The deadline for PCI DSS V4.0 is just around the corner… here’s everything you need to know

With the deadline for PCI DSS V4.0 being only a couple of weeks away, we wanted to share some of the most important things you should be aware of before the transition is complete…

What is PCI Compliance?

Achieving PCI compliance means meeting the standards set by the Payment Card Industry Data Security Standard (PCI DSS). This global standard is mandatory for organisations handling card payments and is designed to enhance data security and protect merchants and customers during debit or credit card transactions.

What is PCI DSS V4.0?

PCI DSS V4.0 is the latest evolution of the PCI DSS, introduced by the PCI Council to address emerging threats and technologies. It represents the most significant set of changes since version 3.2.1, released in 2018.

When should I achieve PCI DSS V4 compliance?

While PCI DSS V4 officially becomes the standard for PCI compliance starting April 1, 2024, there are future-dated requirements effective from April 1, 2025. This allows a grace period for some technical adjustments in your environment, facilitating a phased implementation.

If you are currently operating on version 3.2.1 and your renewal is scheduled before the transition period, you will remain valid under version 3.2.1 until your recertification date, which is 12 months from now. However, if you plan to recertify, implement PCI compliance, or make changes within a new environment, it is advisable to align with version four at this stage.

What’s changing with the introducion of PCI DSS v4.0?

1. Authentication and Password Requirements:

Change: Multi-factor authentication requirements are expanded beyond administrators and the cardholder data environment to cover all users accessing that environment.

Implication: organisations must adapt to broader authentication protocols for enhanced security.

Change: Password requirements are updated from seven characters with at least one uppercase, lowercase, and number to more complex specifications, a minimum of 12 characters (or 8 if the system doesn’t support 12).

Implication: Strengthened password protocols necessitate adjustments for compliance.

Change: Promotion of password savers and vaults for storing longer, more complex passwords.

Implication: Emphasis on secure storage methods for robust password management.

2. E-commerce and Phishing Requirements:

Change: Introduction of new requirements for e-commerce and phishing, including alerting and anti-tampering technologies.

Implication: organisations dealing with payment services through iframe or redirects must implement alert mechanisms for potential malicious activities.

3. Continuous Security Process:

Change: Greater emphasis on security as a continuous process.

Implication: organisations must integrate security measures seamlessly into their ongoing operations, with assigned roles and responsibilities.

4. Reporting Enhancements:

Change: Introduction of new reporting options for assessors, highlighting areas of improvement for increased transparency.

Implication: Improved visibility into compliance status and areas for enhancement in assessment reports.

5. Flexibility in Meeting Security Objectives:

Change: Increased flexibility for organisations using different methods to achieve security objectives.

Implication: Customised approaches are allowed, particularly beneficial for longstanding organisations with embedded risk management frameworks.

6. Validation Method and Procedure Enhancements:

Change: Enhanced alignment between information reported in various compliance documents.

Implication: More comprehensive validation processes to ensure consistency across compliance reports.

Change: More frequent primary account number data discovery tasks.

Implication: organisations need to be more proactive in discovering and addressing vulnerabilities related to primary account numbers.

Change: Mandated Approved Scanning Vendor scans for e-commerce platforms.

Implication: organisations must align with new scanning requirements for increased security measures.

Change: Emphasis on automated mechanisms and technology solutions.

Implication: Increased automation requirements to reduce human error, particularly in daily log checks.

7. Roles and Responsibilities:

Change: Assigning and aligning specific roles for governance within organisations to enhance accountability.

Implication: Clear delineation of roles to ensure accountability for data security, impacting both internal and external roles.

8. Recommended Actions:

Change: Urgency in transitioning to PCI DSS v4.0 and developing a roadmap for implementation.

Implication: organisations need to plan and execute the transition promptly, considering current status and preparing for the implementation of required controls.

9. Additional Factors to Keep in Mind:

Change: Consideration of PCI DSS v4.0 in all technical decisions and due diligence with suppliers.

Implication: organisations need to align with v4.0 standards in technical decisions, inquire about suppliers’ compliance, and thoroughly research new solutions to avoid vulnerabilities.

Is PCI Compliance Necessary in the UK?

All UK merchants and service providers processing, transmitting, or storing payment card data must be PCI DSS compliant. Whether you’re a merchant accepting card payments or a service provider handling cardholder data on behalf of others, compliance is a must.

Do I Need PCI Compliance if I Use a Payment Provider like Stripe or Opayo?

Yes! Even with a payment service provider, PCI compliance is a shared responsibility. While using such services may ease compliance efforts, it doesn’t eliminate the need to adhere to PCI DSS requirements.

What Are the Consequences of Not Being PCI Compliant?

The primary consequence is the risk of not protecting cardholder data, potentially leading to a costly breach. Financial penalties, identity theft, and damage to your organisation’s reputation are among the severe consequences. Non-compliance can also result in fines, increased transaction charges, and the withdrawal of card payment facilities by your bank.

How Much Could I Be Fined if I’m Not PCI Compliant?

Fines can range from increased fees to withdrawal of payment card acceptance facilities. In the worst cases – like if you experience a breach – fines can amount to tens of thousands of pounds, depending on the severity and data stolen.

What Are the PCI Compliance Levels?

There are four levels based on the number of transactions processed annually, ranging from Level 1 for over 6 million transactions to Level 4 for fewer than 20,000 transactions.

What is a PCI QSA (Qualified Security Assessor)?

Qualified Security Assessors are independent organisations qualified by the PCI Council to validate an organisation’s compliance with PCI DSS. They play a crucial role in ensuring adherence to security standards.

How Much Does It Cost to Achieve PCI Compliance?

The cost varies based on factors like transaction volume, payment methods, and the scope of work needed. Engaging with a qualified PCI QSA company, like Securious, can help streamline the process efficiently, so get in touch if you want to better understand how to achieve PCI compliance.

How Can Securious Help with PCI Compliance?

Securious, a PCI QSA company since 2016, offers qualified and experienced PCI QSA consultancy. Our approach involves assessing your situation, conducting a gap analysis, advising on remediation, and completing assessments and reports to ensure compliance.

If you require assistance with PCI compliance, contact us using the contact form below. We are based in Exeter but provide PCI QSA services nationally and internationally.