Skip to content
    Back to Regulatory Radar
    CriticalDeadlineMarch 31, 2025

    PCI DSS v4.0 Future-Dated Requirements Now Mandatory

    All 51 future-dated requirements in PCI DSS v4.0 transitioned from best practice to mandatory, completing the full v4.0 implementation cycle. Key requirements now enforceable include targeted risk analysis for flexible control frequencies, automated detection and response to payment page script modifications, enhanced authentication for all access to the cardholder data environment, and inventory-based management of custom and third-party software. Assessors must now validate compliance with every v4.0 requirement without exception.

    PCI DSSFinTechSaaS

    Key Analytics

    March 31, 2025
    Event Date
    Time Remaining
    August 24, 2026
    Last Verified
    1
    Frameworks Affected

    Impact Analysis

    Organizations that treated future-dated requirements as optional or deferred implementation face immediate non-compliance findings in their next assessment. The script integrity and change-detection requirements for payment pages demand new tooling and monitoring capabilities that many merchants have not deployed. Enhanced authentication requirements extend MFA beyond remote access to include all CDE access, significantly expanding the scope of identity and access management controls.

    Recommended Actions

    • Validate full implementation of all 51 previously future-dated requirements and collect evidence for assessor review
    • Deploy payment page script monitoring and change-detection solutions that meet requirements 6.4.3 and 11.6.1
    • Extend multi-factor authentication to all interactive access to the cardholder data environment per requirement 8.4.2

    Always verify requirements with official regulatory sources.

    Estimated Remediation Effort

    Indicative effort to address this development, broken down by your organization's current compliance posture. Select the posture that best matches where you are today.

    A partial program exists: some policies and controls are in place, but coverage, evidence, and ownership have gaps.

    Analyst estimate
    Significant100-240 hours
    Key Workstreams
    • Gap closure across the 51 formerly future-dated requirements
    • Script integrity tooling for requirements 6.4.3 and 11.6.1
    • MFA scope extension under requirement 8.4.2

    The Cost of Waiting

    Readiness work is dramatically cheaper before a deadline than after one. The ranges below come from the same estimate: the difference is only how prepared you are when the work starts.

    Start preparing nowSignificant · 100-240 hours
    Start cold under pressureMajor · 240-540 hours

    Roughly 140 to 300 hours avoided by preparing early

    Effort ranges are indicative planning estimates, not quotes. Actual effort depends on organizational scope, environment complexity, and evidence maturity. Talk to us for a scoped assessment.

    Related Events