Pci Dss v4 0 at A Glance

Download as pdf or txt
Download as pdf or txt
You are on page 1of 2

AT A GLANCE: PCI DSS v4.

PCI DSS v4.0

What is the PCI Data Security Standard?


The PCI Data Security Standard (PCI DSS) is a global standard that provides a baseline of technical and operational
requirements designated to protect payment data. PCI DSS v4.0 is the next evolution of the standard.

Goals for PCI DSS v4.0

Continue to Meet the Promote Security as Add Flexibility for Enhance Validation
Security Needs of the Continuous Process Different Methodologies Methods
Payment Industry

Developed with Global Industry Collaboration


Development of PCI DSS v4.0 was driven by industry feedback. This version furthers the protection of payment data
with new controls to address sophisticated cyber attacks.

3
Request for Comment (RFCs)
6,000+
Items of Feedback
200+
Companies Provided
On Draft Content Received Feedback

Implementation Timeline
PCI DSS v3.2.1 will remain active for two years after v4.0 is published. This provides organizations time to become
familiar with the new version, and plan for and implement the changes needed.
31 March 2025
Official Release: ISA/QSA 31 March 2024
Future-dated new
PCI DSS v4.0 with training and PCI DSS v3.2.1
requirements
validation supporting retired
become effective
documents documents

Q1 Q2 Q3 Q4 Q1 Q2 Q3 Q4 Q1 Q2 Q3 Q4 Q1 Q2

2022 2023 2024 2025


Transition Transition
period from PCI DSS
period fromv3.2.1 to v4.0
PCI DSS v3.2.1 to v4.0

Implementation of future-dated new requirements

© 2022 PCI Security Standards Council LLC. The intent of this document is to provide supplemental 1
information, which does not replace or supersede PCI SSC Security Standards or their supporting documents.
March 2022
AT A GLANCE: PCI DSS v4.0

What is New in PCI DSS v4.0?


There were many changes incorporated into the latest version of the Standard. Below are examples of some
of those changes. For a comprehensive view, please refer to the Summary of Changes from PCI DSS v3.2.1 to
v4.0, found in the PCI SSC Document Library.

Continue to meet the security needs of the payments industry.


Why it is important: Security practices must evolve as threats change.

Examples:
• Expanded multi-factor authentication requirements.
• Updated password requirements.
• New e-commerce and phishing requirements to address ongoing threats.

Promote security as a continuous process.


Why it is important: Criminals never sleep. Ongoing security is crucial to
protect payment data.
Examples:
• Clearly assigned roles and responsibilities for each requirement.
• Added guidance to help people better understand how to implement and maintain
security.
• New reporting option to highlight areas for improvement and provide more
transparency for report reviewers.

Increase flexibility for organizations using different methods to


achieve security objectives.
Why it is important: Increased flexibility allows more options to achieve a
requirement’s objective and supports payment technology innovation.
Examples:
• Allowance of group, shared, and generic accounts.
• Targeted risk analyses empower organizations to establish frequencies for
performing certain activities.
• Customized approach, a new method to implement and validate PCI DSS
requirements, provides another option for organizations using innovative methods to
achieve security objectives.

Enhance validation methods and procedures.


Why it is important: Clear validation and reporting options support
transparency and granularity.
Example:
• Increased alignment between information reported in a Report on Compliance or
Self-Assessment Questionnaire and information summarized in an Attestation of
Compliance.

Subscribe to the PCI Perspectives Blog

© 2022 PCI Security Standards Council LLC. The intent of this document is to provide supplemental 2
information, which does not replace or supersede PCI SSC Security Standards or their supporting documents.
March 2022

You might also like