ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

A new version of PCI DSS published to secure evolving payments ecosystem

The PCI Security Standards Council (PCI SSC), the global payment security forum, has published a new version of the PCI Data Security Standard (PCI DSS) on Thursday to secure the globally evolving payments ecosystem and avail new overall flexibility. Notably, according to a Verizon study released in 2020, PCI DSS compliance has dropped by 28% since 2016.

 

Version 4.0 of the standard establishes a baseline of technical and operational requirements to improve payment security, and it will supersede version 3.2.1 to combat new threats and technologies.

 

Furthermore, the updates enable novel approaches to combating new threats. According to PCI SCC, the changes were prompted by feedback from the global payments industry over the last three years, encompassing over 6000 items from over 200 organizations.

 

The current version, v3.2.1, will remain active until March 31, 2024. This will give relevant organizations enough time to learn about version 4.0 and implement the changes.

 

Among the variations involved in PCI DSS v4.0 are:

 

  • Updated firewall terminology to network security controls to support a broad range of technologies.
  • Expansion of Requirement 8 includes multi-factor authentication (MFA) for all access to the cardholder data environment.
  • Increased flexibility for organizations to demonstrate how they use different methods to achieve security objectives.
  • New targeting risk analyses will allow organizations to choose how often they perform certain activities based on their business needs and risk exposure.

 

PCI DSS v4.0 is more responsive to the dynamic nature of payments and the threat environment, said PCI SSC’s standards officer Emma Sutcliffe. Version 4.0 reinforces core security principles while allowing for more flexibility in technology implementations.

 

PCI SCC has published several supporting documents alongside the updated standard in the PCI SSC Document Library, including the Summary of Changes from PCI DSS v3.2.1 to v4.0, the v4.0 Report on Compliance (ROC) Template, ROC Attestations of Compliance (AOC) and ROC Frequently Asked Questions. The Self-Assessment Questionnaires (SAQs) will be published in the coming weeks.


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543