PCI DSS v4.0: what’s changing and what you need to do

PCI DSS v4.0

If you’ve been hearing about PCI DSS v4.0 and wondering what it means for you, this overview sets out the main changes that are coming, when they kick in, what you need to do and how you can find out more if needed.

What is PCI DSS v4.0?

PCI DSS v4.0 is the latest update to the Payment Card Industry Data Security Standard, the global standard required of any organisation handling card payments.

It is important and represents the biggest set of changes to PCI DSS since version 3.2.1, which the PCI Council released in 2018.

Why is the PCI SSC introducing PCI DSS v4.0?

In the words of the PCI Standards Security Council, PCI DSS v4.0 is being introduced “to address emerging threats and technologies and enable innovative methods to combat new threats.” 

The changes come after the PCI Council obtained over 6,000 items of feedback from more than 200 organisations involved in the global payments industry. 

How is PCI DSS v4.0 different from v3.2.1?

According to the PCI Council, updates to the standard focus on “meeting the evolving security needs of the payments industry, promoting security as a continuous process, increasing flexibility for organisations using different methods to achieve security objectives, and enhancing validation methods and procedures.”

You can see full details of the updates in the Summary of Changes document on the PCI SSC website.

What actually is changing?

Examples of the changes given by the PCI Council include:

  • Updated firewall terminology to network security controls to support a broader range of technologies used to meet the security objectives traditionally met by firewalls.
  • Expansion of Requirement 8 to implement multi-factor authentication (MFA) for all access into the cardholder data environment.
  • Increased flexibility for organisations to demonstrate how they are using different methods to achieve security objectives.
  • Addition of targeted risk analyses to allow entities the flexibility to define how frequently they perform certain activities, as best suited for their business needs and risk exposure.

When does it come into effect?

Although PCI DSS v4.0 was published by the PCI Council on 31st March 2022, PCI DSS v3.2.1 will remain active for two years in order to provide organisations time to become familiar with the new version, and plan for and implement the changes needed.

As of March 31, 2024, the PCI Council will retire PCI DSS v3.2.1, and PCI DSS v4.0 will be the only active version of the standard. 

Assessors will be able to undertake assessments using either PCI DSS v4.0 or PCI DSS v3.2.1, subject to having completed PCI DSS v4.0 training. In addition, the updated standard gives organisations more time to implement numerous new requirements.

This is the latest version of the timeline, from the PCI Council:

So what do I need to do about PCI DSS v4.0?

If you handle payment card data, either as a merchant or processor, you need to be PCI DSS compliant. That requirement is unchanged (see our Ultimate Guide to PCI Compliance for more details). And for the next two years, until March 2024, you effectively have the option to be compliant with either v3.2.1, as you will be now, or transition to v4.0. 

Which route to go down will depend on a number of factors such as your desire to meet the latest standards and ‘future-proof’ your compliance, or a preference to stick with the existing version while aligning with the new requirements in a planned manner over the next two years.

Every situation is different. Our recommendation is to contact us (or your chosen PCI DSS QSA Company) and talk through the pros and cons of each approach in order to reach a decision that’s right for you. 

For guidance on what’s best for you…

You can read more about PCI DSS in our Ultimate Guide to PCI DSS by clicking here, or talk to one of our Exeter-based PCI QSAs by emailing pci@securious.co.uk. Find out more about achieving PCI DSS compliance with Securious here.

Check out our PCI V4.0 resources page for more articles like this.