PCI DSS v4.0.1: what you need to know
The PCI Security Standards Council (PCI SSC) has officially released PCI DSS version 4.0.1, an update to the Payment Card Industry Data Security Standard (PCI DSS). This revision, published on June 11, 2024, aims to address feedback and clarify existing requirements without introducing new ones or eliminating current ones.
Key updates in PCI DSS v4.0.1
The update primarily focuses on correcting formatting and typographical errors present in the previous version, PCI DSS v4.0, released in March 2022. Additionally, it provides clarity on several requirements to better define their objectives and applicability.
Significant clarifications
- Requirement 3: Clarified applicability notes for issuers and companies supporting issuing services. Introduced a Customised Approach Objective for organisations using keyed cryptographic hashes to render Primary Account Numbers (PAN) unreadable.
- Requirement 6: Reverted language to PCI DSS v3.2.1 for installing patches/updates within 30 days, applying only to critical vulnerabilities. Clarified applicability for managing payment page scripts.
- Requirement 8: Added notes specifying that multi-factor authentication for all non-administrative access into the Cardholder Data Environment (CDE) does not apply to user accounts authenticated with phishing-resistant factors.
- Requirement 12: Updated notes on the relationships between customers and third-party service providers (TPSPs), providing clearer guidance on maintaining written agreements.
The PCI SSC has announced that PCI DSS v4.0.1 will be effective immediately, with PCI DSS v4.0 scheduled to retire on December 31, 2024.
Organisations currently complying with PCI DSS v4.0 should review the Summary of Changes from v4.0 to v4.0.1 available in the PCI SSC Document Library. This document provides detailed information on the updates and will help you understand and implement the necessary changes.
For further information, visit the PCI Security Standards Council website.
Free online PCI DSS v4.0 Readiness Assessment
We have created a free, online assessment that will show you how ready you are for PCI DSS V4.0 – and what you need to do.
Answer 15 high-level questions about your environment and we’ll give you a personalised report with feedback* tailored to your specific needs.
It takes just a few minutes, it’s completely free and you’ll receive your personalised report instantly.