When is PCI DSS 4.0 Required? Timing & Helpful Considerations
Blog post from Basis Theory
PCI DSS 4, released in March 2022, updates the payment-card security standard with roughly 60 new requirements addressing evolving threats, including stronger authentication and password policies, malware protections, web application defenses, encryption, and account reviews. Organizations could assess against either PCI DSS 3.2.1 or version 4 until March 2024, after which PCI DSS 4 became the required standard for non-future-dated requirements, while certain future-dated controls, such as web application firewalls and removable-media malware scanning, had a March 2025 implementation deadline. Transition timelines vary according to an organization’s PCI level and transaction volume, whether it stores, processes, or transmits cardholder data directly, the complexity and age of its systems, available budget, use of prescribed versus customized controls, and reliance on payment service providers or tokenization vendors. Businesses that outsource card-data handling can reduce their compliance scope by relying on a provider’s certified environment, whereas companies with in-house cardholder-data systems may need more extensive technical changes, testing, documentation, and assessment work.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.