PCI DSS V4.0 – the key things you need to know now

We ran a webinar recently about PCI DSS V4.0 in which we discussed some of the key changes to the standard and what they mean for organisations that have to be PCI compliant. We had some great feedback from the attendees so wanted to share some of the key insights in this article…

When is PCI changing?

It’s complicated… There is a transition period from March 2022-2024, meaning v3.2.1 will remain active for two years after  PCI DSS V4.0 is published. This provides organisations with time to become familiar with the new version, and plan for and implement the changes needed (see below for a graphic illustrating the timeline).

And to give you some idea of the scale of these changes, there were 3 x Request For Changes on the DRAFT, and ver 6,000 items of feedback were processed with over 200 companies providing feedback.

PCI DSS V4.0 implementation timeline

Why is PCI changing?

This is the biggest change since v3.2.1, which was in 2018. I believe it’s well overdue and see this as a huge step forwards for the standard.?

The PCI Council‘s goals with the introduction of PCI DSS V4.0 were:

  • To continue to meet the security needs of the payment industry (which is fundamental to the protection of cardholder data)
  • To promote security as a continuous process (which is key to maintaining cardholder data security as well as best practice)
  • To increase flexibility for organisations using different methods to achieve security objectives
  • To enhance validation methods and procedures

What are the changes and what do they mean?

A lot is changing with PCI DSS V4.0 so we won’t be able to cover everything now, but here are some of the most important changes…

Continuing to meet the security needs of the payment industry

This is important because security practices must evolve as threats change.

  • Expanded multi-factor authentication requirements
    • All users and not just admins require MFA to access CDE
  • Updated password requirements
    • Longer complex passwords are required (Minimum 12, if system doesn’t support 12, then 8) (as well as service accounts password changes) Promotion of the use of password vaults
  • New e-commerce and phishing requirements to address ongoing threats
    • Alerting and anti-tampering technology will need to be implemented. Pages that provide payment services through iFrame, Redirect, etc will need an alerting mechanism to alert to malicious activity on these pages

Promoting security as a continuous process

This is important because criminals never sleep. Ongoing security is crucial to protect payment data.

  • Clearly assigned roles and responsibilities for each requirement
    • Acceptance and understanding of the role and responsibilities for each requirement – You may have to implement a RACI (Responsible, Accountable, Consulted, Informed) matrix for example – You would not have a CFO responsible for data centre security for example.
  • Added guidance to help people better understand how to implement and maintain security
    • Purpose, Good Practice and definitions improved throughout the new standard.
  • New reporting option to highlight areas for improvement and provide more transparency for report reviewers
    • A lot more ‘front loaded’ detailed scope, segmentation, diagrams, and QSA now signs the RoC. There is going to be a lot more interaction with Acquirers, payment brands and banks.

Increasing flexibility for organisations using different methods to achieve security objectives

Increased flexibility allows more options to achieve a requirement’s objective and supports payment technology innovation.

  • Allowance of group, shared and generic accounts
    • Can be used under exceptional circumstances, business justification and authorised by management. Applicable to certain POS systems for example.
  • Targeted risk analysis empowerment for organisations to establish frequencies for performing certain activities
    • Can include a number of requirements under a Defined approach to meet the entities risk analysis of the control.
  • Customised approach, a new method to implement and validate PCI DSS requirements, provides another option for organisations using innovative methods to achieve security objectives
    • Intended for entities that decide to meet PCI DSS requirements that do not specifically meet the defined requirement. Allows organisation to take a strategic approach to meet the objective that is unique for that organisation – only applicable to well established organisations.

Enhancing validation methods and procedures

Clear validation and reporting options support transparency and granularity.

  • Increased alignment between information reported in a RoC or SAQ and information summarised in the AoC
    • Gives the receiving party a clear and more informed understanding of the PCI compliance status for the entity.
  • And there are many more, like more frequent PAN data discovery tasks, ASV scans mandated for E-commerce platforms, and broader applicability for encrypted cardholder data and trusted networks
  • Logging and Monitoring
    • Automated mechanisms are to be used to perform audit log reviews. We are moving away from physical log reviews where errors can be present, and the move to an automated solution removes the risk of oversight and missed alerts.

So what should you do to get ready for PCI DSS V4.0?

  • Start sooner rather than later
  • Look at the new standard and how these changes will affect you
  • Assess where you are now
  • Create a roadmap with organisational goals
  • Feed the changes into any technical decisions you’ll be making over the next year or two – start asking questions around PCI V4.0

How Securious can help with PCI DSS V4.0 compliance

PCI DSS V4.0 Transition Audit & Plan

We’ll take the uncertainty away by giving you a bespoke plan to ensure you are prepared for V4.0 and ready to implement it in a way that aligns with your wider business objectives.

Our team of PCI QSAs will:

  • Conduct a review of your existing PCI DSS scope and systems
  • Produce a gap analysis report
  • Detail areas where work will be required
  • Develop a prioritised roadmap and timing plan
  • Alert you to any additional considerations, including SIEM and other tooling

Find out more about our Transition Audit & Plan here.

Final thoughts

A lot is changing with PCI DSS V4.0 and there’s plenty to do – but there is enough time to get there… We recommend acting soon and learning about the new standard as soon as possible. As always, get in touch if Securious can help you.

Check out our PCI V4.0 resources page for more articles like this.