Don’t do SECURITY. Do business SECURELY.

PCI DSS version 4.0 released

The PCI Security Standards Council publishes PCI DSS v4.0, the first major update to the card data security standard since 2018.

The PCI Security Standards Council has published PCI DSS version 4.0, a major update to the Payment Card Industry Data Security Standard for organisations that store, process or transmit payment card data.

Key points

  • Introduces a customised approach, allowing organisations to meet objectives with alternative controls.
  • Strengthens authentication, including wider use of multi-factor authentication.
  • Adds new requirements for targeted risk analyses and for managing scripts on payment pages.
  • PCI DSS v3.2.1 remains active until 31 March 2024 to allow transition.
  • Many new requirements are future-dated and become mandatory on 31 March 2025.

Merchants and service providers in the UK will need to plan their transition, update policies and processes, and budget for new technical controls ahead of the future-dated deadline.

Source: PCI DSS v4.0 announcement (PCI Security Standards Council)

Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.

More insights