PCI 4.0 Updated Requirements: What This Means for Merchants
Blog post from Basis Theory
PCI DSS 4.0 is a major revision of the global card-data security standard for merchants and service providers that store, process, transmit, or can affect the security of payment card information, replacing PCI DSS 3.2.1 after March 31, 2024. The update broadens several traditional concepts, such as firewalls to network security controls and antivirus to anti-malware, while introducing stronger requirements for secure configurations, encryption, certificate and key management, multi-factor authentication, password practices, account reviews, secure software development, payment-page script monitoring, logging, vulnerability scanning, penetration testing, incident response, and security awareness. It also places greater emphasis on documented roles and responsibilities, targeted risk analyses, periodic scope validation, and continuous reviews of cryptographic technologies and security controls. The described changes assign responsibilities variously to merchants, Basis Theory, or both, though applicability varies by merchant environment and Self-Assessment Questionnaire type; organizations are advised to consult a Qualified Security Assessor for use-case-specific guidance.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.