Don’t do SECURITY. Do business SECURELY.

PCI DSS v4.0 future-dated requirements become mandatory

The future-dated requirements in PCI DSS v4.0 become mandatory, including targeted risk analyses, wider MFA and payment page script controls.

Today is the deadline for the future-dated requirements in PCI DSS v4.0 (now v4.0.1) to become mandatory. Until now they were considered best practice.

Key points

  • Targeted risk analyses are required to set the frequency of certain controls.
  • Multi-factor authentication is required for all access into the cardholder data environment.
  • Scripts on payment pages must be authorised, inventoried and protected against tampering.
  • Automated mechanisms are needed to review audit logs.
  • Stronger password and authentication requirements apply.

UK merchants and service providers will be assessed against these requirements from now on. Any gaps should be addressed quickly, as they are likely to appear as findings in your next assessment.

Source: PCI DSS v4.x future-dated requirements (PCI Security Standards Council)

Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.

Get our weekly insights by emailA free weekly threat and vulnerability round-up with our threat log spreadsheet, plus legal, regulatory, standards, and AI updates.
Subscribe free

More insights