Suspect a breach? Report it immediately — response within 1 hour.Report an incident

PCI DSS v4.0

Payment Card Industry Data Security Standard, version 4.0 — a contractual requirement imposed by the card networks, applicable worldwide.

Last updatedAugust 22, 2026

Who's affected

Any organization that stores, processes, or transmits payment cardholder data — online and physical merchants, payment service providers, hosting providers, and any third party with access to this data within the payment processing chain.

What the framework requires

PCI DSS v4.0 organizes its requirements into 12 areas covering network security, cardholder data protection (encryption, tokenization), vulnerability management, access control, monitoring and regular testing, and a formalized information security policy. The applicable compliance route (self-assessment via an SAQ questionnaire, or audit by a QSA) depends on the transaction volume processed by the organization, as determined by the card networks.

Compliance steps

01

Determining the cardholder data scope (scoping)

02

Gap assessment against the 12 PCI DSS v4.0 requirements

03

Scope reduction (network segmentation, tokenization)

04

Implementation of technical and organizational controls

05

Self-assessment (SAQ) or audit by a Qualified Security Assessor (QSA), depending on the applicable level

Common mistakes

  • Underestimating the actual scope of systems that touch card data
  • Confusing point-in-time compliance (at audit time) with continuous compliance
  • Overlooking version 4.0's new requirements (strengthened authentication, stronger encryption in transit) by relying on an outdated v3.2.1 assessment

Cross-mapping to other frameworks (UCM)

FrameworkCovered
iso-27001
soc-2

Downloadable resource

Get the checklist by email.

Frequently asked questions

Is PCI DSS a legal obligation?

No, it is a contractual requirement imposed by the payment card networks and acquirers, not a government law. It nonetheless applies in practice to any organization that wants to accept card payments.

What is the difference between an SAQ and a QSA audit?

The SAQ (Self-Assessment Questionnaire) is an in-house self-assessment for the lowest transaction volumes; above a threshold set by the card networks, a formal audit by an external Qualified Security Assessor (QSA) is required.

Does outsourcing payment to a third-party provider remove the need for PCI DSS compliance?

It reduces the applicable scope but does not fully exempt the organization, which remains responsible for the security of the points where it interacts with the payment flow (redirect page, iframe, terminal).

What are the main changes in version 4.0 compared to 3.2.1?

PCI DSS v4.0 notably strengthens multi-factor authentication and encryption-in-transit requirements, and introduces a customized approach that offers more flexibility in demonstrating compliance.