Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

Timeline of PCI DSS v4.0.1 release and updates for governance and security.

PCI DSS v4.0.1: A Clear Guide to the 2026 Version

PCI DSS v4.0.1 is the only version of the standard you can be assessed against
today. Everything before it has been retired — v3.2.1 in March 2024 and v4.0 itself at the end
of that year — and the requirements that spent three years labelled as best practice became
assessable on 31 March 2025. If your programme was built around “preparing for v4.0”, it is
describing a world that no longer exists.

PCI DSS v4.0.1 version timeline: the five dates that decide which version applies
The PCI DSS version timeline, from v4.0 in 2022 to the future-dated requirements taking effect in March 2025.

The version timeline, in order

Four dates settle almost every question about which version applies.

Date What happened
31 March 2022 PCI SSC published PCI DSS v4.0
31 March 2024 v3.2.1 retired
June 2024 v4.0.1 published as a limited revision
31 December 2024 v4.0 retired — v4.0.1 becomes the only active version
31 March 2025 The 51 future-dated requirements became effective

The two that catch people are the last two. A document set written against v4.0 is not
automatically wrong — but it is written against a retired version, and the future-dated
requirements it may still describe as “best practice” are now simply requirements.

What PCI DSS v4.0.1 actually changed

Less than the version number suggests, and this is the single most useful thing to understand about
it. PCI DSS v4.0.1 was a limited revision: it corrected errors, clarified wording and
improved guidance. It introduced no new requirements and deleted none.

So an organisation that had genuinely implemented v4.0 did not acquire new control obligations when
v4.0.1 arrived. What changed was the text they should be reading, the version their assessor works
from, and the documents they should be citing.

The SAQs did change, and that distinction matters

This is where a lot of commentary is sloppy. The standard gained no requirements, but the
Self-Assessment Questionnaires — which are validation tools, not the standard
— were reissued for v4.0.1 on 15 October 2024, and those did change.

PCI SSC’s bulletin sets out what moved: requirement content aligned to v4.0.1, eligibility criteria
clarified in SAQs A, A-EP and C-VT, a requirement added to SAQ A and a requirement removed
from SAQ C
, and completion guidance updated in SAQs A and A-EP. An accompanying SAQ
Instructions and Guidelines document was published alongside them.

If you self-assess, that is the part that affects you directly — particularly the SAQ A
change, which lands on exactly the e-commerce merchants who assume SAQ A is the light-touch option.
Confirm your eligibility against the current SAQ before starting, not after.

The future-dated requirements are no longer optional

PCI DSS v4.x introduced 64 new requirements. 51 of them were future-dated, meaning
they were treated as best practice until a stated date and were not assessed before it. That date was
31 March 2025.

They are now assessed like any other requirement. This is the most common gap in programmes built
during the transition years: the risk analysis, the documentation and the control design were all
written when those items were optional, and nobody revisited them when the date passed. An assessor
will.

The practical move is a deliberate pass over anything your programme once labelled “best practice”
or “not yet applicable”, checking whether it is now in force. Our
PCI DSS documentation checklist covers
the evidence side of that, including the targeted risk analyses the standard now expects.

Documentation aligned to the version in force.

The PCI-DSS Toolkit ships 180+ editable templates aligned to PCI DSS v4.0.1 — the scope inventory and cardholder data environment definition, targeted risk analysis and customised approach documents, the shared responsibility matrix, and the policies, procedures and registers the standard requires.

Explore the PCI-DSS Toolkit →

How the standard is organised under PCI DSS v4.0.1

The familiar shape is unchanged: twelve principal requirements grouped under six control
objectives, covering network security, protection of stored account data, vulnerability management,
access control, monitoring and testing, and an overarching information security policy.

What v4.x changed is not the skeleton but how you may satisfy it. Two routes now exist:

  • The defined approach — meet the requirement as written, tested against the
    stated testing procedures. This is what everyone did under v3.2.1 and it remains entirely valid.
  • The customised approach — meet the stated objective of a
    requirement using a control of your own design. It is not a shortcut. It obliges you to document the
    objective, design the control, analyse the risk, define your own testing, and have your assessor
    derive testing procedures for it.

In practice the customised approach suits mature organisations with security engineering capacity
and genuinely unusual architectures. For most entities the defined approach is faster, cheaper and
easier to defend — and choosing it is not a compromise.

Targeted risk analysis is the quiet workload

Several v4.x requirements let you set your own frequency for an activity rather than following a
fixed interval — and every one of those requires a documented targeted risk analysis
justifying the frequency you chose, reviewed periodically. Organisations consistently underestimate
this, because each individual analysis is small and there are a number of them.

What to do if your programme still says v4.0

  1. Confirm the version you are being assessed against. It is v4.0.1. Anything in
    your documentation citing v4.0 or v3.2.1 needs updating, even where the substance is unchanged.
  2. Re-baseline the future-dated items. List every requirement your programme treated
    as best practice, and confirm each is now implemented and evidenced.
  3. Re-check SAQ eligibility against the current SAQ if you self-assess, especially
    SAQ A and SAQ C.
  4. Re-confirm scope. It is a requirement in its own right, at least every 12 months
    — see our guide to PCI DSS scope.
  5. Check who validates you. Your acquirer or payment brand sets the route and the
    deadline, not PCI SSC; our guide to
    PCI DSS validation covers who requires
    what.
  6. Diarise the annual cycle. Scope confirmation, targeted risk analysis reviews and
    whatever periodic testing your requirements carry.

Why “preparing for v4.0” is now the wrong frame

A large amount of PCI DSS content still on the web was written between 2022 and 2024, when the
industry question was how to get ready for a version that had not yet bitten. That framing produced
guides organised around transition: what is coming, what to do first, how long you have.

None of that is useful now, and some of it is actively misleading. Material describing the
future-dated requirements as best practice is describing the position before 31 March 2025. Material
telling you to plan your move from v3.2.1 is addressing a version retired in March 2024. Material
built around v4.0 is built around a version retired that December.

The current question is not “how do we prepare?” but “are we meeting PCI DSS v4.0.1 as it stands,
and can we evidence it?” That is a different exercise: less roadmap, more evidence. If a document in
your own programme is still phrased as preparation, it is the same problem in miniature and worth
rewriting for the same reason.

How to tell whether guidance is current

Three quick tests. Does it name v4.0.1 rather than v4.0? Does it treat the
future-dated requirements as in force rather than upcoming? And does it distinguish
the standard from the SAQs, which were revised separately in October 2024? Guidance failing any of
those is at least two years behind, whatever its publication date says.

Frequently asked questions

Which PCI DSS version applies now?
PCI DSS v4.0.1. It became the only active version when v4.0 was retired on 31 December 2024.

Do I have to do anything new because of v4.0.1?
It added no requirements and removed none, so an organisation genuinely compliant with v4.0 did not
gain obligations. You should be working from the v4.0.1 text and, if you self-assess, the v4.0.1
SAQs.

Are the future-dated requirements in force?
Yes. The 51 future-dated requirements became effective on 31 March 2025 and are assessed like any
other.

Should I use the customised approach?
Only if you have a genuine reason and the capacity to support it. It requires you to document the
objective, design and justify the control, and work with your assessor to derive testing procedures.
The defined approach is easier to defend.

Is PCI DSS v4.0.1 a certification?
No. PCI DSS compliance is validated through a Report on Compliance or a Self-Assessment
Questionnaire, with an Attestation of Compliance, and the requirement to validate comes from your
acquirer or the payment brands.

References

PCI DSS is not the only PCI standard with version dates worth tracking. The PIN standard sits at v3.1 and its phase-in dates have all now passed — see PCI PIN Security Requirements.

More on PCI DSS

All of these are covered by the PCI-DSS Toolkit, or start with the free ISO templates.

Stay Compliance-Ready

Get compliance tips, new toolkit releases, and standard updates in your inbox.

We don’t spam! Read our privacy policy for more info.