on supply chains, browser-based attacks and stolen credentials, rather than traditional network vulnerabilities.
As a result, the PCI Security Standards Council laid out four clear objectives:
- Respond to today’s cyber threats rather than yesterday’s
- Make security a continuous process NOT an annual exercise
- Introduce greater flexibility for those organisations with mature security programmes
- Strengthen validation to ensure that controls are effective rather than simply documented
For consultants, this last point is perhaps the most important update we have seen during assessments because the emphasis has moved away from simply having policies in place towards demonstrating that security operates effectively on a daily basis.
What changed in PCI DSS 4.0.1?
When the latest iteration of the standard was released in 2024, it took into account feedback from assessors, merchants and service providers and refined the wording of several requirements to remove ambiguity.
In PC DSS 4.0.1, minor refinements have now been introduced to demonstrate the continuous effort to enhance payment account data security and facilitate the wider adoption of consistent data security measures.
Examples as listed on the PCI SSC website include:
Requirement 3
- Clarified Applicability Notes for issuers and companies supporting issuing services
- Added a Customised Approach Objective and clarified applicability for organisations using keyed cryptographic hashes to render Primary Account Numbers (PAN) unreadable
Requirement 6
- Reverted to PCI DSS v3.2.1 language around the installation of patches/updates within 30 days to clarify that this only applies for “critical vulnerabilities”
- Added Applicability Notes to clarify how the requirement for managing payment page scripts should apply
Requirement 8
- Added an Applicability Note that multi-factor authentication for all (non-administrative) access into the CDE does not apply to user accounts that are only authenticated with phishing-resistant authentication factors
Requirement 12
- Updated Applicability Notes to clarify a number of points around relationships between customers and third-party service providers
Appendices
- Removed Customised Approach sample templates from Appendix E and referred to the sample templates that are available on the PCI SSC website
- Added definitions for “Legal Exception”, “Phishing Resistant Authentication” and “Visitor” to Appendix G
It’s important to note, that no new requirements were introduced and none were removed. However, some requirements have become more prominent due to new and evolving technologies. A prime example of this is quarterly validated vulnerability scans, which were previously out of scope for some SAQ A e-commerce merchants but is now a requirement, depending on how payment pages are implemented.
Requirement 11.3.2 also reinforces that these scans must be performed by a PCI SSC Approved Scanning Vendor (ASV). Any vulnerabilities identified must be remediated and a passing rescan obtained before the requirement can be considered satisfied.
What does this mean for organisations?
PCI DSS 4.0.1 may have been with us since 2024 but perhaps the more important date for organisations to be aware of was March 2025 when the new requirements became mandatory.
Many organisations validated against PCI DSS 4.0 before March 2025 may now find themselves noncompliant now that the transition period has ended.
As a PCI QSA, one of the common issues I have seen during audits is in organisations catching up with some of these refinements and adequately demonstrating their ongoing security.
In particular, the requirement to perform continuous risk analysis and implement a frequent testing strategy is often a weakness. However, it is essential for organisations looking to align with the standard to demonstrate a move towards risk-based decision making.
Similarly, organisations are now required to validate PCI scope annually and revisit this as their payment systems, cloud services or other solutions evolve. In our work at Arcanum we recommend regular scoping exercises – which helps to avoid both unnecessary assessment costs and also dangerous blind spots in security.
One of the other key areas that has become essential in recent iterations of the PCI DSS standard is the requirement for multi-factor authentication across an organisation – not just for administrative users. This is a common issue within organisations of all sizes and one that I recommend information security teams get to grips with at the earliest opportunity.
Next steps
If you treated the PCI DSS 4.0.1 future-dated requirements as best practice rather than mandatory previously, then your next steps should be:
- Perform a fresh PCI DSS 4.0.1 gap assessment
- Review all your future-dated requirements implemented since March 2025
- Validate your PCI scope and document the outcome
- Review MFA coverage across your entire Cardholder Data Environment
- Assess browser security controls for any payment pages
- Review vulnerability management and patching processes
- Update responsibility matrices and security documentation
- Carry out penetration testing and vulnerability assessments against the current standard
- Work with a Qualified Security Assessor to identify remediation work before formal assessment
Perhaps the biggest takeaway from recent iterations of the PCI Data Security Standard is that it reflects the evolving nature of threats in the modern world. Organisations that find PCI DSS compliance easiest to maintain are those that embed security into everyday operations rather than preparing for annual compliance.
In my experience, organisations that regularly test their environments, review scope, monitor vulnerabilities and look to continually improve security controls find assessments to be much smoother – and, just as importantly, find it easier to maintain stronger protection for customer payment data.
Whether you are looking to complete a Self Assessment Questionnaire for the first time or want to align with 4.0.1 ahead of forma Report on Compliance (RoC), get in touch with Arcanum today and we can help to achieve compliance and demonstrate robust security standards. Book a PCI DSS consultation.