Introduction to PCI DSS 4.0
PCI DSS 4.0 is the most significant update to the Payment Card Industry Data Security Standard since its inception. Released in March 2022, it introduces 64 new requirements and a more flexible, outcome-based approach to security.
Key Dates
March 2022: PCI DSS 4.0 published
March 2024: PCI DSS 3.2.1 retired
March 2025: All organizations must comply with 4.0
March 2025: Future-dated requirements become mandatory
What's Different in 4.0
Customized Approach:
Alternative to traditional controls
Outcome-focused validation
Greater flexibility
Requires robust risk assessment
Enhanced Authentication:
MFA for all access to CDE
Stricter password requirements
Phishing-resistant authentication
Continuous Security:
Ongoing security program
Targeted risk analysis
Regular security testing
Major Requirement Changes
Requirement 3: Protect Stored Account Data
New Requirements:
Encryption of SAD after authorization
Technical controls to prevent copy/relocation of PAN
Cryptographic key management enhancements
Data retention policy automation
Key Changes:
Broader encryption requirements
Enhanced key management
Automated data discovery
Requirement 4: Protect Data in Transit
New Requirements:
TLS 1.2+ mandatory
Certificates from trusted CAs
Inventory of trusted keys/certificates
Process to detect certificate expiration
Key Changes:
Stricter TLS requirements
Certificate lifecycle management
Trust anchor documentation
Requirement 5: Protect Systems from Malware
New Requirements:
Anti-malware on all system types
Periodic malware scans for removable media
Anti-phishing mechanisms
Detection of behaviors as well as signatures
Key Changes:
Expanded scope beyond Windows
Behavioral analysis requirements
Phishing protection mandate
Requirement 6: Develop Secure Systems
New Requirements:
Software inventory maintenance
Vulnerability classification and prioritization
Protection of payment page scripts
Automated code review for bespoke software
Key Changes:
Software Bill of Materials (SBOM)
Risk-based vulnerability management
Client-side security focus
Requirement 7: Restrict Access
New Requirements:
Regular access reviews (6 months)
Privileged access review processes
System accounts management
Enhanced role definitions
Key Changes:
More frequent access reviews
System account controls
Documented access policies
Requirement 8: Identify and Authenticate
New Requirements:
MFA for all CDE access (not just remote)
12-character minimum passwords
Password change frequency based on risk
Phishing-resistant MFA options
Key Changes:
Universal MFA requirement
Stronger password requirements
Risk-based authentication
Requirement 10: Log and Monitor
New Requirements:
Automated log review mechanisms
Targeted risk analysis for log retention
Real-time alerting capabilities
Failure detection for security controls
Key Changes:
Automation requirements
Risk-based log retention
Proactive alerting
Requirement 11: Test Security
New Requirements:
Internal vulnerability scans after significant changes
Authenticated internal scanning
Multi-tenant service provider penetration testing
Intrusion detection for all external perimeter
Key Changes:
Change-triggered scanning
Authenticated scanning mandate
Enhanced pentest requirements
Requirement 12: Support Security
New Requirements:
Documented security awareness program
Targeted risk analysis process
Incident response plan updates
Technology personnel acknowledgment
Key Changes:
Formalized risk analysis
Enhanced IR requirements
Security culture emphasis
Implementation Roadmap
Phase 1: Assessment (Months 1-3)
Gap Analysis:
Compare current state to 4.0
Identify new requirements impact
Assess customized approach viability
Estimate remediation effort
Planning:
Prioritize requirements
Allocate resources
Set milestones
Engage stakeholders
Phase 2: Foundation (Months 4-8)
High-Priority Items:
MFA implementation everywhere
Password policy updates
Encryption enhancements
Log monitoring automation
Process Updates:
Targeted risk analysis procedures
Access review processes
Incident response plan updates
Security awareness program
Phase 3: Technical Controls (Months 9-14)
Security Controls:
Anti-phishing mechanisms
Payment page script protection
Vulnerability management enhancements
Change detection mechanisms
Monitoring:
Real-time alerting
Automated log review
Security control monitoring
Failure detection
Phase 4: Validation (Months 15-18)
Testing:
Internal vulnerability scans
Penetration testing
Control validation
Documentation review
Assessment:
Self-assessment questionnaire
External audit preparation
Evidence collection
Remediation completion
Customized Approach
When to Consider
Good Candidates:
Mature security programs
Strong risk management
Innovative technologies
Unique environments
Requirements:
Documented controls matrix
Risk assessment methodology
Evidence of effectiveness
QSA agreement
Implementation Steps
1Define Objective: Understand requirement intent
2Design Controls: Create alternative approach
3Document Rationale: Explain equivalence
4Validate Effectiveness: Prove it works
5Maintain Evidence: Ongoing documentation
Key Technical Requirements
MFA Everywhere
Scope: All access to CDE, not just remote
Requirements:
Two or more factors
Independent channels
Phishing-resistant preferred
System-enforced
Password Requirements
Minimum Standards:
12 characters minimum
Complexity or passphrase
Risk-based change frequency
No reuse of last 4 passwords
Client-Side Security
Payment Page Protection:
Script inventory
Integrity monitoring
Authorization controls
Change detection
Compliance Challenges
Challenge 1: MFA Everywhere
Solution: Phased rollout, prioritize CDE access, leverage existing IAM
Challenge 2: Targeted Risk Analysis
Solution: Develop methodology, train teams, document decisions
Challenge 3: Automation Requirements
Solution: SIEM enhancements, automated scanning, alerting tools
Challenge 4: Script Protection
Solution: Content Security Policy, Subresource Integrity, monitoring tools
Validation and Maintenance
SAQ Selection
Choose appropriate Self-Assessment Questionnaire:
SAQ A: Card-not-present, fully outsourced
SAQ A-EP: E-commerce with website
SAQ B: Imprint machines, standalone terminals
SAQ C: Payment application systems
SAQ D: All other merchants
Ongoing Compliance
Quarterly vulnerability scans
Annual penetration tests
Regular access reviews
Continuous monitoring
Annual reassessment
Conclusion
PCI DSS 4.0 represents a significant evolution in payment security standards. Organizations should begin transition planning immediately, focusing on new requirements around MFA, authentication, and automated monitoring. The customized approach offers flexibility for mature organizations, while the extended timeline provides opportunity for thoughtful implementation.