Standards

PCI DSS v4.0.1: What's Actually New (and Now Enforced)

What v4.0.1 changed

PCI DSS v4.0.1 is a refinement release, but its enforcement date matters more than its version number: 47 previously future-dated requirements became fully mandatory on March 31, 2025. This is the first full assessment cycle under complete v4.0.1 enforcement, and the standard grew from roughly 370 to over 500 individual testing items.

The four requirements catching everyone

  • 6.4.3 -- Payment-page script inventory. Every script on your payment pages must be inventoried with a written business justification and integrity-checking mechanisms. First-party and third-party scripts both count.
  • 11.6.1 -- Tamper detection. Automated change-and-tamper detection for payment-page content and HTTP headers, running continuously -- not a quarterly check.
  • 8.3.6 -- MFA for all CDE access. Multi-factor authentication is now required for all access into the cardholder data environment, not just remote access.
  • 12.3.2 -- Targeted risk analyses. Documented analyses justifying the frequency of each periodic control -- you must defend why your cadences are what they are.

What assessors test now

QSAs in this cycle are testing the new requirements in full: expect to show the script inventory, demonstrate the tamper-detection tooling firing, prove MFA coverage across every CDE access path, and hand over written risk analyses. "We didn't know" stopped working on March 31, 2025.

Remediation priorities

  1. Script inventory first. It's the fastest win and the most commonly failed new item -- most merchants have never listed their payment-page scripts.
  2. MFA coverage audit. Walk every path into the CDE and confirm MFA -- service accounts and vendor access are the usual gaps.
  3. Stand up tamper detection. Evaluate tooling now; this is the requirement most likely to need a new product.
  4. Write the risk analyses. Documented, dated, and signed -- assessors want the paper trail, not just the practice.

Questions

Is PCI DSS v4.0 still valid?

v4.0.1 is the current release and the one assessors test against. v4.0 assessments have been retired -- confirm with your QSA which version your ROC will cite.

Do the new requirements apply to SAQ merchants?

Yes, where the SAQ includes them -- SAQ A-EP in particular picked up script-related requirements. Check your SAQ type's requirement list.

Independent directory note. This guide is educational content, not assessment advice. Confirm requirements with your QSA and acquirer.

Related reading

Get quotes from PCI QSA firms

Tell us about your environment once -- matched assessors reply with scoped quotes. Free, 2 minutes.

Get a free quote