Skip to content
    Back to Regulatory Radar
    ImportantFramework UpdateJune 11, 2024

    PCI DSS v4.0.1 Released with Clarifications

    The PCI Security Standards Council released PCI DSS v4.0.1 on June 11, 2024 as a limited revision correcting formatting and typographical errors and clarifying the focus and intent of certain requirements. No requirements were added or removed. Notable clarifications include a note that multi-factor authentication does not apply to accounts using phishing-resistant authentication factors, narrowed applicability guidance for payment page script requirements, and reverted patch management language limiting mandatory timelines to critical vulnerabilities. PCI DSS v4.0 was retired on December 31, 2024, making v4.0.1 the only active version of the standard.

    PCI DSSFinTechSaaS

    Key Analytics

    June 11, 2024
    Event Date
    Time Remaining
    August 24, 2026
    Last Verified
    1
    Frameworks Affected

    Impact Analysis

    Organizations that implemented controls under v4.0 should review the v4.0.1 clarifications to verify their interpretations align with the Council's intent. The clarified MFA applicability for phishing-resistant authentication and the narrowed scope of the payment page script requirements (6.4.3 and 11.6.1) may change control decisions made under earlier guidance. With v4.0 retired at the end of 2024, all assessments are now performed against v4.0.1, so compliance documentation should reference the updated version. The March 31, 2025 effective date for future-dated requirements was not changed by this revision.

    Recommended Actions

    • Review the PCI DSS v4.0 to v4.0.1 Summary of Changes document and compare clarifications against your current implementation decisions
    • Update compliance documentation, policies, and evidence collection procedures to reference v4.0.1
    • Verify that MFA implementations and payment page script controls align with the v4.0.1 clarifications before your next assessment

    Always verify requirements with official regulatory sources.

    Estimated Remediation Effort

    Indicative effort to address this development, broken down by your organization's current compliance posture. Select the posture that best matches where you are today.

    A partial program exists: some policies and controls are in place, but coverage, evidence, and ownership have gaps.

    Analyst estimate
    Moderate35-75 hours
    Key Workstreams
    • Summary of Changes review against current control decisions
    • MFA and script control alignment to the clarified scope
    • Documentation and evidence procedure updates to v4.0.1

    The Cost of Waiting

    Readiness work is dramatically cheaper before a deadline than after one. The ranges below come from the same estimate: the difference is only how prepared you are when the work starts.

    Start preparing nowModerate · 35-75 hours
    Start cold under pressureSignificant · 80-180 hours

    Roughly 45 to 105 hours avoided by preparing early

    Effort ranges are indicative planning estimates, not quotes. Actual effort depends on organizational scope, environment complexity, and evidence maturity. Talk to us for a scoped assessment.

    Related Events