PCI DSS 4.0: What Changed and What It Means for Your Next Assessment
v3.2.1 is retired. Here’s what’s actually different in v4.0.1, which changes bite first-timers hardest, and how to plan the transition.
The headline changes
PCI DSS v4.0 (now v4.0.1) replaced v3.2.1, which was retired on March 31, 2025. The structure is the same — 12 requirements in 6 goals — but several requirements got materially stricter:
- MFA everywhere it matters. Multi-factor authentication is now required for all access into the cardholder data environment, not just remote access.
- Stronger password standards. Minimum 12 characters (8 for service accounts that can’t support 12), with complexity and rotation rules tightened.
- Targeted risk analyses. Where the standard lets you set frequencies (vulnerability scans, log reviews), you must now document a formal risk analysis justifying the cadence.
- Authenticated vulnerability scans. Internal scans must use authenticated scanning — deeper, and more likely to surface findings.
- Customized approach. A new way to meet requirements: instead of following the defined implementation, you can design your own controls and prove they meet the requirement’s objective. Powerful, but it shifts the burden of proof to you.
What bites first-timers
The MFA expansion and the targeted risk analyses. Both sound administrative; both generate findings in first-time v4 assessments because they require evidence — documented analyses, enforced configurations — not just policies.
Turn reading into quotes. Get scoped, comparable quotes from accredited QSA companies — free, 2 minutes, no obligation.
Request quotesThe customized approach
Worth knowing about, rarely the right first move. It lets mature security teams substitute equivalent controls, but your QSA must validate the design against each requirement’s Customized Approach Objective — expect a longer, more expensive assessment the first time you use it.
Planning your v4 assessment
Run the readiness quiz against v4.0.1 expectations, close the MFA and logging gaps first, and tell your QSA explicitly that this is a first-time v4 assessment — scoping assumptions differ from 3.2.1-era engagements.
Keep reading
ROC vs SAQ: Do You Actually Need a QSA On Site?
The real difference between a Report on Compliance and a Self-Assessment Questionnaire, who decides which one you do, and the expensive mistake in between.
How to Choose a PCI QSA Company: 11 Questions Before You Sign
What separates a good QSA company from an expensive rubber stamp — and the exact questions that reveal which one you’re talking to.
PCI DSS Assessment Cost in 2026: What the Fee Actually Covers
Where the money goes in a PCI engagement — the assessment fee, the testing, the remediation nobody budgets for — and how to keep the total down.
Questions
Is PCI DSS v4.0.1 very different from v4.0?
v4.0.1 is a maintenance update — corrections and clarifications, not a new requirements regime. If you were ready for v4.0, you’re ready for v4.0.1.
Can we still be assessed against v3.2.1?
No — v3.2.1 was retired March 31, 2025. All new assessments are against v4.0.1.
Turn reading into quotes
Get scoped, comparable quotes from accredited QSA companies — free, 2 minutes.
How it works: tell us once (4 questions, 2 min) → we match accredited QSA companies to your size and scope → they send scoped quotes directly. Free, no obligation.