
The PCI Security Standards Council (PCI SSC), the global payment security forum, has published a new version of the PCI Data Security Standard (PCI DSS) on Thursday to secure the globally evolving payments ecosystem and avail new overall flexibility. Notably, according to a Verizon study released in 2020, PCI DSS compliance has dropped by 28% since 2016.
Version 4.0 of the standard establishes a baseline of technical and operational requirements to improve payment security, and it will supersede version 3.2.1 to combat new threats and technologies.
Furthermore, the updates enable novel approaches to combating new threats. According to PCI SCC, the changes were prompted by feedback from the global payments industry over the last three years, encompassing over 6000 items from over 200 organizations.
The current version, v3.2.1, will remain active until March 31, 2024. This will give relevant organizations enough time to learn about version 4.0 and implement the changes.
Among the variations involved in PCI DSS v4.0 are:
PCI DSS v4.0 is more responsive to the dynamic nature of payments and the threat environment, said PCI SSC’s standards officer Emma Sutcliffe. Version 4.0 reinforces core security principles while allowing for more flexibility in technology implementations.
PCI SCC has published several supporting documents alongside the updated standard in the PCI SSC Document Library, including the Summary of Changes from PCI DSS v3.2.1 to v4.0, the v4.0 Report on Compliance (ROC) Template, ROC Attestations of Compliance (AOC) and ROC Frequently Asked Questions. The Self-Assessment Questionnaires (SAQs) will be published in the coming weeks.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543