PCI DSS
PCI DSS 4.0: what changed
Version 3.2.1 retired in 2024 and the last of the new requirements became mandatory in 2025. Here is what is different and what to check first.
Certifyi compliance team · Updated September 2026
Short answer. PCI DSS 4.0 was published in March 2022 and became the only active version when 3.2.1 was retired on 31 March 2024. Version 4.0.1, a clarification release, followed in June 2024. The twelve requirements keep their structure, but 4.0 adds a customized approach as an alternative to defined controls, requires targeted risk analyses to justify control frequencies, extends multi-factor authentication to all access to the cardholder data environment, adds management of payment-page scripts, strengthens password rules to 12 characters, and made 51 future-dated requirements mandatory on 31 March 2025.
The twelve requirements, unchanged in shape
The standard still runs from installing network security controls (1) through secure configurations (2), protecting stored account data (3) and data in transit (4), malware protection (5), secure systems and software (6), access restriction (7), identification and authentication (8), physical access (9), logging and monitoring (10), testing (11) and organisational policies (12). What changed is inside them.
The biggest changes
- Customized approach: for any requirement you may design your own control that meets the stated objective, documented with a targeted risk analysis and tested by the assessor. The defined approach remains the default.
- Targeted risk analysis (12.3.1): where a requirement says “periodically”, you now decide the frequency through a documented risk analysis, reviewed at least yearly.
- MFA everywhere in the CDE (8.4.2): multi-factor authentication for all access into the cardholder data environment, not only administrators and remote users.
- Payment page scripts (6.4.3) and change detection (11.6.1): inventory, authorise and verify scripts on payment pages; detect unauthorised changes to HTTP headers and page content.
- Passwords: minimum 12 characters (or 8 if the system cannot support 12), with checks against known-bad passwords.
- Anti-phishing (5.4.1): mechanisms to detect and protect personnel from phishing attacks.
- Roles and responsibilities: documented for every requirement, not only at the programme level.
- Automated log review (10.4.1.1) and detection of failures in critical security controls.
Who does what: SAQ, ROC and levels
| Merchant level | Transactions per year (typical) | Validation |
|---|---|---|
| Level 1 | Over 6 million | Annual Report on Compliance by a QSA or internal auditor; quarterly ASV scans |
| Level 2 | 1 to 6 million | Annual SAQ; quarterly ASV scans |
| Level 3 | 20,000 to 1 million e-commerce | Annual SAQ; quarterly ASV scans |
| Level 4 | Fewer than 20,000 e-commerce or up to 1 million total | Annual SAQ; ASV scans as required by the acquirer |
| Service providers | Levels set by the card brands | Level 1 requires a ROC by a QSA |
Where SaaS companies get caught
Most SaaS companies outsource card handling to a payment processor and believe PCI does not apply. It still does: you complete an SAQ A or SAQ A-EP depending on how the payment page is delivered, and 4.0 added script-management and change-detection requirements to SAQ A for e-commerce merchants that redirect to or embed a processor’s page. If your checkout embeds an iframe or loads the processor’s JavaScript, inventory and protect that page.
How Certifyi maps PCI DSS
PCI DSS 4.0.1 is one of the frameworks on the shared control library. MFA, logging, vulnerability management, change control and access reviews are the same controls SOC 2 and ISO 27001 already test, so a company with either can usually evidence most of an SAQ from existing collection. The targeted risk analyses live in the risk register, and the QSA works in the Auditor Workspace.
PCI DSS 4.0, answered
Is PCI DSS a law?
No. It is a contractual standard enforced by the card brands through acquiring banks. Non-compliance leads to fines from the acquirer and, after a breach, liability for card reissuance and fraud.
Do we need PCI if we use Stripe or a similar processor?
Yes, but a reduced scope. Most SaaS merchants complete SAQ A or SAQ A-EP annually and keep the payment page and its scripts protected.
What is the difference between 4.0 and 4.0.1?
Version 4.0.1 corrected errors and clarified wording without adding or removing requirements. It is the current version.
How often are penetration tests required?
At least annually and after significant changes, covering the CDE perimeter and critical systems, plus segmentation testing every six months for service providers.
Get audit-ready in 8 to 12 weeks
Certifyi pairs the platform with a named compliance lead who implements with your team, priced on scope and due at audit sign-off.