How the standard is organized
PCI DSS v4.0.1 groups its 12 principal requirements under 6 goals. Each principal requirement breaks into numbered detailed requirements, with testing procedures that assessors follow and guidance that explains the intent. They apply to the cardholder data environment. That means the people, processes, and technology that store, process, or transmit account data, plus anything connected to them or able to affect their security.
Scope drives cost. Network segmentation, tokenization, and outsourcing to validated providers can shrink the environment that must meet every requirement.
Goal 1: build and maintain a secure network and systems
Requirement 1 covers network security controls, a broader term in v4 than firewalls, so it includes cloud security groups and similar tools. Firewalls still count. Rules must be documented, justified, and reviewed at least every 6 months. Requirement 2 asks for secure configuration standards for all system components, including changing vendor default passwords and removing services that aren't needed.
Goal 2: protect account data
Requirement 3 limits what can be stored. Sensitive authentication data, such as full track data, card verification codes, and PINs, must not be kept after authorization. Stored card numbers must be unreadable through methods such as strong encryption, truncation, or tokenization, and the cryptographic keys must be managed. Requirement 4 requires strong cryptography whenever card numbers travel over open, public networks.
Goal 3: maintain a vulnerability management program
Requirement 5 covers malware protection on systems at risk and, since March 2025, technical controls against phishing. Phishing controls are new. Requirement 6 covers secure software development, timely patching, and protection of public web applications. It also contains Requirement 6.4.3, which requires merchants to manage and authorize every script on their payment pages, a direct response to online skimming attacks.
Goal 4: implement strong access control measures
Requirement 7 limits access by job need. Requirement 8 covers identification and authentication, including multi-factor authentication for all access into the cardholder data environment, including both remote and local access. Requirement 9 covers physical security, from data centres to paper records, and protecting point-of-interaction devices against tampering and substitution.
Goal 5: regularly monitor and test networks
Requirement 10 requires logging of access to system components and cardholder data, with automated mechanisms for log review. Retention matters too. Requirement 11 covers wireless checks, internal and external vulnerability scans at least every 3 months, penetration testing, intrusion detection, and change detection. Requirement 11.6.1 adds a mechanism to detect unauthorized changes to payment pages as the customer's browser receives them.
Goal 6: maintain an information security policy
Requirement 12 ties the program together. It covers the security policy, roles and responsibilities, targeted risk analyses, security awareness, management of third-party service providers, and an incident response plan. Since March 2025, service providers must confirm their PCI DSS scope at least every 6 months, and merchants must do so at least once a year.
Defined and customized approaches
Version 4 added a second way to meet many requirements. The defined approach follows the stated requirement and testing procedure. The customized approach lets an entity meet the stated objective of a requirement with controls of its own design, backed by a documented risk analysis and a controls matrix that the assessor tests. It suits mature organizations. Entities completing a Self-Assessment Questionnaire use the defined approach.
Resources
- PCI Data Security Standard (PCI DSS), PCI Security Standards Council
- Document Library (standard, SAQs, and guidance), PCI Security Standards Council
- Merchant Resources, PCI Security Standards Council
- Qualified Security Assessors list, PCI Security Standards Council
- Approved Scanning Vendors list, PCI Security Standards Council
References
- PCI Data Security Standard (PCI DSS), PCI Security Standards Council
- Document Library, PCI Security Standards Council
- Now is the Time for Organizations to Adopt the Future-Dated Requirements of PCI DSS v4.x, PCI Security Standards Council
General information, reviewed 2026-10-11. Not legal advice.