PCI-DSS · Version Changes

PCI DSS v4.0: What Actually Changed vs. v3.2.1

PCI DSS v3.2.1 retired on March 31, 2024. Version 4.0.1 — a clarifying revision of v4.0 — is now the sole active standard. Here is what the update actually requires, sourced directly to the PCI Security Standards Council’s own summary of changes.

Quick Answer

The Short Version

PCI DSS v4.0 added 64 new requirements on top of v3.2.1’s baseline: 13 became mandatory immediately when v3.2.1 retired (April 2024), and the remaining 51 — the “future-dated” requirements — became mandatory on March 31, 2025. The headline changes are a new Customized Approach option, mandatory MFA for all access into the cardholder data environment, a minimum 12-character password length, and a formal Targeted Risk Analysis process for setting your own control frequencies.

Timeline

The Version Timeline

PCI DSS v4.0 was published in March 2022 after a three-year development process incorporating roughly 6,000 feedback items from more than 200 organizations. The Council gave the industry two years to prepare before v3.2.1 retired.

March 2022PCI DSS v4.0 published.
March 31, 2024v3.2.1 officially retired. The 13 requirements that were not future-dated became mandatory.
June 2024v4.0.1 published — a limited revision with formatting corrections and clarified requirement intent, no new or deleted requirements.
December 31, 2024v4.0 retired; v4.0.1 became the sole active version.
March 31, 2025The remaining 51 future-dated requirements became mandatory for all assessments.

Source: PCI Security Standards Council, “Just Published: PCI DSS v4.0.1” and the Council’s official Summary of Changes, v3.2.1 to v4.0.

The Substance

The Six Changes That Actually Matter

Expanded MFA (Req. 8)

Under v3.2.1, MFA was required only for remote access and administrative access to the CDE. v4.0 expands this to all access into the cardholder data environment, not just remote and admin paths. The v4.0.1 clarifying revision added a narrow exception for phishing-resistant authentication factors.

Password Length (Req. 8)

Minimum password length increases from seven to twelve characters (eight where a system cannot yet support twelve). This was one of the future-dated requirements, mandatory since March 31, 2025.

Targeted Risk Analysis

A new, formal Targeted Risk Analysis (TRA) process lets an entity define the frequency of certain activities — such as specific log reviews or periodic scans — based on a documented risk analysis rather than a fixed schedule the standard used to dictate outright.

Customized Approach

v4.0 keeps the traditional prescriptive (“Defined Approach”) method and adds an optional Customized Approach, letting an organization design and validate its own control to meet a requirement’s stated objective through its own testing methodology and risk analysis — more implementation flexibility, more assessor scrutiny.

Network Security Controls

“Firewall” terminology throughout the standard was replaced with “network security controls” — a deliberate broadening to recognize cloud-native constructs (security groups, NSGs, service meshes) that provide equivalent boundary enforcement without being a traditional firewall appliance.

Continuous Vulnerability Management

Point-in-time scanning gives way to more continuous vulnerability management expectations, including authenticated internal vulnerability scanning and more explicit roles-and-responsibilities documentation for every requirement.

Why It’s Not Optional

The Future-Dated Requirements Are Already in Force

Because all 51 future-dated requirements became mandatory on March 31, 2025, “we’ll get to v4.0 eventually” is no longer a viable posture for any organization undergoing an assessment or ROC today. If your last assessment predates that deadline, assume your control set has a gap until you’ve specifically verified MFA scope, password policy, and segmentation testing evidence against the current standard.

Armorstack’s VERITY portfolio runs a targeted v4.0.1 gap assessment against your last ROC or SAQ to identify exactly which of the 51 future-dated controls are already covered by existing infrastructure work and which require net-new implementation — typically the fastest path to closing the gap without re-scoping the entire environment.

Not Sure Where Your v4.0.1 Gaps Are?

Armorstack runs a targeted gap assessment against the current standard and tells you exactly which of the 51 future-dated requirements still need work.

877-890-5508 · [email protected]