The Payment Card Industry Data Security Standard (PCI DSS) consists of 12 core requirements designed to ensure organizations securely handle cardholder data. Version 4.0.1 includes updated requirements effective through March 2025.
Key changes and new requirements in the latest version of the PCI DSS standard.
Stronger requirements for multi-factor authentication and privileged access management.
New flexibility to meet security objectives through alternative methods.
More emphasis on risk assessment and validation frequency based on risk levels.
Firewalls and network security controls to protect cardholder data.
Remove default passwords and configure systems securely.
Protect cardholder data through encryption and secure storage.
Encrypt cardholder data during transmission over open networks.
Deploy and maintain anti-malware solutions.
Maintain secure development practices and patch management.
Implement role-based access controls.
Implement strong authentication and user identification.
Control physical access to systems and media.
Implement comprehensive logging and monitoring.
Perform regular security testing and monitoring.
Maintain information security policies and procedures.
For Level 1 merchants or complex environments, consider working with a Qualified Security Assessor (QSA).
PCI DSS compliance is not a one-time event. Maintain ongoing monitoring, testing, and validation processes.