8 Things You Need to Know About PCI 4.0.1
PCI DSS Transition
The PCI Security Standards Council updated the Payment Card Industry Data Security Standard (PCI DSS) on March 31, 2022, introducing new rules to facilitate higher levels of security for cardholder data. As of March 31, 2025, PCI DSS 4.0.1 is in full effect, with the new controls being enforced in the latest round of compliance. Whether this is your first time getting compliant, or you are looking to renew your status, you must abide by the newly enforced controls.Here are the updated PCI 4.0.1 controls that have proved to be the biggest lift for organizations thus far:
- Strengthened Network Controls and Ruleset Reviews: PCI DSS 4.0.1 emphasizes the significance of network configurations and controls during ruleset reviews. Your organization must conduct these reviews every six months to verify the effectiveness and integrity of your network controls. By proactively reviewing and fine-tuning rulesets, you can better detect and respond to potential security vulnerabilities and intrusions, safeguarding cardholder data.
- Increased Clarity for Formal Roles and Responsibilities: Explicit definition, documentation, and assignment of roles and responsibilities are essential. This includes personnel approval to strengthen accountability and effective management of security controls.
- Continuous Control Monitoring and Scoping: PCI DSS 4.0.1 stresses the importance of periodically evaluating the operational effectiveness of security controls. This helps identify any potential weaknesses or gaps in security measures. Your organization must establish processes to verify that controls are functioning as intended and being monitored appropriately. Furthermore, scoping documents must be created and maintained annually, or if a significant change to the environment has occurred.
- Cryptography and Encryption: PCI DSS 4.0.1 introduces changes to cryptography and encryption. Formally, merchants were permitted to use disk-level encryption to protect any kind of nonremovable media. PCI DSS 4.0.1 now prohibits this practice and suggests encrypting at the file-level. This change is attempting to secure entities against zero-day attacks. Additionally, organizations may now only use a keyed cryptographic hash method and encrypt or protect all stored sensitive authentication data.
- Comprehensive Access Reviews: PCI DSS 4.0.1 places increased scrutiny on service and system accounts. You are required to review and justify the privileges associated with these accounts based on the level of access required. Furthermore, the standard explicitly prohibits the practice of hardcoding passwords, which reduces the risk of unauthorized access and strengthens the overall security posture.
- Updated Logging Requirements: Manually reviewing logs has been deemed too time-consuming and prone to error by the council, your organization is no longer permitted to manually review logs and therefore must implement automated review tools. This change aims to help promote your organization’s integration of AI in analytics and security. Additionally, all organizations, not just service providers, are now required to detect, alert, and address failures of critical security control systems.
- Secure Script Management: PCI DSS 4.0 requires organizations to validate and inventory all scripts used on public-facing web applications under Requirement 6.4.3. This includes ensuring scripts are authorized, their integrity is maintained, and each has a documented business or technical justification. Given the dynamic nature of modern websites and third-party integrations, regular scanning is essential to maintain compliance and protect against malicious script activity.
- Real-Time Tamper Detection: PCI DSS 4.0 Requirement 11.6.1 requires the deployment of automated tamper detection systems to monitor all payment pages. These systems must be capable of detecting and alerting personnel to unauthorized changes that affect security-related HTTP headers and script content. This enables organizations to quickly identify and respond to threats, reducing the risk of compromised payment environments.