AuditXYZ

Compliance Framework

Payment Card Industry Data Security Standard v4.0 (PCI DSS)

PCI DSS v4.0 is the global standard for protecting payment card data. This guide covers all 12 requirements, merchant levels, SAQ types, cost breakdowns, and the transition from v3.2.1 to v4.0.

$15,000–$500,0003–12 monthsAudit Required4.0.1
Issuing BodyPCI Security Standards Council
First Published2004-12-15
Latest Version4.0.1
Typical Cost$15,000–$500,000
Typical Timeline3–12 months
Audit RequiredYes
Audit FrequencyAnnual assessment required. Level 1 merchants require on-site QSA audit; Levels 2-4 may self-assess with SAQ.
Geographyglobal

PCI DSS v4.0: The Complete Guide

The Payment Card Industry Data Security Standard (PCI DSS) is the mandatory security standard for any organization that stores, processes, or transmits payment card data. Version 4.0.1, the current release, represents the most significant update in the standard's history — introducing a customized approach to validation and strengthening requirements for authentication, encryption, and web-based attack detection. All future-dated requirements in v4.0.1 became mandatory in March 2025.

What PCI DSS Is and Who Issues It

PCI DSS is issued and maintained by the PCI Security Standards Council (PCI SSC), a global forum founded jointly by American Express, Discover, JCB, Mastercard, and Visa. The Council publishes the standard and manages the ecosystem of Qualified Security Assessors (QSAs), Approved Scanning Vendors (ASVs), and Internal Security Assessors (ISAs). Compliance enforcement, however, is carried out by the payment brands and acquiring banks — not the Council itself.

The standard first appeared in 2004, consolidating separate card brand programs. Version 4.0 launched in March 2022, with v4.0.1 released in June 2024 to address errata. The March 2025 deadline meant organizations had approximately three years to implement all new requirements, including those that were previously marked as best practices.

Who Must Comply

Every entity in the payment chain must comply: merchants, payment processors, acquirers, issuers, and service providers. The scope of compliance is determined by your role in the payment ecosystem and the volume of transactions you handle annually.

Merchant levels determine the depth of assessment required:

  • Level 1: Over 6 million transactions annually — requires an on-site assessment by a QSA and quarterly network scans by an ASV
  • Level 2: 1 million to 6 million transactions — may self-assess using a Self-Assessment Questionnaire (SAQ) or opt for a QSA-led assessment
  • Level 3: 20,000 to 1 million e-commerce transactions — SAQ required
  • Level 4: Under 20,000 e-commerce transactions or up to 1 million other transactions — SAQ typically required at the acquiring bank's discretion

Service providers have their own tier structure. Level 1 service providers (those processing over 300,000 transactions) require annual QSA assessments and quarterly scans.

The 12 Requirements Explained in Depth

PCI DSS v4.0.1 organizes its controls into 12 requirements across six goals:

Build and Maintain a Secure Network and Systems

  • Requirement 1 mandates network security controls — firewalls, routers, and related infrastructure configured to restrict unauthorized traffic into and out of the cardholder data environment (CDE). v4.0 updated language from "firewalls and routers" to the broader "network security controls" to accommodate modern architectures including cloud and zero-trust environments.
  • Requirement 2 requires that vendor default passwords and settings are changed before any system is placed in production. The customized approach allows organizations to meet the objective through alternative controls with documented rationale.

Protect Account Data

  • Requirement 3 governs stored account data, limiting what may be stored, requiring strong cryptography for stored PANs, and prohibiting retention of sensitive authentication data post-authorization. v4.0 strengthened key management requirements and added an inventory requirement for all locations where account data is stored.
  • Requirement 4 requires encryption of cardholder data transmitted over open, public networks. v4.0 added a requirement to maintain an inventory of trusted certificates.

Maintain a Vulnerability Management Program

  • Requirement 5 addresses anti-malware controls, now extending beyond traditional malware to cover all types of malicious software. v4.0 added requirements for periodic evaluations of systems not commonly affected by malware.
  • Requirement 6 covers secure systems development, requiring vulnerability management, security patch processes, and — one of the most significant v4.0 additions — automated technical controls to detect and prevent web-based attacks on public-facing web applications, such as web application firewalls or detection solutions.

Implement Strong Access Control Measures

  • Requirement 7 enforces access control based on business need-to-know, with access restricted to the minimum necessary.
  • Requirement 8 governs user identification and authentication. v4.0 mandated MFA for all access to the CDE (not just remote access), increased minimum password lengths to 12 characters, and introduced phishing-resistant authentication requirements for certain scenarios.
  • Requirement 9 addresses physical access to cardholder data and systems, including controls over point-of-interaction (POI) devices.

Regularly Monitor and Test Networks

  • Requirement 10 requires logging and monitoring of all access to system components and cardholder data. v4.0 added requirements for automated log review mechanisms.
  • Requirement 11 mandates regular security testing, including quarterly vulnerability scans, annual penetration testing, and — new in v4.0 — targeted risk analysis to determine penetration testing frequency.

Maintain an Information Security Policy

  • Requirement 12 requires organizations to document, publish, and maintain information security policies and a comprehensive security awareness program. The v4.0 addition of a targeted risk analysis process for several flexible requirements fundamentally changed how organizations approach compliance decisions.

The v4.0.1 Customized Approach

One of v4.0's landmark innovations is the customized approach, an alternative to the traditional defined approach. Under the customized approach, an organization may implement controls that differ from those specified in PCI DSS requirements — provided they demonstrate through rigorous testing and documentation that the security objective is met or exceeded. This gives large, sophisticated organizations more flexibility while maintaining security outcomes. The defined approach remains available and is the recommended choice for most organizations.

Audit and Assessment Process

The assessment process depends on your merchant level and the applicable SAQ type:

SAQ TypeWho It Applies ToApproximate Control Count
SAQ ACard-not-present merchants outsourcing all cardholder functions22 requirements
SAQ A-EPE-commerce merchants with payment page redirects191 requirements
SAQ BMerchants with imprint machines or standalone dial-out terminals41 requirements
SAQ DAll other merchants not in other SAQ categories329 requirements

Level 1 merchants undergo a Report on Compliance (RoC) prepared by a QSA. The QSA conducts document review, interviews, and technical testing across the full 12 requirements. Service providers at Level 1 similarly require a RoC and quarterly scans.

All merchants must also complete an Attestation of Compliance (AoC) confirming their compliance status to acquiring banks and payment brands.

Costs and Timeline

Organization TypeTypical TimelineEstimated Cost Range
Level 4 merchant, SAQ A3–4 months$15,000–$30,000
Level 3 merchant, SAQ D6–9 months$50,000–$150,000
Level 1 merchant, RoC9–12 months$200,000–$500,000
Service provider, Level 16–12 months$100,000–$400,000

Ongoing annual costs include quarterly ASV scans ($2,000–$8,000), annual penetration testing ($15,000–$80,000), and QSA or SAQ renewal fees.

PCI DSS shares significant control overlap with other security frameworks, making simultaneous compliance more efficient:

  • ISO 27001 shares approximately 60% control overlap. Organizations with ISO 27001 certification will find many PCI DSS controls already addressed, particularly around risk management, access control, and incident response. However, PCI DSS is more prescriptive in payment-specific areas such as cardholder data handling and network segmentation.
  • SOC 2 shares roughly 55% overlap. SOC 2's Security trust service criterion aligns closely with PCI DSS network and access controls. Organizations pursuing both certifications benefit from shared evidence collection.
  • SWIFT CSP aligns with PCI DSS around network security, access management, and incident response for financial institutions. See the SWIFT CSP guide for details.
  • NIST CSF provides a risk-based overlay at approximately 50% overlap. Organizations using NIST CSF as a governance layer can map PCI DSS requirements into the CSF's identify, protect, detect, respond, and recover functions.

If your organization also handles health data, see the HIPAA guide for the intersection between PCI DSS payment security and protected health information requirements.

How Automation Helps

PCI DSS compliance involves hundreds of controls, continuous monitoring obligations, and annual evidence collection — a significant burden without automation. Compliance automation platforms accelerate PCI DSS programs in several ways:

  • Automated evidence collection from cloud providers (AWS, Azure, GCP) maps infrastructure configurations directly to PCI DSS requirements
  • Continuous control monitoring flags configuration drift before it becomes a finding
  • Policy management features maintain version-controlled documentation aligned to requirement 12
  • Vendor risk workflows track the compliance status of service providers and third-party processors

LowerPlane is an AI-powered compliance automation platform supporting 50-plus frameworks including PCI DSS v4.0.1, SOC 2, and HIPAA. Starting at $4,000 per year with a free tier available, LowerPlane is rated 9.4/10 on AuditXYZ. Organizations using LowerPlane for PCI DSS report reducing evidence collection time by 60–70%, freeing QSAs and internal teams to focus on remediation rather than paperwork. See the compliance automation comparison for a full platform evaluation. For fintech companies building payment infrastructure, the fintech compliance guide covers the full regulatory stack.

Frequently Asked Questions

What does PCI DSS compliance actually mean — does it guarantee security?

PCI DSS compliance means your organization has passed an assessment demonstrating that your controls met the standard's requirements at a point in time. It does not guarantee you will never experience a breach. The standard explicitly states that compliance is not a security guarantee. However, organizations that consistently meet PCI DSS requirements have substantially lower breach rates than non-compliant entities. Compliance is the floor, not the ceiling.

How do I reduce my PCI DSS scope?

Scope reduction is the most impactful thing most organizations can do. Strategies include: using a hosted payment page or iframe (which removes your web servers from scope), tokenizing card data so raw PANs never touch your systems, segmenting your cardholder data environment from the rest of your network, and using point-to-point encryption (P2PE) solutions at physical payment terminals. Each approach can dramatically reduce the number of systems in scope and the controls you need to validate.

Is PCI DSS a legal requirement?

PCI DSS is a contractual requirement imposed by payment brands through merchant agreements with acquiring banks. It is not a law in most jurisdictions. However, some US states reference PCI DSS in their data breach laws, and non-compliance that leads to a breach can result in significant fines from payment brands, termination of card acceptance privileges, and civil liability.

What changed in PCI DSS v4.0.1 that is now mandatory?

The most significant requirements that became mandatory in March 2025 include: MFA for all access into the CDE (Requirement 8.4.2), automated detection and prevention of web-based attacks on public-facing applications (Requirement 6.4.2), automated log review mechanisms (Requirement 10.4.2), and targeted risk analyses documenting the rationale for assessment frequencies (Requirement 12.3). Organizations that had not implemented these as best practices faced a compliance gap from March 2025.

How often do I need to reassess?

Full assessments are annual. Additionally, organizations must conduct quarterly vulnerability scans by an ASV, quarterly internal vulnerability scans, and annual penetration testing. Any significant change to the CDE — such as adding new systems, changing network topology, or onboarding a new payment application — may trigger an interim assessment or scope review.

Request a PCI DSS consultation

Step 1 of 520%

Which framework do you need?

Framework Mappings

Overlap with other frameworks

ISO 27001Medium60%
SOC 2Medium55%
NIST CSFMedium50%

Related frameworks

Get matched with a PCI DSS auditor in 24 hours

Free, no-obligation — just tell us your email and we'll do the rest.

By submitting, you agree to our privacy policy.