Free Consultation
#PCI DSS
#pci
#compliance

PCI DSS Explained: The 12 Requirements and What Changed in Version 4.0

October 1, 2026

Any organization that stores, processes, or transmits payment card data answers to a security standard most owners have heard of but few have read in full. The Payment Card Industry Data Security Standard (PCI DSS) provides a baseline of technical and operational requirements designed to protect account data. This article covers the 12 core requirements at a summary level and flags the version 4.0 changes that now carry real assessment consequences.

The standard matters beyond retail checkout counters. SaaS platforms that bill customers directly, healthcare organizations with patient payment portals, and technology vendors processing card payments on behalf of clients all fall under its scope. Understanding the structure of PCI DSS, and tracking what the 4.0 revision changed, helps a compliance or security team plan remediation work before an assessor finds the gaps first.

What Is PCI DSS?

PCI DSS is a global data security standard maintained by the PCI Security Standards Council. The standard applies to merchants, service providers, and any other entity that handles cardholder data. It defines a common set of controls across network security, access management, monitoring, and governance.

The requirements are organized into 12 principal categories grouped under six broader control objectives: building a secure network, protecting account data, maintaining a vulnerability management program, implementing strong access controls, monitoring and testing networks, and maintaining an information security policy.

What Are the 12 PCI DSS Requirements?

The 12 core requirements of PCI DSS have remained consistent across versions, including the current v4.0.1 release. At a summary level, the requirements break down as follows.

What Is PCI DSS 4.0?

The PCI Security Standards Council announced Version 4.0 of the standard in March 2022. Version 3.2.1 officially retired two years later, making 4.0 the sole active standard from that point forward.

Version 4.0 introduced 64 new or updated requirements, with 51 designated as "future-dated" and 13 effective immediately upon rollout. A limited revision followed soon after: PCI DSS v4.0.1 was published in mid-2024, with no new or deleted requirements, only corrections and clarifications. Version 4.0 itself retired at the end of 2024, so v4.0.1 became the only active version for every assessment conducted from 2025 onward.

Several immediate changes shifted how organizations document compliance. A new requirement, 12.3.2, calls for documenting each customized approach a business uses to meet a control and performing a targeted risk analysis to justify it. Another immediate requirement, 12.5.2, calls for documenting and confirming PCI DSS scope, including the cardholder data environment and everything that stores, processes, or transmits card data, at least once every 12 months.

Which PCI DSS 4.0 Requirements Became Mandatory in 2025?

As of March 31, 2025, every future-dated requirement is mandatory, with no additional grace period. Qualified Security Assessors now evaluate these requirements during every assessment. For a business still treating these items as optional, that window has closed.

Three areas carry the most practical weight for small and mid-sized businesses.

For organizations whose last assessment predated the deadline, 2026 marks the first full calendar year in which every PCI DSS assessment occurs after the cutoff, meaning some of these controls may be tested as mandatory for the first time.

Why PCI DSS 4.0 Compliance Carries More Weight Now

An assessment under the current standard no longer treats the future-dated controls as aspirational. A Qualified Security Assessor reviews them with the same rigor applied to any other requirement. A gap in multi-factor authentication coverage, password strength, or payment page monitoring now produces a documented finding rather than a note for next year. Noncompliance can also trigger escalating fines from card networks, levied through the merchant's acquiring bank, along with exposure to fraud liability if a breach involving card data follows.

For a SaaS company billing customers directly or a healthcare provider running a patient payment portal, the stakes extend past the card brands. A breach touching payment data frequently triggers state breach notification obligations and customer trust damage that outlasts any processor penalty.

How to Prepare for a PCI DSS 4.0.1 Assessment

A practical path toward readiness follows a few consistent steps regardless of company size.

Moving Forward With PCI DSS 4.0.1

PCI DSS was never a one-time checklist, and the 4.0.1 revision makes that clear. The 12 requirements still provide the structural map, but the controls once labeled as future best practices now carry full assessment weight. Businesses handling card data gain the most by treating compliance as a continuous program rather than an annual scramble, and by closing gaps in authentication, logging, and payment page security before an assessor identifies them.

Planet 9 is a Bay Area cybersecurity consulting firm specializing in PCI DSS readiness for SMBs in retail, e-commerce, and payments. Our vCISOs and compliance managers help organizations choose the right approach, configure GRC tools if needed, and get audit-ready without wasted time.

Book a Free Consultation

Schedule a free consultation today to explore how Planet 9 can help you achieve your security and compliance goals.
Book Free Consultation

FAQs

How does a vCISO service differ from hiring a full-time CISO?
A part-time CISO offers the same strategic oversight and expertise as a full-time CISO but on a flexible, cost-effective basis. It’s ideal for small to mid-sized businesses that need executive-level guidance without the overhead.
Is a virtual CISO service suitable for regulated industries like healthcare or finance?
Yes, virtual CISOs (or fractional CISOs) are especially valuable for industries with strict compliance requirements such as HIPAA, PCI DSS, or GLBA. They help ensure your organization meets regulatory standards and is prepared for audits.
What can I expect during a vCISO engagement?
Our vCISO service typically includes cybersecurity assessments, program development, compliance planning, incident response strategy, vendor risk management, and ongoing executive reporting tailored to your business.
How do I know if my business needs a CISO-as-a-Service?
If you lack in-house security leadership, struggle with compliance, or face growing cyber risks, a vCISO can fill that gap, providing strategic direction, improving resilience, and helping you make smarter security investments.

FAQs

What is PCI DSS?
PCI DSS stands for the Payment Card Industry Data Security Standard, a set of security controls maintained by the PCI Security Standards Council for any organization that stores, processes, or transmits payment card data. It covers network security, access control, monitoring, and governance across 12 core requirement categories.
What are the 12 PCI DSS requirements?
The 12 requirements span network security controls, secure configurations, protection of stored and transmitted account data, malware defense, secure software development, access restriction, authentication, physical security, logging and monitoring, regular security testing, and organizational security policy. They group under six broader control objectives covering network security, data protection, vulnerability management, access control, monitoring, and governance.
What is PCI DSS 4.0?
PCI DSS 4.0 is the current major version of the standard, published by the PCI Security Standards Council in March 2022 and fully replacing the prior version in 2024. It introduced dozens of new or updated controls, many of which carried a transition period before becoming mandatory in 2025.
Is PCI DSS 4.0 mandatory for every business that takes card payments?
PCI DSS applies to any entity that stores, processes, or transmits cardholder data, regardless of size, and the current version, 4.0.1, is the only active version assessors use. The scope and validation method, whether a self-assessment questionnaire or a formal report, depends on transaction volume and card brand requirements rather than company size alone.
How often does a business need a PCI DSS assessment?
PCI DSS compliance is generally validated annually, with scope confirmation and risk analysis documentation also expected on a yearly cycle under the current standard. Ongoing requirements, such as quarterly vulnerability scanning and daily log review, continue between formal assessment cycles.

Related blog posts