Regulation · Filed · London · 8 min read

PCI DSS 4.0: What Actually Changed and What to Do About It

The substantive PCI DSS 4.0 changes that affect your control estate — customized approach, targeted risk analysis, and the March 2025 compliance deadline.

By Cyber Inspect Editorial Board

The headline changes

PCI DSS 4.0 introduces the 'customized approach' (define your own control to meet the objective), targeted risk analyses for flexible controls, stricter authentication (MFA for all CDE access), and expanded scoping documentation.

Deadlines that already passed

Version 3.2.1 was retired 31 March 2024. The additional 4.0 future-dated requirements became mandatory 31 March 2025. If you're still on 3.2.1 scoping, you're operating below the standard.