PCI DSS 4.0.1, released in June 2024, is a limited update to version 4.0, focusing on clarifying existing requirements, correcting minor errors, and providing additional guidance. It’s crucial for businesses to understand these updates to maintain compliance and ensure the ongoing security of payment card data. This article details the key changes introduced in 4.0.1.
Let’s dive in. 🙂
Here we go!
What is PCI DSS v4.0.1 from the PCI Security Standards Council?
PCI DSS 4.0.1 is a limited update to PCI DSS 4.0. It does not introduce any new requirements or remove existing ones. Instead, it clarifies the intent of existing requirements, corrects minor errors, and provides additional guidance to help organizations implement the standard effectively. The compliance deadline for these updates remains March 31, 2025.
The effective date for the new requirements remains March 31, 2025, irrespective of the limited revision.
For a comprehensive overview of PCI DSS v4.0 and its foundational requirements, refer to our guide on PCI DSS v4.0.
The PCI DSS v4.0.1 key changes include:
Corrections: It corrects the issues and typographical errors that have been present in PCI DSS v4.0.
Clarifications: It provides additional guidance on specific requirements, making it easier for organisations to interpret and implement the standards effectively.
When was PCI DSS 4.0.1 released?
PCI DSS 4.0.1 was released on June 11, 2024. Updated Report on Compliance (ROC) templates, Attestations of Compliance (AOCs), Self-Assessment Questionnaires (SAQs), and supporting documentation are expected to be released soon.
What changes were made from PCI DSS v4.0 to 4.0.1?
Purpose clarification
The first major change in 4.0.1 is the addition of the purpose section, which was not present in the last version. The newly added purpose clearly explains the intent of all the requirements so that organisations can accurately interpret the required elements and implement necessary controls accordingly. It also reduces the complexity that could have led to misconceptions or incomplete compliance.
Requirement 3 – Enhancing sensitive data storage
Requirement 3 of PCI DSS 4.0.1 explains that storing Sensitive Authentication Data (SAD) must justify the legitimate business need to ensure that sensitive information and stored account data are only retained when necessary. Additionally, the applicability notes have been added to redefine storage conditions. This brings business attention to understanding which scenarios of sensitive authentication data can be stored in non-persistent memory to ensure secure and effective temporary storage.
Last but not least, requirement 3.5 has now been rephrased to render primary account numbers unreadable. It will encourage organisations to implement protective measures like keyed cryptographic hashes to enhance data security beyond basic encryption methods.
💡 It affects: Companies that support issuing services meaning financial institutions like banks, credit unions or other card issuers that generate and distribute cards to consumers.
Revised data and certificate management
In requirement 4, the self-signed certificate reference is no more, and an applicability note about receiving cardholder data via unsolicited channels has been moved to a new subsection.
Moreover, a good practice section has been introduced to enhance the guidance on acceptable use policies for managing end-user technologies.
Redefined automated security mechanism
The new update removes the applicability note about the automated mechanism in requirement 5.4.1 of v4.0 to clarify that it does not apply to the system providing the mechanism.
This important update also highlights that the PCI DSS generally applies to systems that manage payment or payment processing.
Revamped vulnerability management and third party service providers
The PCI DSS 4.0.1 update in requirement 6 clarifies that vulnerability scans are meant to complement security compliance requirements outlined in PCI DSS v4.0 11.3.1 and 11.3.2. Requirement 12.8 specifically looks into how to manage relationships between host organisations and their third party service providers. Merchants are responsible for the script running on their own pages, while the third party service provider (TPSP) is responsible for scripts running in iframes on the consumer browser. Third-party service providers (TPSPs) must support their customers’ requests for information about the TPSP’s PCI DSS compliance status.
Requirement 6 of PCI DSS v4.0.1 states that only critical vulnerabilities must have updates installed within 30 days.
Clarification in Requirement 6.4.3 states that merchants are responsible for the scripts running on their parent pages, not those executed in third-party service provider iframes.
Requirement 8 of PCI DSS v4.0.1 clarifies that MFA does not apply to user accounts authenticated with phishing-resistant authentication factors.
Moreover, applicability notes have been added to explain how these payment pages scripts apply to both an entity’s web pages and third party service providers or payment processors’ embedded payment forms. Additionally, a few good practices related to PAN storage in pre-production environments have been removed, and some are updated for more clarification.
Cyber attacks are not a matter of if, but when. Be prepared.
Box-ticking approach to penetration tests is long gone. We help you identify, analyse and remediate vulnerabilities so you don’t see the same pentest report next time.
Redefined authentication and access controls
The overview and applicability notes have been revised in PCI DSS v4.0.1 requirement 8. Additionally, certain terminology in the customised approach sample templates has been changed to align with industry standards, specifically changing “account” to “ID” to refer to “group, shared, or generic IDs.”
Clarifications now recognise multi-factor authentication (MFA) as a best practice for non-console administrative access, particularly outside the Cardholder Data Environment (CDE). Additionally, definitions for potential attack vectors, such as replay attacks, have been added, and corresponding protective security measures against these attacks, such as the use of phishing-resistant authentication factors, have become mandatory.
Strengthened physical security protocols
The update focuses on advising businesses to identify sensitive areas in their environment to ensure appropriate physical security controls are implemented. The PCI DSS v4.0.1 also clarifies that certain requirements in 9.2.1 do not apply to locations that are publicly accessible by cardholders (i.e., consumers).
Furthermore, clarification has been added to refer to visitor logs for tracking visitor activity both within the facility and in sensitive areas. Lastly, applicability notes have also been included to guide which types of devices are not covered by the requirements in 9.5.1.
Improved log monitoring and audit practices
The update provides guidance on establishing a baseline for audit activity and adds a reference to managing and interpreting log data. It also clarifies the 10.5.1 section to ensure businesses reliably monitor their environments and respond effectively to potential threats.
Wireless technology risk mitigation
An applicability note related to the use of unauthorised wireless technology has now been moved to the purpose section in requirement 11, where it clarifies that the requirements are now specific to critical or high-risk vulnerabilities. With reference to the PCI SSC’s ASV program guide, both internal and external vulnerability scans are now integrated into the vulnerability management process.
More requirements related to security-impacting HTTP headers and payment page content have been updated to enforce weekly reviews. Apart from this, organisations are now required to obtain complaint evidence from third-party service providers to acknowledge their detection mechanisms are not exhaustive.
All these new changes in PCI DSS v4.0.1 will ensure the organisation stays vigilant and has a structured approach to maintain secure systems.
Enhanced leadership roles
In the requirement 12 section, the new version adjusted the documentation terminologies for consistency while applicability notes further clarified the difference between agreement and acknowledgement and targeted risk analysis. It also removed common executive management titles from the purpose section and guidance to support information security measures.
It also stresses the need to maintain scoping documentation that has all system components included in cardholder data transmission, storage and processing.
Updating Appendices and getting rid of templates
In the appendices, the overview clauses have been updated from connections to payment gateways and processors to payment gateway and processor services offered within a shared environment. Appendix D has revised timeframes to align with Section 7, which outlines guidance for initial PCI DSS assessment.
References to PCI DSS v4.x sample templates have also been updated, leading users to the PCI SSC website instead of Appendix E.
Additionally, the wording for the customised approach has been redefined, highlighting the need for documentation by a QSA or ISA. Sample templates are also removed from Appendix E, with a note that they are now available on the PCI SSC website.
When does PCI DSS v4.0 retire?
PCI DSS v4.0 will retire on December 31, 2024, after which only PCI DSS v4.0.1 will remain in effect. It’s important to note that v4.0.1 does not bring any additional or removed requirements. Also, businesses must continue to follow the future-dated requirements of v4.0 and adjust their security measures accordingly to ensure PCI DSS compliance.
Author’s take
Since the new PCI DSS v4.0.1 does not introduce any new requirements or delete any previous ones, it will be easy for businesses to adapt to the new changes, which primarily aim to provide more guidance. Big enterprises and small to mid-sized businesses are being targeted for ransomware, reputational damage, and whatnot. Recently, Casio, a globally recognised company, suffered a data breach due to a ransomware attack. Therefore, every business handling payment information must stay updated with the PCI DSS v4.0.1 standard and comply with it.
Compliance is not just a regulatory check but a critical component to ensure business integrity and customers’ trust. With emerging threats, every payment-related business needs to embrace PCI DSS compliance and prioritise it as a fundamental business requirement rather than treating it as a mere checkbox for regulatory purposes.
Secure code is an essential element for business growth
Show your customers and supply chain you can manage application risks with secure coding practices.
Summary
If done right, the PCI DSS framework can reduce data breaches in the payment industry and overall security. The new changes in PCI 4.0.1 give businesses a more proactive approach with clear guidance and a secure system and protect sensitive info, especially cardholder data.
PCI DSS v4.0 is about to expire and businesses need to work with Qualified Security Assessors (QSAs) to get their valuable insights and guidance to transition to v4.0.1 smoothly.
At Cyphere, we assist businesses in achieving their goals by integrating security into their foundational processes.
Contact us to discuss PCI DSS assessment or any of your security compliance concerns
PCI DSS Compliance v4.0 FAQs
What is PCI DSS v4.0.1?
PCI DSS v4.0.1 is an update to PCI DSS v4.0, clarifying existing requirements and providing additional guidance. It doesn’t introduce new requirements. The compliance deadline is March 31, 2025.
What are the key changes in PCI DSS v4.0.1?
Key changes include clarifications to requirements related to data storage, certificate management, vulnerability scanning, third-party providers, authentication, physical security, and log monitoring. It also adds a “purpose” section to each requirement for better understanding.
How does PCI DSS v4.0.1 affect my business?
If you’re already compliant with v4.0, the transition should be smooth. Review the clarifications to ensure your practices align. A QSA can assist with the transition.
When is the PCI DSS v4.0.1 compliance deadline?
The compliance deadline for PCI DSS v4.0.1 is March 31, 2025. PCI DSS v4.0 retires December 31, 2024.




