PCI DSS v4.0.1 Future-Dated Testing Requirements Now Mandatory
PCI DSS v4.0.1 future-dated requirements became mandatory on 31 March 2025, including Requirement 11.4.7 (multi-tenant service providers must support customer external penetration testing), Requirement 11.3.1.2 (authenticated internal vulnerability scanning), and Requirement 6.4.2 (an automated technical solution that continually detects and prevents web-based attacks on public-facing web applications).
Key Analytics
Impact Analysis
The core penetration testing methodology requirement (11.4.1, a documented methodology based on industry-accepted approaches with 12-month retention of results) carried over from v3.2.1 and has applied since v4.0 took effect; it was never future-dated. What became mandatory on 31 March 2025 is the surrounding testing perimeter: authenticated internal vulnerability scans, management of vulnerabilities not ranked high-risk or critical, multi-tenant pentest support obligations, and continuous web attack detection and prevention replacing periodic web application reviews. All are now assessed in full under v4.0.1.
Recommended Actions
- Confirm your documented penetration testing methodology satisfies Req 11.4.1, including 12-month retention of test results
- Deploy an automated solution that continually detects and prevents web-based attacks per Req 6.4.2; periodic web app reviews no longer satisfy the requirement
- Implement authenticated internal vulnerability scanning per Req 11.3.1.2 and manage lower-ranked vulnerabilities per Req 11.3.1.1
- Multi-tenant service providers: establish processes to support customer external penetration testing per Req 11.4.7
- Verify pentest scope covers the full cardholder data environment and schedule annual tests with qualified testers
Always verify requirements with official regulatory sources.
Estimated Remediation Effort
Indicative effort to address this development, broken down by your organization's current compliance posture. Select the posture that best matches where you are today.
A partial program exists: some policies and controls are in place, but coverage, evidence, and ownership have gaps.
- ›Deploy continuous web attack detection to replace periodic web app reviews (Req 6.4.2)
- ›Stand up authenticated internal scanning and lower-ranked vulnerability handling
- ›Close methodology and 12-month retention gaps against Req 11.4.1
- ›Establish the multi-tenant pentest support process (Req 11.4.7)
The Cost of Waiting
Readiness work is dramatically cheaper before a deadline than after one. The ranges below come from the same estimate: the difference is only how prepared you are when the work starts.
Roughly 120 to 250 hours avoided by preparing early
Effort ranges are indicative planning estimates, not quotes. Actual effort depends on organizational scope, environment complexity, and evidence maturity. Talk to us for a scoped assessment.