PCI DSS 4.0: What Changed and the Deadlines
PCI DSS version 4.0 was released in March 2022 and is now the active standard, with a minor 4.0.1 revision published in 2024. It is the biggest update the standard has had in years.
The headline changes
A new customised approach lets mature organisations meet the intent of a requirement with their own controls, validated by their assessor, rather than following the prescriptive method.
Stronger authentication requirements, including expanded multi-factor authentication and updated password rules.
More emphasis on continuous security as business-as-usual, rather than a once-a-year scramble.
The key dates
PCI DSS v3.2.1 was retired on 31 March 2024, making v4.0 the only active version.
A set of future-dated v4.0 requirements became mandatory on 31 March 2025, giving organisations time to implement the more demanding new controls.
What it means for you
If you have not already, map your controls to v4.0 and confirm the future-dated requirements are now in place. Compliance automation platforms have updated their frameworks to v4.0, which makes the mapping far easier.
PCI DSS policy templates
Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.
Automate PCI DSS with Drata
Drata maps the controls, collects evidence automatically, and keeps you audit-ready. Automated, continuous compliance with deep integrations.
FAQ
- Is PCI DSS 4.0 mandatory now?
- Yes. v3.2.1 was retired on 31 March 2024, and the future-dated v4.0 requirements became mandatory on 31 March 2025.
- What is the customised approach?
- A v4.0 option that lets you meet a requirement’s intent with your own controls, validated by your assessor, instead of the prescriptive defined approach.