PCI DSS v4.0: Key Changes and What They Mean for Your Organization
Back to Insights
PhishingComplianceFirewall

PCI DSS v4.0: Key Changes and What They Mean for Your Organization

July 6, 20263 Min Read

PCI DSS v4.0 Is Now the Only Version

As of March 31, 2024, PCI DSS v3.2.1 has been officially retired. Any organization that processes, stores, or transmits cardholder data must now comply with PCI DSS v4.0 — or face significant consequences including fines, increased transaction fees, and potential loss of the ability to process card payments.

For organizations in Bangladesh's growing fintech and e-commerce sectors, understanding these changes is critical.

Major Changes in PCI DSS v4.0

1. Customized Implementation Approach

PCI DSS v4.0 introduces a "Customized Approach" alongside the traditional "Defined Approach." The Customized Approach allows organizations to design their own controls to meet the intent of a requirement — providing flexibility for innovative security solutions that may not fit the prescriptive controls of the Defined Approach.

Implication: Organizations with major security programs can now demonstrate compliance through compensating controls that better reflect their actual risk environment.

2. Enhanced Authentication Requirements (Req. 8)

  • Multi-Factor Authentication (MFA) is now required for ALL access into the cardholder data environment (CDE) — not just remote access.
  • Passwords must be at least 12 characters (up from 7) for systems not using MFA.
  • Service accounts must have their credentials reviewed periodically.

3. New Requirements for Targeted Risk Analysis

Many requirements now explicitly require organizations to conduct a Targeted Risk Analysis (TRA) to justify their chosen approach and frequency of security activities. This replaces the blanket prescriptive timeframes with risk-based decision-making.

4. Software Security (Req. 6)

  • New requirements for managing software security throughout the development lifecycle
  • Web Application Firewalls (WAF) or automated technical solutions are now required for public-facing web applications
  • API security is explicitly called out for the first time

5. Phishing-Resistant Authentication

For requirements targeting phishing attacks, v4.0 encourages phishing-resistant authentication mechanisms (FIDO2/WebAuthn) as a best practice moving toward mandatory controls.

6. E-Commerce and Payment Page Security (Req. 6.4)

New requirements specifically address the security of payment pages, including:

  • Inventorying all scripts loaded on payment pages
  • Implementing Content Security Policy (CSP) headers
  • Regularly reviewing the integrity of scripts loaded from third-party sources

Key Dates

  • March 31, 2024: PCI DSS v3.2.1 retired. V4.0 is the only valid version.
  • March 31, 2025: All "future-dated" requirements from PCI DSS v4.0 become mandatory.

Steps to Achieve Compliance

  1. Conduct a gap analysis against PCI DSS v4.0 requirements
  2. Define your cardholder data environment scope accurately
  3. Implement enhanced MFA across all CDE access
  4. Conduct Targeted Risk Analyses for applicable requirements
  5. Update your security policies and procedures
  6. Engage a Qualified Security Assessor (QSA) for your Report on Compliance (ROC)

Conclusion

PCI DSS v4.0 represents a mature evolution of the standard — moving from checkbox compliance toward genuine risk management. Organizations that embrace this shift will be better positioned for compliance and better protected against the real threats facing payment environments.

Oberon's compliance team specializes in PCI DSS readiness assessments and remediation support.