Back to Blog
GRC22 min read2024-11-25

PCI DSS 4.0: What's New & How to Comply

Complete guide to PCI DSS 4.0 changes, new requirements, and implementation roadmap for payment card security compliance.

A

Asfaleia Team

Security Consultant

Share on LinkedIn
PCI DSS 4.0: What's New & How to Comply
64
New Requirements
Mar 2025
Compliance Deadline
12 Char
Min Password Length
MFA
Required Everywhere

What's New in PCI DSS 4.0

PCI DSS 4.0 is the most significant update since the standard's creation. It introduces 64 new requirements, a customized approach option, and stronger authentication mandates.

Critical Deadline

Organizations must achieve full PCI DSS 4.0 compliance by March 2025. Future-dated requirements also become mandatory at this time.

Transition Timeline

Key Milestones

1

March 2024

PCI DSS 3.2.1 retired, all new assessments must be 4.0

2

March 2025

Full compliance with 4.0 required for all organizations

3

March 2025

Future-dated requirements become mandatory

MFA Changes

  • MFA required for ALL CDE access - not just remote
  • 12-character minimum passwords - up from 7
  • Phishing-resistant MFA - recommended

Key Changes Summary

PCI DSS 4.0 Requirements

Authentication
MFA for ALL CDE access
12-char minimum passwords
Risk-based change frequency
Phishing-resistant MFA
New Controls
Anti-phishing mechanisms
Payment page script protection
Authenticated vulnerability scans
Automated log review
Customized Approach
Alternative to defined approach
Outcome-focused validation
Requires risk assessment
QSA agreement needed
Continuous Security
Targeted risk analysis
Ongoing security program
Regular testing
Documented procedures

Customized Approach

PCI DSS 4.0 introduces a Customized Approach allowing organizations to meet security objectives through alternative controls. Requires mature security program and QSA agreement.

Priority Actions

Start with MFA deployment, password policy updates, and payment page script inventory. These are high-impact requirements with longer implementation timelines.

Conclusion

PCI DSS 4.0 brings essential updates addressing modern threats. Begin transition planning immediately, focusing on authentication, automation, and continuous security practices.

Tags

#PCI DSS#Compliance#Payment Security#Data Protection#GRC
A

Written by

Asfaleia Team

Security Consultant

PCI QSA with extensive experience in payment card security assessments.

Need PCI DSS 4.0 Help?

Our QSAs can guide your PCI DSS 4.0 transition.