Skip to main content
  • For Support:

    815-308-2095

  • New Client
    815-788-6041

PCI DSS 4.0: What Changed, and What Your Business Must Do Now

July 14, 2026

If your business handles payment cards, understanding the PCI DSS 4.0 changes is no longer a future planning exercise. The future-dated requirements introduced with this major update became mandatory on March 31, 2025. The current version of the standard is PCI DSS 4.0.1. If your controls are not updated to meet the new standard, your business is out of compliance right now.

PCI DSS 4.0’s future-dated requirements became mandatory on March 31, 2025. If your controls are not updated, your business is out of compliance right now.

PCI DSS stands for Payment Card Industry Data Security Standard. It is a set of security requirements created and maintained by the PCI Security Standards Council. The major card brands — Visa, Mastercard, American Express, Discover, and JCB — founded this council to protect cardholder data. The standard applies to any business that accepts, processes, stores, or transmits payment card data. Size and transaction volume do not matter.

This guide explains what PCI DSS 4.0 is, what actually changed between versions, and how Chicagoland businesses can close their security gaps. The transition is the most significant update to payment security in years. It shifts the focus from an annual compliance checklist to continuous, proactive security.

Key Takeaways

  • The current active version is PCI DSS 4.0.1. It added clarifications to 4.0 without changing the core security obligations.
  • The biggest changes include broader multi-factor authentication, stricter passwords, and new e-commerce payment page protections. They also add targeted risk analysis, deeper penetration testing, and the customized approach option.
  • PCI compliance is not a US government law. It is a contractual obligation enforced by the card brands through your acquiring bank or payment processor.
  • Not sure where you stand? LeadingIT’s free 2-minute PCI self-check, further down this page, shows your risk level and exact gaps with no sign-up required.

PCI DSS 4.0 vs 4.0.1: Is There a Difference?

If you searched for PCI DSS 4.0.1 compliance and landed here, here is the short answer: no new security requirements exist in 4.0.1. The PCI Security Standards Council released version 4.0.1 to add clarifications and correct formatting issues in the original 4.0 document.

Every security obligation you must meet comes from PCI DSS 4.0. But when validating your compliance today, you must use the version 4.0.1 forms and documentation. Do not use the older 4.0 versions of the forms.

Bottom line: the rules did not change between 4.0 and 4.0.1. Only the paperwork clarity improved. If you hear “PCI DSS 4.0” and “PCI DSS 4.0.1” used interchangeably, that is why.

The Major PCI DSS 4.0 Changes in Plain English

The transition from the old standard brought dozens of new rules. The PCI DSS 3.2 vs 4.0 differences introduce 64 new requirements designed to combat modern cyber threats. Here are the core changes your business needs to implement.

AreaOld (3.2.1) ApproachNew (4.0) Requirement
Multi-Factor AuthenticationRequired primarily for remote access into the networkRequired for all access into the cardholder data environment (CDE)
Passwords and AuthenticationShorter minimum length and looser complexity rulesLonger minimum password length, stronger complexity rules, and blocking known weak or compromised passwords
E-commerce and Payment Page Security(New in 4.0)Must manage all payment page scripts and monitor for unauthorized changes to HTTP headers and the payment page
Compliance TimelinesRigid, fixed timelines for every taskTargeted risk analysis lets you set the frequency of certain security activities based on your own risk profile
Penetration TestingLess rigorous testing of network segmentation and overall security postureMust prove segmentation actually isolates the CDE, plus targeted penetration testing if using the customized approach
Approach to RequirementsOnly the defined (traditional) approachChoice of the defined approach or the new customized approach for mature organizations

Expanded Multi-Factor Authentication

The cardholder data environment (CDE) is the set of systems, people, and processes that store, process, or transmit cardholder data. It also includes any system connected to those systems. Anyone accessing the CDE must now prove their identity with more than just a password.

Stricter Passwords and Authentication

Longer minimum passwords and stronger complexity rules are now required. You must also regularly review access privileges so employees only have the access their job requires.

E-commerce and Payment Page Security

For businesses taking payments online, the standard adds strict rules to prevent skimming attacks. Malicious actors frequently target payment pages to steal card data as customers type it in.

Targeted Risk Analysis

The targeted risk analysis requirement applies only to certain controls, not everything. For example, a requirement may say you must inspect point-of-sale devices periodically. A targeted risk analysis helps you document and justify exactly how many days or weeks that timeframe means for your specific store.

Updated Penetration Testing

The PCI DSS 4.0 penetration testing rules require deeper testing of your security posture than in previous versions. You must prove that segmentation actually isolates the CDE from the rest of your network.

The Customized Approach Versus the Defined Approach

The defined approach is the traditional method: you follow the exact steps written in the standard. The customized approach gives mature organizations flexibility. It lets businesses use alternative security controls if they meet the specific objective of the requirement. Most small businesses will stick to the defined approach. But the customized option provides flexibility for complex IT environments.

The 12 Requirements Under the New Standard

The core framework of the standard still relies on twelve foundational rules. You can read more about the 12 requirements explained in our detailed breakdown. Under version 4.0, these goals remain the same, but the specific testing and validation steps have grown more rigorous.

  1. Install and maintain network security controls and firewalls.
  2. Apply secure configurations and never keep vendor defaults.
  3. Protect stored account data.
  4. Protect cardholder data with strong cryptography in transit over open public networks.
  5. Protect systems against malware.
  6. Develop and maintain secure systems and software through regular patching.
  7. Restrict access by business need-to-know.
  8. Identify users and authenticate access with unique IDs.
  9. Restrict physical access to cardholder data.
  10. Log and monitor all access.
  11. Test security regularly.
  12. Maintain an information security policy and program.

The Retirement of Version 3.2.1

The standard’s timeline breaks into four milestones:

DateMilestone
March 31, 2024PCI DSS 3.2.1 officially retired; businesses could only validate against PCI DSS 4.0
2024 to 2025Grace period for the most complex future-dated requirements
March 31, 2025Future-dated requirements became fully mandatory
CurrentPCI DSS 4.0.1 is the active version

The grace period gave organizations extra time to implement the most complex new controls. It was not a delay on the whole standard.

PCI DSS 4.0.1 superseded 4.0 to provide clarifications and correct formatting issues. The core security obligations did not change between 4.0 and 4.0.1. But you must use the 4.0.1 documentation and forms when validating your compliance today.

What Your Business Must Do Now

The PCI DSS 4.0 deadline has passed. If your business accepts, processes, stores, or transmits payment card data, you must comply with the new rules immediately.

PCI compliance is not a government law in the US. it is a contractual obligation enforced by the card brands through your acquiring bank or payment processor.

If you are behind, close the gap in this order:

conduct gap assessment, identify and protect data, complete correct SAQ, confirm merchant level, PCI DSS 4.0 Compliance Readiness Workflow

Conduct a Gap Assessment

Compare your current security controls against the new PCI DSS 4.0 requirements. Identify where your network segmentation, multi-factor authentication, and logging fall short. Network segmentation can shrink your cardholder data environment. A smaller CDE means less of your systems must meet the standard.

Protect the Right Data

When assessing your compliance, you must know exactly what data you are protecting.

Data TypeIncludesStorage Rule
Cardholder DataPrimary account number (PAN), cardholder name, expiration date, service codeMay be stored only if rendered unreadable through encryption, tokenization, truncation, or hashing
Sensitive Authentication DataCVV or CVC security code, full magnetic-stripe or track data, PINsNever store after authorization, even if encrypted

If your systems retain sensitive authentication data after authorization, you are immediately out of compliance.

Complete the Right Self-Assessment Questionnaire

Most small and mid-size businesses validate compliance annually with a Self-Assessment Questionnaire (SAQ). Which form applies depends on how you take payments. You must use the updated version 4.0.1 form.

ASV scanning requirement: Most SAQ types also require quarterly external vulnerability scans by an Approved Scanning Vendor (ASV). This is a separate obligation from the SAQ itself. Ask your acquiring bank or processor whether quarterly ASV scans apply to your merchant profile.

SAQ TypeApplies To
SAQ ACard-not-present transactions where payment processing is fully outsourced to a validated third party
SAQ A-EPE-commerce sites whose website affects the security of the payment page
SAQ BImprint machines or standalone dial-out terminals with no electronic storage
SAQ B-IPStandalone IP-connected terminals
SAQ CPayment application systems connected to the internet
SAQ C-VTManual entry via a virtual terminal
SAQ P2PEValidated point-to-point encryption solutions
SAQ DEveryone else, including service providers (the longest form)

Understand Your Merchant Level

The card brands tier merchants by annual transaction volume to determine how they must validate compliance. Under the commonly used Visa and Mastercard tiering:

Merchant LevelTransaction VolumeValidation Required
Level 1Over 6 million transactions per yearOn-site assessment by a Qualified Security Assessor (QSA), producing a Report on Compliance (ROC)
Level 21 to 6 million transactions
Level 320,000 to 1 million e-commerce transactions
Level 4Fewer than 20,000 e-commerce transactions, or up to 1 million total transactions across all channelsSAQ (most small businesses fall into this level)

Understand the Enforcement Mechanics

Consequences of non-compliance flow through your processor. Here is how the severity escalates:

Escalation LevelTriggerConsequence
1Ongoing non-complianceMonthly non-compliance fees on your merchant account
2Card-data breachForensic investigation
3Card-data breachCard-brand assessments passed through the acquirer
4Card-data breachCard reissuance costs
5Card-data breachHigher processing rates
6Card-data breachPotential loss of the ability to accept cards at all

See Where You Stand

Take our free 2-minute PCI self-check: answer 8 plain-English questions to see your risk level and the exact gaps to fix, with no sign-up required to see your result. free 2-minute PCI DSS self-assessment

Frequently Asked Questions

What’s the latest version of PCI DSS?

The current version of the standard is PCI DSS 4.0.1. It superseded version 4.0 to add minor clarifications and corrections. Version 3.2.1 was officially retired on March 31, 2024.

What is the difference between PCI DSS 4.0 and 3?

Version 4.0 introduces stricter authentication rules, expanded multi-factor authentication, and new protections for e-commerce payment pages. It also shifts from rigid timelines to targeted risk analyses, allowing businesses to set control frequencies based on their unique risk profiles.

Is PCI DSS 4.0 still valid?

Yes, version 4.0 and its minor update 4.0.1 constitute the active and mandatory standard. The future-dated requirements introduced in this version became fully mandatory on March 31, 2025.

How to achieve PCI DSS 4.0 compliance?

You achieve compliance by implementing the required security controls for your cardholder data environment and validating them annually. Most small businesses validate by completing the appropriate Self-Assessment Questionnaire. Some merchant profiles also require quarterly external vulnerability scans by an Approved Scanning Vendor.

Is it mandatory to be PCI compliant?

PCI compliance is mandatory for any business that accepts, processes, stores, or transmits payment card data. While it is not a government law in the US, it is a strict contractual obligation enforced by the major card brands through your merchant agreement.

Get Help With Your PCI Compliance

LeadingIT helps you become and stay compliant with the updated payment security standards. We are a Chicagoland managed it and cybersecurity provider that has helped Illinois businesses since 2010. We serve roughly 200 organizations and over 2,500 users from offices in Woodstock and Manteno.

We operate the technical half of PCI compliance as part of managed IT. Our team handles your network segmentation, multi-factor authentication, patching, logging, and scan remediation. We also help clients complete their annual questionnaire correctly. LeadingIT is NOT a QSA or ASV and does not certify PCI compliance.

Explore LeadingIT’s PCI compliance services (done-for-you path) to see how we manage the technical heavy lifting. You can contact us or use our book a call to speak with our team today at 815-788-6041.


Stephen Taylor is the founder and driving force behind LeadingIT, a Chicagoland-based IT and cloud services company, where he focuses on delivering practical, client-first technology solutions for businesses. A Microsoft Certified professional and author of Technology Should Just Work, he combines hands-on expertise with a passion for making IT simple, transparent, and effective. Read more about the author.

Let Us Be Your Guide In Cybersecurity Protections
And IT Support With Our All-Inclusive Model.