💳 PCI DSS v4.0

PCI DSS v4.0 Reference

SAQ type selector, all 12 requirements, key changes from v3.2.1, customised approach, and compliance checklist for Indian fintech and merchants.

PCI DSS v4.0 — Key Facts

ItemDetail
Current versionPCI DSS v4.0 — published March 2022
v3.2.1 retirementv3.2.1 retired 31 March 2024 — v4.0 is now the only active standard
New future-dated requirements64 new requirements in v4.0 were \"best practice\" until 31 March 2025, after which they became mandatory
Who must complyAny organisation that stores, processes, or transmits cardholder data (CHD) — merchants, service providers, payment gateways, acquirers
India contextAll RBI-regulated payment aggregators, payment gateways, acquiring banks, and merchants above thresholds must comply. NPCI mandates PCI DSS for UPI apps handling card data
Compliance validationAnnual self-assessment (SAQ) or audit by a Qualified Security Assessor (QSA) depending on transaction volume
Merchant levelsLevel 1: >6M transactions/year → QSA audit required. Levels 2–4: lower volumes → SAQ typically acceptable
Service provider levelsLevel 1: >300K transactions/year. Level 2: less than 300K — different SAQ required

Two compliance approaches in v4.0

Defined Approach
Follow every specific requirement exactly as written. Most common approach. Straightforward to validate — auditor checks each requirement.
Customised Approach
New in v4.0. Demonstrate you meet the security objective of each requirement through alternative controls. Requires documented methodology and is assessed by QSA only. Gives more flexibility for modern architectures.

SAQ Type Selector

Answer the questions below to identify which Self-Assessment Questionnaire applies to your organisation. If in doubt, consult your acquirer or a QSA.

SAQ Types Reference

SAQWho it applies toControls
SAQ ACard-not-present merchants fully outsourcing to a PCI-compliant third party. No electronic CHD storage. Includes redirect and iframe.~13 requirements. Simplest SAQ.
SAQ A-EPE-commerce merchants using third-party JS (Stripe Elements, Braintree). Your site loads the JS but card data goes direct to PSP.~190 requirements. More comprehensive than SAQ A.
SAQ BMerchants using imprinters or standalone dial-out terminals only. Very rare today.~41 requirements.
SAQ B-IPMerchants using standalone IP-connected terminals not storing CHD.~83 requirements.
SAQ CMerchants with payment application systems connected to internet. Not storing CHD.~158 requirements.
SAQ C-VTMerchants entering card data via isolated virtual terminals on a dedicated PC.~83 requirements.
SAQ D (Merchant)All other merchants not covered by A, A-EP, B, B-IP, C, or C-VT. Storing or processing CHD directly.All 12 requirements — most comprehensive.
SAQ D (Service Provider)Service providers storing, processing, or transmitting CHD.All 12 requirements + additional service provider requirements.

All 12 PCI DSS v4.0 Requirements

Build & Maintain Secure Networks

Req 1 Build and maintain a secure network and systems
Req 2 Do not use vendor-supplied defaults for system passwords and other security parameters

Protect Account Data

Req 3 Protect stored account data
Req 4 Protect cardholder data with strong cryptography during transmission

Maintain a Vulnerability Management Program

Req 5 Protect all systems and networks from malicious software
Req 6 Develop and maintain secure systems and software

Implement Strong Access Control Measures

Req 7 Restrict access to system components and cardholder data by business need-to-know
Req 8 Identify users and authenticate access to system components
Req 9 Restrict physical access to cardholder data

Regularly Monitor and Test Networks

Req 10 Log and monitor all access to system components and cardholder data
Req 11 Test security of systems and networks regularly

Maintain an Information Security Policy

Req 12 Support information security with organisational policies and programs

Key Changes from PCI DSS v3.2.1 → v4.0

Change AreaWhat changedEffective
Customised Approach New option to demonstrate security objective equivalence via alternative controls instead of following requirements verbatim. Requires QSA validation. 31 March 2024
Multi-factor Authentication (MFA) MFA now required for ALL access into the cardholder data environment (CDE) — not just remote access. Includes administrators accessing from within the internal network. 31 March 2025
Password requirements Minimum 12-character passwords (up from 8). Password change required if compromise suspected — but periodic forced changes no longer mandatory if MFA is in place. 31 March 2025
Anti-phishing controls Requirement 5.4.1: anti-phishing mechanisms in place — this includes email filtering, URL filtering, and user training. New explicit requirement. 31 March 2025
Targeted risk analysis Many requirements now allow timing/frequency to be set based on a documented targeted risk analysis rather than fixed intervals. 31 March 2024
E-commerce / skimming prevention Requirement 6.4.3/11.6.1: payment page scripts inventoried and authorised. HTTP headers monitored for unauthorised modifications. Specifically targets Magecart/skimming attacks. 31 March 2025
Pen test scoping Clarified that internal and external penetration testing must cover the full CDE boundary, not just a sample. 31 March 2024
Audit log protection 10.3.3: audit logs protected from destruction and modifications by all users including admins. Immutable log storage required. 31 March 2025
Encryption of CHD at rest Req 3 restructured — clearer requirements on protecting stored account data. Primary Account Number (PAN) must be rendered unreadable wherever stored. 31 March 2024
Roles and responsibilities Each requirement now explicitly states who is responsible — clearer accountability across the organisation. 31 March 2024

PCI DSS v4.0 Compliance Checklist — Key Controls

Network Security
Data Protection
Access Control
Vulnerability Management
Monitoring & Logging
Policies & Governance