PCI DSS v4.0
What is PCI DSS v4.0?
PCI DSS v4.0 is the global security standard for organisations that store, process, or transmit cardholder data, published by the PCI Security Standards Council. Version 4.0, released in March 2022 with full enforcement from 31 March 2025, introduced a customised approach to validation, expanded multi-factor authentication requirements, and added 64 new requirements. It contains 63 top-level controls across 12 requirement areas. It comprises 63 controls organised across 12 domains, published by PCI Security Standards Council, and applies in International.
What PCI DSS v4.0 asks an organisation to do
What is PCI DSS v4.0?
The Payment Card Industry Data Security Standard (PCI DSS) v4.0 is the mandatory security standard for any organisation that stores, processes, or transmits payment card data from the major card brands (Visa, Mastercard, American Express, Discover, JCB). Published by the PCI Security Standards Council, it replaced version 3.2.1 with full enforcement from 31 March 2025. Compliance is validated through Self-Assessment Questionnaires (SAQs) or on-site assessments by Qualified Security Assessors (QSAs), depending on transaction volume.
What are the 12 PCI DSS requirements?
PCI DSS v4.0 is organised into 12 top-level requirements grouped under 6 goals:
- Install and Maintain Network Security Controls: Implement and maintain firewall/security configurations to protect cardholder data
- Apply Secure Configurations: Do not use vendor-supplied defaults for system passwords and security parameters
- Protect Stored Account Data: Protect stored cardholder data through encryption, masking, and retention policies
- Protect Cardholder Data in Transit: Encrypt transmission of cardholder data across open, public networks
- Protect from Malicious Software: Protect all systems and networks from malicious software
- Develop Secure Systems and Software: Develop and maintain secure systems and applications
- Restrict Access by Business Need: Restrict access to cardholder data to authorised personnel only
- Identify Users and Authenticate Access: Identify and authenticate access to system components
- Restrict Physical Access: Restrict physical access to cardholder data and systems
- Log and Monitor All Access: Log and monitor all access to cardholder data and network resources
- Test Security Regularly: Regularly test security systems and processes including vulnerability scans and penetration tests
- Maintain an Information Security Policy: Maintain a policy that addresses information security for all personnel
What changed in PCI DSS v4.0?
Version 4.0 introduced several major changes from v3.2.1:
- Customised Approach: A new validation method allowing organisations to meet security objectives using controls different from those in the defined approach, provided they demonstrate equivalent security
- Expanded MFA: Multi-factor authentication now required for all access to the cardholder data environment, not just remote access
- Targeted Risk Analysis: Organisations must perform targeted risk analyses to determine the frequency of certain periodic activities
- Enhanced Authentication: Increased password length requirements (minimum 12 characters) and stricter authentication controls
- 64 New Requirements: Added requirements addressing emerging threats including phishing, e-commerce skimming, and automated security testing
Map this against the frameworks you already hold
The compliance knowledge graph holds cross-framework control mappings for hundreds of standards, including the ones you are likely to be certified against already.
Browse the framework graph →Key controls, from the 63 PCI DSS v4.0 defines
| ID | Control |
|---|---|
| 1.1 | Network Security Controls Defined |
| 3.1 | Account Data Protection |
| 4.1 | Transmission Encryption |
| 6.1 | Secure Development |
| 8.1 | User Identification |
| 8.4 | Multi-Factor Authentication |
| 11.1 | Security Testing |
| 12.1 | Information Security Policy |
The 12 domains PCI DSS v4.0 groups its controls into
Where PCI DSS v4.0 overlaps with the standards you already hold
Step-by-step implementation of PCI DSS v4.0
More PCI DSS v4.0 comparisons
Analysis of PCI DSS v4.0
Training that covers PCI DSS v4.0
What PCI DSS v4.0 means in your sector
What PCI DSS v4.0 means for your job
Questions people ask about PCI DSS v4.0
What is PCI DSS v4.0?
How many controls does PCI DSS v4.0 have?
Where does PCI DSS v4.0 apply?
What frameworks does PCI DSS v4.0 map to?
How do I get started with PCI DSS v4.0 compliance?
Query PCI DSS v4.0 programmatically
PCI DSS v4.0, its 63 controls and every mapping into other standards are available over a REST endpoint and an MCP server, so an agent can read them directly. The free tier is 10 calls a day and needs no signup.
PCI DSS v4.0 API reference and MCP config →How ready are you for PCI DSS v4.0?
Answer 25 questions and get a professional readiness report with gap analysis, maturity scores, and prioritised action items. Results in 5 minutes.