What PCI DSS v4.0.1 requires
The Payment Card Industry Data Security Standard (PCI DSS) v4.0.1 is structured around six control objectives: build and maintain a secure network and systems, protect account data, maintain a vulnerability management programme, implement strong access-control measures, regularly monitor and test networks, and maintain an information security policy. The standard contains 12 high-level requirements and numerous sub-requirements, each with defined testing procedures.
Version 4.0.1 introduced more targeted risk analysis, greater flexibility for customised approaches, and an expanded set of future-dated requirements that became mandatory on 31 March 2025. These include enhanced authentication, inventory and change management, cryptography, and targeted risk analysis for specific controls.
Scope reduction first
The most cost-effective PCI DSS work is the work that removes systems from scope. Every component that no longer stores, process or transmit cardholder data is a permanent reduction in audit cost and breach risk. Common scope-reduction techniques include:
- Tokenisation. Replace cardholder data with non-sensitive tokens in internal systems so the original data never leaves the processor.
- Redirect and hosted-field patterns. Keep the payment form on the provider's domain so cardholder data does not touch the merchant's environment.
- Network segmentation. Isolate the cardholder data environment from the corporate network and restrict traffic to only what is required.
These techniques do not remove the need for compliance, but they reduce the surface area that must be assessed and the cost of maintaining it.
What changed on 31 March 2025
PCI DSS v4.0.1 introduced a number of "future-dated" requirements that became mandatory on 31 March 2025. After that date, assessors must validate that organisations meet these requirements during their regular PCI DSS assessment. Organisations that had treated them as best practice needed to complete implementation, documentation and evidence collection.
Assessment timing
How CYBERVETTER helps
We help merchants, service providers and payment processors reduce PCI scope before they spend money on compliance, then validate what remains. Our work includes:
- Scope mapping and data-flow analysis to find cardholder data that should not be there.
- Tokenisation, redirect, hosted-field and segmentation design.
- Gap assessment against PCI DSS v4.0.1 and the future-dated requirements.
- Policy, procedure and evidence preparation for the QSA assessment.
- Remediation programme management and pre-assessment testing.