PCI DSS v4.0 – Five changes you need to know
Organizations handling payment card data must adapt to PCI DSS v4.0's enhanced security requirements to improve compliance and reduce cyber risk.

Defense.com

As cyber threats continue to evolve, organizations that process, store, or transmit payment card data must strengthen their security posture. The release of PCI DSS v4.0 marks the most significant update to the Payment Card Industry Data Security Standard in years, introducing new requirements designed to better protect cardholder data against modern cyber risks.
Although PCI DSS is not a legal requirement, compliance is mandatory for organizations that handle payment card data. Businesses can still be held accountable for security incidents and face financial penalties from payment providers or acquiring banks, even when payment processing is outsourced.
What's New in PCI DSS v4.0?
Released by the PCI Security Standards Council (PCI SSC) in March 2022, PCI DSS v4.0 replaces version 3.2.1 and introduces 53 new requirements for most organizations, with an additional 11 requirements for service providers. While some controls became effective immediately, the majority transitioned from best practices to mandatory requirements on 31 March 2025.
The updated standard places greater emphasis on proactive security, operational resilience, and flexibility in how organizations achieve compliance.
Five Key Changes
1. Broader Vulnerability Management
PCI DSS v4.0 expands vulnerability management beyond critical and high-risk findings. Organizations are now expected to identify, prioritize, and address vulnerabilities of all severity levels, recognizing that attackers often combine multiple lower-risk vulnerabilities to compromise systems.
2. Stronger Protection Against Malware and Phishing
The standard introduces enhanced malware controls, including automatic scanning of removable media such as USB devices. It also strengthens phishing defenses by requiring organizations to train employees to recognize phishing attempts while implementing technologies that detect and block malicious emails.
3. Enhanced Security Awareness Training
Security awareness is no longer viewed as a once-a-year exercise. Organizations must regularly review and update training programs to address emerging threats, including phishing, social engineering, new vulnerabilities, and the secure use of workplace technologies. This reflects the growing importance of employees as a critical layer of cyber defense.
4. Expanded Multi-Factor Authentication (MFA)
PCI DSS v4.0 significantly increases the use of multi-factor authentication (MFA). MFA is now required for all access to the Cardholder Data Environment (CDE), helping reduce the risk of unauthorized access and credential-based attacks as part of a layered security strategy.
5. Greater Flexibility in Compliance
One of the most notable changes is the introduction of two compliance pathways:
- Defined Approach – Organizations follow the prescribed PCI DSS controls and testing procedures exactly as documented, making compliance straightforward and consistent.
- Customized Approach – Organizations can demonstrate that alternative security controls achieve the same security objectives, providing greater flexibility for businesses with mature security and risk management programs.
This allows organizations to innovate while still meeting the intent of the standard.
Why It Matters
PCI DSS v4.0 reflects today's cyber threat landscape by encouraging organizations to move beyond simple compliance and adopt a more comprehensive approach to cyber security. The updated requirements focus on continuous risk management, stronger authentication, improved employee awareness, and modern security controls that better defend against sophisticated attacks.
For organizations already compliant with PCI DSS v3.2.1, some updates may require only minor process changes, while others may involve more substantial investments in technology, governance, and training.
The Bottom Line
PCI DSS v4.0 is more than just a standards update—it represents a shift toward continuous cyber resilience. With stronger security requirements, expanded authentication measures, improved staff awareness, and more flexible compliance options, the standard helps organizations better protect payment card data in an increasingly complex threat environment.
Organizations that handle cardholder data should ensure they have fully transitioned to PCI DSS v4.0 and regularly review their security controls to maintain compliance while reducing cyber risk.