PCI DSS

PCI DSS 4.0: what changed

Version 3.2.1 retired in 2024 and the last of the new requirements became mandatory in 2025. Here is what is different and what to check first.
Certifyi compliance team · Updated September 2026
Short answer. PCI DSS 4.0 was published in March 2022 and became the only active version when 3.2.1 was retired on 31 March 2024. Version 4.0.1, a clarification release, followed in June 2024. The twelve requirements keep their structure, but 4.0 adds a customized approach as an alternative to defined controls, requires targeted risk analyses to justify control frequencies, extends multi-factor authentication to all access to the cardholder data environment, adds management of payment-page scripts, strengthens password rules to 12 characters, and made 51 future-dated requirements mandatory on 31 March 2025.

The twelve requirements, unchanged in shape

The standard still runs from installing network security controls (1) through secure configurations (2), protecting stored account data (3) and data in transit (4), malware protection (5), secure systems and software (6), access restriction (7), identification and authentication (8), physical access (9), logging and monitoring (10), testing (11) and organisational policies (12). What changed is inside them.

The biggest changes

Who does what: SAQ, ROC and levels

Merchant levelTransactions per year (typical)Validation
Level 1Over 6 millionAnnual Report on Compliance by a QSA or internal auditor; quarterly ASV scans
Level 21 to 6 millionAnnual SAQ; quarterly ASV scans
Level 320,000 to 1 million e-commerceAnnual SAQ; quarterly ASV scans
Level 4Fewer than 20,000 e-commerce or up to 1 million totalAnnual SAQ; ASV scans as required by the acquirer
Service providersLevels set by the card brandsLevel 1 requires a ROC by a QSA

Where SaaS companies get caught

Most SaaS companies outsource card handling to a payment processor and believe PCI does not apply. It still does: you complete an SAQ A or SAQ A-EP depending on how the payment page is delivered, and 4.0 added script-management and change-detection requirements to SAQ A for e-commerce merchants that redirect to or embed a processor’s page. If your checkout embeds an iframe or loads the processor’s JavaScript, inventory and protect that page.

How Certifyi maps PCI DSS

PCI DSS 4.0.1 is one of the frameworks on the shared control library. MFA, logging, vulnerability management, change control and access reviews are the same controls SOC 2 and ISO 27001 already test, so a company with either can usually evidence most of an SAQ from existing collection. The targeted risk analyses live in the risk register, and the QSA works in the Auditor Workspace.

PCI DSS 4.0, answered

No. It is a contractual standard enforced by the card brands through acquiring banks. Non-compliance leads to fines from the acquirer and, after a breach, liability for card reissuance and fraud.

Yes, but a reduced scope. Most SaaS merchants complete SAQ A or SAQ A-EP annually and keep the payment page and its scripts protected.

Version 4.0.1 corrected errors and clarified wording without adding or removing requirements. It is the current version.

At least annually and after significant changes, covering the CDE perimeter and critical systems, plus segmentation testing every six months for service providers.

Get audit-ready in 8 to 12 weeks

Certifyi pairs the platform with a named compliance lead who implements with your team, priced on scope and due at audit sign-off.
Scroll to Top