Timeline
The move to version 4 took 3 years. Each date below is confirmed on the PCI Security Standards Council's site or blog.
- March 2022: PCI DSS v4.0 published
- March 31, 2024: PCI DSS v3.2.1 retired
- June 11, 2024: PCI DSS v4.0.1 published as a limited revision
- December 31, 2024: PCI DSS v4.0 retired
- January 30, 2025: revised SAQ A published
- March 31, 2025: future-dated requirements became mandatory
- June 3 to July 20, 2026: request for comments on v4.0.1
What version 4 changed
PCI DSS v4.0 introduced 64 new requirements. Of these, 51 were future-dated, which gave organizations until March 31, 2025 to put them in place, while the rest applied as soon as an entity assessed against v4.0. The aim was to keep up with threats such as phishing, online skimming, and stolen credentials. It also gave mature organizations more flexibility.
Some of the most visible new requirements are listed below. Many apply to all entities, and a few apply only to service providers.
- Multi-factor authentication for all access into the cardholder data environment
- Management and authorization of every script on payment pages (6.4.3)
- Detection of unauthorized changes to payment pages (11.6.1)
- Technical controls against phishing attacks
- Targeted risk analyses to justify how often some controls run
- Annual scope confirmation for merchants (12.5.2), every 6 months for service providers
- Documented roles and responsibilities for each requirement
- The customized approach as an alternative to the defined approach
What version 4.0.1 changed
Version 4.0.1, published June 11, 2024, was a limited revision. It corrected formatting and typographical errors and clarified the focus and intent of some requirements and guidance. No requirements were added or removed. Organizations that had already started on v4.0 could move to v4.0.1 with little extra work. It didn't move the March 31, 2025 effective date for the future-dated requirements, and v4.0 retired on December 31, 2024.
The 2026 request for comments
From June 3 to July 20, 2026, the Council ran a 6-week request for comments on v4.0.1, open to eligible stakeholders through its portal. It marks the start of work on the next iteration of PCI DSS. Scope was broad. The Council asked for feedback on new requirements and testing procedures, risks the standard doesn't address well, areas where experience since v4.0.1 suggests changes, and how the standard should respond to artificial intelligence and mobile technology.
No release date for the next version has been announced. Until the Council publishes one, v4.0.1 remains the only active version.
Where this leaves organizations today
Every requirement now applies. Assessments performed today include the former future-dated items with no grace period. Organizations that relied on the SAQ A change should keep evidence that their payment page meets the new eligibility criterion, since acquirers can ask for it. Watch the Council's blog for news on the next version, which will come with its own transition period.
Resources
- PCI Data Security Standard (PCI DSS), PCI Security Standards Council
- Document Library (standard, SAQs, and guidance), PCI Security Standards Council
- Merchant Resources, PCI Security Standards Council
- Qualified Security Assessors list, PCI Security Standards Council
- Approved Scanning Vendors list, PCI Security Standards Council
References
- Just Published: PCI DSS v4.0.1, PCI Security Standards Council
- Now is the Time for Organizations to Adopt the Future-Dated Requirements of PCI DSS v4.x, PCI Security Standards Council
- Request for Comments: PCI Data Security Standard (PCI DSS) v4.0.1, PCI Security Standards Council
General information, reviewed 2026-10-11. Not legal advice.