Regulation · Filed · London · 8 min read
PCI DSS 4.0: What Actually Changed and What to Do About It
The substantive PCI DSS 4.0 changes that affect your control estate — customized approach, targeted risk analysis, and the March 2025 compliance deadline.
By Cyber Inspect Editorial Board
The headline changes
PCI DSS 4.0 introduces the 'customized approach' (define your own control to meet the objective), targeted risk analyses for flexible controls, stricter authentication (MFA for all CDE access), and expanded scoping documentation.
Deadlines that already passed
Version 3.2.1 was retired 31 March 2024. The additional 4.0 future-dated requirements became mandatory 31 March 2025. If you're still on 3.2.1 scoping, you're operating below the standard.