Back to Blog
GRC22 min read2024-11-25

PCI DSS 4.0: What's New & How to Comply

Complete guide to PCI DSS 4.0 changes, new requirements, and implementation roadmap for payment card security compliance.

A

Asfaleia Team

Security Consultant

PCI DSS 4.0: What's New & How to Comply
Sections

Introduction to PCI DSS 4.0

PCI DSS 4.0 is the most significant update to the Payment Card Industry Data Security Standard since its inception. Released in March 2022, it introduces 64 new requirements and a more flexible, outcome-based approach to security.

Key Dates

March 2022: PCI DSS 4.0 published
March 2024: PCI DSS 3.2.1 retired
March 2025: All organizations must comply with 4.0
March 2025: Future-dated requirements become mandatory

What's Different in 4.0

Customized Approach:
Alternative to traditional controls
Outcome-focused validation
Greater flexibility
Requires robust risk assessment
Enhanced Authentication:
MFA for all access to CDE
Stricter password requirements
Phishing-resistant authentication
Continuous Security:
Ongoing security program
Targeted risk analysis
Regular security testing

Major Requirement Changes

Requirement 3: Protect Stored Account Data

New Requirements:
Encryption of SAD after authorization
Technical controls to prevent copy/relocation of PAN
Cryptographic key management enhancements
Data retention policy automation
Key Changes:
Broader encryption requirements
Enhanced key management
Automated data discovery

Requirement 4: Protect Data in Transit

New Requirements:
TLS 1.2+ mandatory
Certificates from trusted CAs
Inventory of trusted keys/certificates
Process to detect certificate expiration
Key Changes:
Stricter TLS requirements
Certificate lifecycle management
Trust anchor documentation

Requirement 5: Protect Systems from Malware

New Requirements:
Anti-malware on all system types
Periodic malware scans for removable media
Anti-phishing mechanisms
Detection of behaviors as well as signatures
Key Changes:
Expanded scope beyond Windows
Behavioral analysis requirements
Phishing protection mandate

Requirement 6: Develop Secure Systems

New Requirements:
Software inventory maintenance
Vulnerability classification and prioritization
Protection of payment page scripts
Automated code review for bespoke software
Key Changes:
Software Bill of Materials (SBOM)
Risk-based vulnerability management
Client-side security focus

Requirement 7: Restrict Access

New Requirements:
Regular access reviews (6 months)
Privileged access review processes
System accounts management
Enhanced role definitions
Key Changes:
More frequent access reviews
System account controls
Documented access policies

Requirement 8: Identify and Authenticate

New Requirements:
MFA for all CDE access (not just remote)
12-character minimum passwords
Password change frequency based on risk
Phishing-resistant MFA options
Key Changes:
Universal MFA requirement
Stronger password requirements
Risk-based authentication

Requirement 10: Log and Monitor

New Requirements:
Automated log review mechanisms
Targeted risk analysis for log retention
Real-time alerting capabilities
Failure detection for security controls
Key Changes:
Automation requirements
Risk-based log retention
Proactive alerting

Requirement 11: Test Security

New Requirements:
Internal vulnerability scans after significant changes
Authenticated internal scanning
Multi-tenant service provider penetration testing
Intrusion detection for all external perimeter
Key Changes:
Change-triggered scanning
Authenticated scanning mandate
Enhanced pentest requirements

Requirement 12: Support Security

New Requirements:
Documented security awareness program
Targeted risk analysis process
Incident response plan updates
Technology personnel acknowledgment
Key Changes:
Formalized risk analysis
Enhanced IR requirements
Security culture emphasis

Implementation Roadmap

Phase 1: Assessment (Months 1-3)

Gap Analysis:
Compare current state to 4.0
Identify new requirements impact
Assess customized approach viability
Estimate remediation effort
Planning:
Prioritize requirements
Allocate resources
Set milestones
Engage stakeholders

Phase 2: Foundation (Months 4-8)

High-Priority Items:
MFA implementation everywhere
Password policy updates
Encryption enhancements
Log monitoring automation
Process Updates:
Targeted risk analysis procedures
Access review processes
Incident response plan updates
Security awareness program

Phase 3: Technical Controls (Months 9-14)

Security Controls:
Anti-phishing mechanisms
Payment page script protection
Vulnerability management enhancements
Change detection mechanisms
Monitoring:
Real-time alerting
Automated log review
Security control monitoring
Failure detection

Phase 4: Validation (Months 15-18)

Testing:
Internal vulnerability scans
Penetration testing
Control validation
Documentation review
Assessment:
Self-assessment questionnaire
External audit preparation
Evidence collection
Remediation completion

Customized Approach

When to Consider

Good Candidates:
Mature security programs
Strong risk management
Innovative technologies
Unique environments
Requirements:
Documented controls matrix
Risk assessment methodology
Evidence of effectiveness
QSA agreement

Implementation Steps

1Define Objective: Understand requirement intent
2Design Controls: Create alternative approach
3Document Rationale: Explain equivalence
4Validate Effectiveness: Prove it works
5Maintain Evidence: Ongoing documentation

Key Technical Requirements

MFA Everywhere

Scope: All access to CDE, not just remote
Requirements:
Two or more factors
Independent channels
Phishing-resistant preferred
System-enforced

Password Requirements

Minimum Standards:
12 characters minimum
Complexity or passphrase
Risk-based change frequency
No reuse of last 4 passwords

Client-Side Security

Payment Page Protection:
Script inventory
Integrity monitoring
Authorization controls
Change detection

Compliance Challenges

Challenge 1: MFA Everywhere

Solution: Phased rollout, prioritize CDE access, leverage existing IAM

Challenge 2: Targeted Risk Analysis

Solution: Develop methodology, train teams, document decisions

Challenge 3: Automation Requirements

Solution: SIEM enhancements, automated scanning, alerting tools

Challenge 4: Script Protection

Solution: Content Security Policy, Subresource Integrity, monitoring tools

Validation and Maintenance

SAQ Selection

Choose appropriate Self-Assessment Questionnaire:

SAQ A: Card-not-present, fully outsourced
SAQ A-EP: E-commerce with website
SAQ B: Imprint machines, standalone terminals
SAQ C: Payment application systems
SAQ D: All other merchants

Ongoing Compliance

Quarterly vulnerability scans
Annual penetration tests
Regular access reviews
Continuous monitoring
Annual reassessment

Conclusion

PCI DSS 4.0 represents a significant evolution in payment security standards. Organizations should begin transition planning immediately, focusing on new requirements around MFA, authentication, and automated monitoring. The customized approach offers flexibility for mature organizations, while the extended timeline provides opportunity for thoughtful implementation.

Tags

#PCI DSS#Compliance#Payment Security#Data Protection#GRC

Downloadable-style takeaway

Use this as a working assessment checklist.

Pull the headings into your next security review, assign owners, and mark each section as ready, partial, or missing.

A

Written by

Asfaleia Team

Security Consultant

Written by the Asfaleia Tech Security Team, combining field experience across offensive testing, detection engineering, incident readiness, and compliance evidence.

Ready to Strengthen Your Security?

Let's discuss how Asfaleia-Tech can help protect your organization.