PCI 4.0 in 2025: What best practices are becoming requirements?
Blog post from Basis Theory
PCI DSS 4.0 introduced more than 50 future-dated requirements that were scheduled to become mandatory on March 31, 2025, creating significant implementation and assessment obligations for organizations handling cardholder data. Key changes include requiring multi-factor authentication for all access to cardholder data environments, a technically demanding requirement primarily affecting businesses that store payment data in-house rather than relying on third-party vaulting or payment providers. Requirements concerning payment-page script security, including 6.4 and 11.6, require organizations to inventory, authorize, justify, monitor, and protect third-party scripts used on checkout pages to reduce web-skimming and formjacking risks, with options including removing unnecessary scripts or using a fully hosted payment page from a payment service provider. Additional protections require a web application firewall or equivalent controls, while updated SAQ and RoC processes emphasize risk assessments when environmental changes occur. The material advises merchants to prepare carefully to avoid noncompliance and notes that outsourcing payment-data handling can reduce PCI scope and simplify compliance efforts.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.