Payment card data breaches remain one of the costliest categories of security incidents for merchants and service providers of every size. The Payment Card Industry Data Security Standard (PCI DSS) has spent more than a decade evolving to keep pace with new attack methods, and the current version, PCI DSS 4.0, represents the largest overhaul since the standard's creation. Businesses that earned certification under the prior version, PCI DSS 3.2.1, cannot assume that certification still reflects current requirements.
This article summarizes the substantive changes introduced in PCI DSS 4.0 and its refinement, version 4.0.1. It also identifies the specific control updates that organizations already familiar with the older standard need to address now that the transition period has closed. PCI DSS 4.0 is not a light refresh. It rewrites authentication rules, adds new e-commerce protections, and introduces a different approach to demonstrating compliance. Organizations still operating under 3.2.1 assumptions are likely out of alignment with what an assessor now expects to see.
What Is PCI DSS 4.0 and Why Did the Standard Change?
PCI DSS 4.0 is the current major version of the payment card data security standard maintained by the Payment Card Industry Security Standards Council (PCI SSC). It marks the first major update to the standard in over a decade, replacing a framework that had not kept pace with modern authentication threats, cloud infrastructure, and e-commerce skimming attacks. The Council designed the update to address flexibility gaps, close authentication loopholes, and formalize risk-based decision making rather than relying purely on fixed, one-size-fits-all controls.
The standard now exists in an updated form called PCI DSS 4.0.1. The PCI Security Standards Council published this limited revision to correct formatting and typographical errors and to clarify the focus and intent of some requirements, without adding or deleting any requirements. Version 4.0.1 is the version currently supported. The Council retired PCI DSS 4.0 on 31 December 2024, after which 4.0.1 became the only active version of the standard.
Timeline: How the Standard Reached Its Latest Version
Understanding the rollout schedule matters for any organization evaluating its current compliance posture. The PCI Security Standards Council officially retired PCI DSS 3.2.1 as of 31 March 2024. From that point forward, new assessments had to reference the 4.0 framework instead of the older standard.
The Council did not require full compliance with every new control immediately. Version 4.0 introduced 64 new requirements. Of those, 51 were future-dated and became effective on 31 March 2025. The remaining requirements applied immediately upon the March 2024 retirement of the older standard. That phased approach gave merchants roughly two years of runway, but the runway has run out. The Council confirmed this deadline as final, and no extension followed. Every requirement in the standard is now enforceable during assessments.
The Biggest Compliance Changes Under PCI DSS 4.0
Several categories of change carry the most practical weight for organizations updating their programs. The most significant updates include:
- Stronger password requirements. Requirement 8.3.6 raises the minimum password length from 7 to 12 alphanumeric characters. This requirement became mandatory on 31 March 2025.
- Broader Multi-Factor Authentication (MFA) coverage. The prior standard limited mandatory MFA to narrower scenarios. Under PCI DSS 3.2.1, MFA was required only for remote access from outside the network and for administrative access to system components within the cardholder data environment. Non-administrative local users were exempt. Version 4.0 closes that gap and extends authentication requirements to a wider range of account types accessing sensitive systems.
- New e-commerce anti-skimming controls. Requirements 6.4.3 and 11.6.1 were added to reduce the risk of e-skimming attacks during e-commerce transactions. These requirements focus on ensuring that payment page scripts are authorized, checked for integrity, and monitored for tampering.
- Mandatory environment scoping. A documented scoping exercise covering the cardholder data environment moved from discussion guidance into a formal, trackable requirement. This took effect immediately under version 4.0, and service providers face a stricter future-dated cadence for repeating that exercise.
- Tighter encryption standards for stored account data. Full-disk or partition-level encryption alone no longer satisfies the requirement to render stored cardholder data unreadable, except on removable media. File-level, column-level, or field-level encryption is now expected for data at rest in most environments.
Each of these changes reflects threat patterns the Council observed since the prior standard was written, including credential stuffing, e-commerce script tampering, and weak encryption implementations on stored data.
What Businesses Already Compliant Under the Old Standard Need to Update
Organizations holding a certification issued under PCI DSS 3.2.1 need a structured gap review rather than a simple checklist comparison. The password and authentication changes alone typically require coordination between security teams and application owners. Legacy systems built around seven-character password fields may need code-level changes to support the new twelve-character minimum. Authentication workflows built around narrow MFA triggers need reconfiguration to cover the expanded population of users now in scope.
E-commerce operations carry a separate burden. Requirements 6.4.3 and 11.6.1 demand an inventory of every script running on payment pages, along with a mechanism to detect unauthorized changes. Organizations relying entirely on third-party payment page hosting still need to confirm, in writing, how that hosting arrangement satisfies these obligations. Environment scoping documentation also needs a formal annual review cycle, rather than the informal scoping narrative many organizations previously included in assessment paperwork.
Finally, any organization still storing cardholder data using only disk-level encryption needs to migrate toward field-level or column-level encryption methods. Disk-level encryption alone no longer meets the requirement outside of removable media use cases.
The Customized Approach and Targeted Risk Analysis
PCI DSS 4.0 introduced two structural concepts that did not exist under the prior standard: the Customized Approach and Targeted Risk Analysis. The Customized Approach gives organizations an alternative to the traditional Defined Approach. It allows implementation of alternative controls that achieve the same security objective as a stated requirement, provided the alternative is documented, tested, and validated by a Qualified Security Assessor. This replaces the older concept of compensating controls with a more structured validation process.
Risk assessment under the new standard takes the form of one or more narrowly focused targeted risk analyses. These analyses replace the organization-wide risk assessments required under the prior version and are designed to guide informed, risk-based decisions where the standard allows flexibility. A targeted risk analysis is required in two distinct situations: to justify how frequently a discretionary control runs, and to demonstrate that a customized control achieves equivalent protection to the standard's defined requirement. Organizations considering the Customized Approach should weigh the added documentation burden against the operational flexibility it provides. Assessors expect a complete controls matrix and supporting analysis before granting credit for any customized control.
Is PCI DSS 4.0 Fully in Effect Now?
Yes. Every requirement introduced under PCI DSS 4.0, including the requirements that carried a future-dated grace period, became mandatory as of 31 March 2025. Assessments conducted after that date score the full requirement set, including the password length increase, expanded authentication rules, e-commerce script monitoring, and mandatory scoping documentation. Organizations that validated compliance in 2024 while treating future-dated items as optional face a materially different set of expectations at the next assessment cycle.
Moving Forward with PCI DSS 4.0
PCI DSS 4.0 changes the baseline for what payment card security looks like, and the transition period that once softened the deadline has closed. Businesses still operating on assumptions carried over from the 3.2.1 era face real exposure at their next assessment, particularly around authentication, e-commerce script monitoring, and encryption of stored account data. Closing those gaps requires a structured review against the current requirement set, not a quick patch.
Planet 9 is a Bay Area cybersecurity consulting firm specializing in PCI DSS readiness for SMBs in retail, e-commerce, and payments. Our vCISOs and compliance managers help organizations choose the right approach, configure GRC tools if needed, and get audit-ready without wasted time.





