Skip to content
    Back to Regulatory Radar
    CriticalFramework UpdateMarch 31, 2022

    PCI DSS v4.0 Released

    The PCI Security Standards Council published PCI DSS v4.0, the first major revision since v3.2.1 in 2018. The update introduced 64 new requirements, a customized approach for meeting security objectives, and expanded multi-factor authentication mandates. Organizations were given a two-year transition window, with v3.2.1 retiring on March 31, 2024. A limited revision, v4.0.1, was published in June 2024 and became the only supported version after v4.0 retired on December 31, 2024; all 51 future-dated requirements became mandatory on March 31, 2025.

    PCI DSSFinTechSaaS

    Key Analytics

    March 31, 2022
    Event Date
    Time Remaining
    August 24, 2026
    Last Verified
    1
    Frameworks Affected

    Impact Analysis

    Every organization that stores, processes, or transmits cardholder data must now comply with the full v4.x requirement set; as of March 31, 2025 the future-dated requirements are enforceable in all assessments. The customized approach option provides flexibility but demands mature risk management documentation and evidence. Requirements around targeted risk analysis, authenticated vulnerability scanning, and payment page script integrity monitoring require significant technical investment, and assessments must now be performed against v4.0.1.

    Recommended Actions

    • Confirm all 64 new v4.x requirements, including the 51 formerly future-dated items mandatory since March 31, 2025, are implemented and evidenced
    • Align policies, SAQs, and ROC documentation to PCI DSS v4.0.1, the only version supported since December 31, 2024
    • Evaluate whether the customized approach is viable based on organizational maturity and document the decision with targeted risk analyses

    Always verify requirements with official regulatory sources.

    Estimated Remediation Effort

    Indicative effort to address this development, broken down by your organization's current compliance posture. Select the posture that best matches where you are today.

    A partial program exists: some policies and controls are in place, but coverage, evidence, and ownership have gaps.

    Analyst estimate
    Significant110-250 hours
    Key Workstreams
    • Gap assessment against the 64 new v4.x requirements
    • Remediation of the 51 formerly future-dated items
    • Policy and SAQ alignment to v4.0.1

    The Cost of Waiting

    Readiness work is dramatically cheaper before a deadline than after one. The ranges below come from the same estimate: the difference is only how prepared you are when the work starts.

    Start preparing nowSignificant · 110-250 hours
    Start cold under pressureMajor · 260-600 hours

    Roughly 150 to 350 hours avoided by preparing early

    Effort ranges are indicative planning estimates, not quotes. Actual effort depends on organizational scope, environment complexity, and evidence maturity. Talk to us for a scoped assessment.

    Related Events