Home / Companies / Basis Theory / Blog / Post Details
Content Deep Dive

PCI 4.0 Updated Requirements: What This Means for Merchants

Blog post from Basis Theory

Post Details
Company
Date Published
Author
Basis Theory
Word Count
1,862
Company Posts That Month
7
Language
English
Hacker News Points
-
Post removed?
No
Summary

PCI DSS 4.0 is a major revision of the global card-data security standard for merchants and service providers that store, process, transmit, or can affect the security of payment card information, replacing PCI DSS 3.2.1 after March 31, 2024. The update broadens several traditional concepts, such as firewalls to network security controls and antivirus to anti-malware, while introducing stronger requirements for secure configurations, encryption, certificate and key management, multi-factor authentication, password practices, account reviews, secure software development, payment-page script monitoring, logging, vulnerability scanning, penetration testing, incident response, and security awareness. It also places greater emphasis on documented roles and responsibilities, targeted risk analyses, periodic scope validation, and continuous reviews of cryptographic technologies and security controls. The described changes assign responsibilities variously to merchants, Basis Theory, or both, though applicability varies by merchant environment and Self-Assessment Questionnaire type; organizations are advised to consult a Qualified Security Assessor for use-case-specific guidance.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.