PCI DSS 4.0: What Changed, and What Your Business Must Do Now

If your business handles payment cards, understanding the PCI DSS 4.0 changes is no longer a future planning exercise. The future-dated requirements introduced with this major update became mandatory on March 31, 2025. The current version of the standard is PCI DSS 4.0.1. If your controls are not updated to meet the new standard, your business is out of compliance right now.
PCI DSS 4.0’s future-dated requirements became mandatory on March 31, 2025. If your controls are not updated, your business is out of compliance right now.
PCI DSS stands for Payment Card Industry Data Security Standard. It is a set of security requirements created and maintained by the PCI Security Standards Council. The major card brands — Visa, Mastercard, American Express, Discover, and JCB — founded this council to protect cardholder data. The standard applies to any business that accepts, processes, stores, or transmits payment card data. Size and transaction volume do not matter.
This guide explains what PCI DSS 4.0 is, what actually changed between versions, and how Chicagoland businesses can close their security gaps. The transition is the most significant update to payment security in years. It shifts the focus from an annual compliance checklist to continuous, proactive security.
Key Takeaways
- The current active version is PCI DSS 4.0.1. It added clarifications to 4.0 without changing the core security obligations.
- The biggest changes include broader multi-factor authentication, stricter passwords, and new e-commerce payment page protections. They also add targeted risk analysis, deeper penetration testing, and the customized approach option.
- PCI compliance is not a US government law. It is a contractual obligation enforced by the card brands through your acquiring bank or payment processor.
- Not sure where you stand? LeadingIT’s free 2-minute PCI self-check, further down this page, shows your risk level and exact gaps with no sign-up required.
PCI DSS 4.0 vs 4.0.1: Is There a Difference?
If you searched for PCI DSS 4.0.1 compliance and landed here, here is the short answer: no new security requirements exist in 4.0.1. The PCI Security Standards Council released version 4.0.1 to add clarifications and correct formatting issues in the original 4.0 document.
Every security obligation you must meet comes from PCI DSS 4.0. But when validating your compliance today, you must use the version 4.0.1 forms and documentation. Do not use the older 4.0 versions of the forms.
Bottom line: the rules did not change between 4.0 and 4.0.1. Only the paperwork clarity improved. If you hear “PCI DSS 4.0” and “PCI DSS 4.0.1” used interchangeably, that is why.
The Major PCI DSS 4.0 Changes in Plain English
The transition from the old standard brought dozens of new rules. The PCI DSS 3.2 vs 4.0 differences introduce 64 new requirements designed to combat modern cyber threats. Here are the core changes your business needs to implement.
| Area | Old (3.2.1) Approach | New (4.0) Requirement |
|---|---|---|
| Multi-Factor Authentication | Required primarily for remote access into the network | Required for all access into the cardholder data environment (CDE) |
| Passwords and Authentication | Shorter minimum length and looser complexity rules | Longer minimum password length, stronger complexity rules, and blocking known weak or compromised passwords |
| E-commerce and Payment Page Security | (New in 4.0) | Must manage all payment page scripts and monitor for unauthorized changes to HTTP headers and the payment page |
| Compliance Timelines | Rigid, fixed timelines for every task | Targeted risk analysis lets you set the frequency of certain security activities based on your own risk profile |
| Penetration Testing | Less rigorous testing of network segmentation and overall security posture | Must prove segmentation actually isolates the CDE, plus targeted penetration testing if using the customized approach |
| Approach to Requirements | Only the defined (traditional) approach | Choice of the defined approach or the new customized approach for mature organizations |
Expanded Multi-Factor Authentication
The cardholder data environment (CDE) is the set of systems, people, and processes that store, process, or transmit cardholder data. It also includes any system connected to those systems. Anyone accessing the CDE must now prove their identity with more than just a password.
Stricter Passwords and Authentication
Longer minimum passwords and stronger complexity rules are now required. You must also regularly review access privileges so employees only have the access their job requires.
E-commerce and Payment Page Security
For businesses taking payments online, the standard adds strict rules to prevent skimming attacks. Malicious actors frequently target payment pages to steal card data as customers type it in.
Targeted Risk Analysis
The targeted risk analysis requirement applies only to certain controls, not everything. For example, a requirement may say you must inspect point-of-sale devices periodically. A targeted risk analysis helps you document and justify exactly how many days or weeks that timeframe means for your specific store.
Updated Penetration Testing
The PCI DSS 4.0 penetration testing rules require deeper testing of your security posture than in previous versions. You must prove that segmentation actually isolates the CDE from the rest of your network.
The Customized Approach Versus the Defined Approach
The defined approach is the traditional method: you follow the exact steps written in the standard. The customized approach gives mature organizations flexibility. It lets businesses use alternative security controls if they meet the specific objective of the requirement. Most small businesses will stick to the defined approach. But the customized option provides flexibility for complex IT environments.
The 12 Requirements Under the New Standard
The core framework of the standard still relies on twelve foundational rules. You can read more about the 12 requirements explained in our detailed breakdown. Under version 4.0, these goals remain the same, but the specific testing and validation steps have grown more rigorous.
- Install and maintain network security controls and firewalls.
- Apply secure configurations and never keep vendor defaults.
- Protect stored account data.
- Protect cardholder data with strong cryptography in transit over open public networks.
- Protect systems against malware.
- Develop and maintain secure systems and software through regular patching.
- Restrict access by business need-to-know.
- Identify users and authenticate access with unique IDs.
- Restrict physical access to cardholder data.
- Log and monitor all access.
- Test security regularly.
- Maintain an information security policy and program.
The Retirement of Version 3.2.1
The standard’s timeline breaks into four milestones:
| Date | Milestone |
|---|---|
| March 31, 2024 | PCI DSS 3.2.1 officially retired; businesses could only validate against PCI DSS 4.0 |
| 2024 to 2025 | Grace period for the most complex future-dated requirements |
| March 31, 2025 | Future-dated requirements became fully mandatory |
| Current | PCI DSS 4.0.1 is the active version |
The grace period gave organizations extra time to implement the most complex new controls. It was not a delay on the whole standard.
PCI DSS 4.0.1 superseded 4.0 to provide clarifications and correct formatting issues. The core security obligations did not change between 4.0 and 4.0.1. But you must use the 4.0.1 documentation and forms when validating your compliance today.
What Your Business Must Do Now
The PCI DSS 4.0 deadline has passed. If your business accepts, processes, stores, or transmits payment card data, you must comply with the new rules immediately.
PCI compliance is not a government law in the US. it is a contractual obligation enforced by the card brands through your acquiring bank or payment processor.
If you are behind, close the gap in this order:

Conduct a Gap Assessment
Compare your current security controls against the new PCI DSS 4.0 requirements. Identify where your network segmentation, multi-factor authentication, and logging fall short. Network segmentation can shrink your cardholder data environment. A smaller CDE means less of your systems must meet the standard.
Protect the Right Data
When assessing your compliance, you must know exactly what data you are protecting.
| Data Type | Includes | Storage Rule |
|---|---|---|
| Cardholder Data | Primary account number (PAN), cardholder name, expiration date, service code | May be stored only if rendered unreadable through encryption, tokenization, truncation, or hashing |
| Sensitive Authentication Data | CVV or CVC security code, full magnetic-stripe or track data, PINs | Never store after authorization, even if encrypted |
If your systems retain sensitive authentication data after authorization, you are immediately out of compliance.
Complete the Right Self-Assessment Questionnaire
Most small and mid-size businesses validate compliance annually with a Self-Assessment Questionnaire (SAQ). Which form applies depends on how you take payments. You must use the updated version 4.0.1 form.
ASV scanning requirement: Most SAQ types also require quarterly external vulnerability scans by an Approved Scanning Vendor (ASV). This is a separate obligation from the SAQ itself. Ask your acquiring bank or processor whether quarterly ASV scans apply to your merchant profile.
| SAQ Type | Applies To |
|---|---|
| SAQ A | Card-not-present transactions where payment processing is fully outsourced to a validated third party |
| SAQ A-EP | E-commerce sites whose website affects the security of the payment page |
| SAQ B | Imprint machines or standalone dial-out terminals with no electronic storage |
| SAQ B-IP | Standalone IP-connected terminals |
| SAQ C | Payment application systems connected to the internet |
| SAQ C-VT | Manual entry via a virtual terminal |
| SAQ P2PE | Validated point-to-point encryption solutions |
| SAQ D | Everyone else, including service providers (the longest form) |
Understand Your Merchant Level
The card brands tier merchants by annual transaction volume to determine how they must validate compliance. Under the commonly used Visa and Mastercard tiering:
| Merchant Level | Transaction Volume | Validation Required |
|---|---|---|
| Level 1 | Over 6 million transactions per year | On-site assessment by a Qualified Security Assessor (QSA), producing a Report on Compliance (ROC) |
| Level 2 | 1 to 6 million transactions | |
| Level 3 | 20,000 to 1 million e-commerce transactions | |
| Level 4 | Fewer than 20,000 e-commerce transactions, or up to 1 million total transactions across all channels | SAQ (most small businesses fall into this level) |
Understand the Enforcement Mechanics
Consequences of non-compliance flow through your processor. Here is how the severity escalates:
| Escalation Level | Trigger | Consequence |
|---|---|---|
| 1 | Ongoing non-compliance | Monthly non-compliance fees on your merchant account |
| 2 | Card-data breach | Forensic investigation |
| 3 | Card-data breach | Card-brand assessments passed through the acquirer |
| 4 | Card-data breach | Card reissuance costs |
| 5 | Card-data breach | Higher processing rates |
| 6 | Card-data breach | Potential loss of the ability to accept cards at all |
See Where You Stand
Take our free 2-minute PCI self-check: answer 8 plain-English questions to see your risk level and the exact gaps to fix, with no sign-up required to see your result. free 2-minute PCI DSS self-assessment
Related Guides
- What Is PCI Compliance? A Plain-English Guide
- The 12 PCI DSS Requirements Explained in Plain English
- Which PCI SAQ Do I Need? A 2-Minute Decision Guide
- PCI Compliance Levels 1-4: Which Merchant Level Are You?
Frequently Asked Questions
What’s the latest version of PCI DSS?
The current version of the standard is PCI DSS 4.0.1. It superseded version 4.0 to add minor clarifications and corrections. Version 3.2.1 was officially retired on March 31, 2024.
What is the difference between PCI DSS 4.0 and 3?
Version 4.0 introduces stricter authentication rules, expanded multi-factor authentication, and new protections for e-commerce payment pages. It also shifts from rigid timelines to targeted risk analyses, allowing businesses to set control frequencies based on their unique risk profiles.
Is PCI DSS 4.0 still valid?
Yes, version 4.0 and its minor update 4.0.1 constitute the active and mandatory standard. The future-dated requirements introduced in this version became fully mandatory on March 31, 2025.
How to achieve PCI DSS 4.0 compliance?
You achieve compliance by implementing the required security controls for your cardholder data environment and validating them annually. Most small businesses validate by completing the appropriate Self-Assessment Questionnaire. Some merchant profiles also require quarterly external vulnerability scans by an Approved Scanning Vendor.
Is it mandatory to be PCI compliant?
PCI compliance is mandatory for any business that accepts, processes, stores, or transmits payment card data. While it is not a government law in the US, it is a strict contractual obligation enforced by the major card brands through your merchant agreement.
Get Help With Your PCI Compliance
LeadingIT helps you become and stay compliant with the updated payment security standards. We are a Chicagoland managed it and cybersecurity provider that has helped Illinois businesses since 2010. We serve roughly 200 organizations and over 2,500 users from offices in Woodstock and Manteno.
We operate the technical half of PCI compliance as part of managed IT. Our team handles your network segmentation, multi-factor authentication, patching, logging, and scan remediation. We also help clients complete their annual questionnaire correctly. LeadingIT is NOT a QSA or ASV and does not certify PCI compliance.
Explore LeadingIT’s PCI compliance services (done-for-you path) to see how we manage the technical heavy lifting. You can contact us or use our book a call to speak with our team today at 815-788-6041.
