PCI DSS v4.0.1 Request for Comments Opens: What Organizations Need to Know
The PCI Security Standards Council has opened a six-week public comment period from June 3 to July 20, 2026, for eligible stakeholders to review and provide feedback on the proposed PCI Data Security Standard (PCI DSS) v4.0.1. This revision follows the current v4.0 standard and may introduce new requirements or clarifications affecting organizations that handle payment card data.
PCI Security Standards Council Opens Comment Period for DSS v4.0.1
The Payment Card Industry Security Standards Council (PCI SSC) has announced a six-week request for comments (RFC) period for the proposed PCI Data Security Standard (PCI DSS) v4.0.1, running from June 3 through July 20, 2026. This development represents a significant opportunity for eligible stakeholders to influence the evolution of payment card data security requirements.
Who Can Participate in the RFC Process
The comment period is specifically open to eligible PCI SSC stakeholders, which typically includes participating organizations such as payment brands, acquiring banks, processors, merchants, and qualified security assessors (QSAs). Organizations must have formal stakeholder status with the PCI SSC to participate in this review process.
The RFC process is a critical component of the PCI SSC's collaborative approach to developing security standards, ensuring that practical implementation concerns and industry feedback are incorporated before final publication.
Expected Changes and Updates in v4.0.1
While the specific details of the proposed changes in PCI DSS v4.0.1 have not been publicly disclosed, version increments typically address:
- Clarifications to existing requirements that have generated frequent questions
- Minor corrections to technical specifications or implementation guidance
- Updates to reflect emerging threats or payment technologies
- Refinements based on real-world implementation feedback from v4.0
Compliance Implications for Organizations
Organizations subject to PCI DSS compliance should prepare for potential impacts from v4.0.1:
Immediate Actions
- Monitor the RFC outcomes and final publication timeline
- Review current compliance posture against existing v4.0 requirements
- Engage with qualified security assessors to understand potential changes
Strategic Planning
- Budget for potential system updates or security enhancements
- Plan compliance timeline adjustments if new requirements are introduced
- Consider participating in the RFC process if your organization is an eligible stakeholder
Timeline and Implementation Expectations
The six-week comment period concludes on July 20, 2026. Following this period, the PCI SSC will:
1. Review and analyze all submitted feedback 2. Incorporate appropriate changes based on stakeholder input 3. Publish the final version of PCI DSS v4.0.1 4. Provide implementation guidance and transition timelines
Based on historical patterns, organizations can expect a grace period of 12-18 months between final publication and mandatory compliance with any new requirements, allowing adequate time for system updates and validation processes.
What Organizations Should Do Now
While awaiting the final v4.0.1 publication, organizations should:
- Maintain current compliance with PCI DSS v4.0 requirements
- Stay informed about the RFC outcomes and final changes
- Engage with compliance partners including QSAs and technology vendors
- Assess current security posture to identify areas that may be affected by updates
Frequently Asked Questions
Who is eligible to participate in the PCI DSS v4.0.1 comment period?
Only eligible PCI SSC stakeholders can participate, including payment brands, acquiring banks, processors, merchants, and qualified security assessors with formal stakeholder status.
When does the PCI DSS v4.0.1 comment period end?
The six-week request for comments period runs from June 3 to July 20, 2026.
Will PCI DSS v4.0.1 introduce new compliance requirements?
The specific changes haven't been disclosed, but version updates typically include clarifications, corrections, and refinements rather than major new requirements.
How long do organizations have to implement PCI DSS v4.0.1 requirements?
Historically, organizations receive 12-18 months from final publication to achieve mandatory compliance with new PCI DSS requirements.
Should organizations wait for PCI DSS v4.0.1 before completing current compliance efforts?
No, organizations should maintain current compliance with PCI DSS v4.0 requirements while monitoring v4.0.1 developments for future planning.
Related News
PCI Security Standards Council Showcases AI Innovation in Payment Security with In-Solutions Global
Jun 2, 2026PCI Security Standards Council Opens Nominations for Global Executive Assessor Roundtable (GEAR)
May 28, 2026PaySprint Advances Compliance Focus Across Fintech Infrastructure Services
May 21, 2026PCI Security Standards Council Opens RFC Period for Secure Software Lifecycle Standard v2.0
May 15, 2026Generate compliance docs with PoliWriter
PoliWriter creates all the policies and documentation you need for compliance, customized to your organization. AI-powered, audit-ready, hours not months.
Get Started Free