PCI DSS 4.0 was released in March 2022 as a major update to the payment card industry security standard, with the transition deadline of March 31, 2025 now past. Organizations that have not yet completed their migration face increased audit scrutiny and potential non-compliance findings. This guide covers the most significant changes in PCI DSS 4.0, the new requirements that demand immediate attention, and practical steps for organizations still working toward full compliance.
PoliWriter generates all the policies, mappings, and audit-ready artifacts referenced in this guide — customized to your AWS / GitHub / Okta stack. 60+ integrations, continuous monitoring, evidence collection — at a fraction of Vanta's price.
Monthly billing · cancel anytime · 30-day money-back guarantee
PCI DSS 4.0 became the only active version on March 31, 2025, when version 3.2.1 was officially retired. All 64 new requirements, including the 51 future-dated requirements, became mandatory on this date. Organizations assessed after this date are evaluated entirely against PCI DSS 4.0.
The biggest changes include MFA required for all CDE access (not just remote), mandatory anti-phishing mechanisms, WAF required for all public-facing web apps, payment page change-and-tamper-detection, increased password length to 12 characters, targeted risk analysis replacing fixed frequencies, and the introduction of the Customized Approach.
The Customized Approach allows organizations to meet PCI DSS security objectives through alternative controls rather than following the prescriptive requirements of the Defined Approach. It requires more rigorous documentation, targeted risk analysis, and assessor validation, making it more suitable for mature security programs.
Non-compliance after March 31, 2025 can result in increased transaction fees, placement in mandatory remediation programs, potential restrictions on payment processing, and increased liability in the event of a breach. Organizations should conduct immediate gap assessments and document remediation progress.
Yes. Requirement 6.4.2 now mandates a web application firewall for all public-facing web applications. Under PCI DSS 3.2.1, a WAF was an alternative to manual code reviews. Under 4.0, it is required regardless of whether code reviews are also performed.
Targeted risk analysis under Requirement 12.3.1 requires organizations to evaluate their specific risk profile to determine appropriate frequencies for security activities. Each analysis must document assets, threats, vulnerabilities, risk levels, and the justification for chosen frequencies. It replaces the previous fixed-frequency approach for many requirements.
PoliWriter generates all the policies, mappings, and audit-ready artifacts referenced in this guide — customized to your AWS / GitHub / Okta stack. 60+ integrations, continuous monitoring, evidence collection — at a fraction of Vanta's price.
PoliWriter creates all the policies you need for PCI DSS compliance, customized to your organization. AI-powered, audit-ready, hours not months.
Get Started Free