PCI DSS v4.0 (Payment Card Industry Data Security Standard)
PCI DSS v4.0 is a global security standard designed to protect cardholder data and prevent credit card fraud. It was established by the PCI Security Standards Council to ensure that any entity processing, storing, or transmitting payment card information maintains a secure technical and operational environment.
Who it applies to
- Merchants who accept credit, debit, or prepaid cards for payments.
- Service providers that process, store, or transmit cardholder data on behalf of merchants.
- Payment gateways and processors.
- Any organization that stores primary account numbers (PAN) or sensitive authentication data.
How it works
The standard is organized into 12 primary requirements grouped into six goals, such as building secure networks and maintaining a vulnerability management program. Version 4.0 introduces more flexibility via the "Customized Approach," which allows organizations to implement alternative security controls if they can prove those controls meet the specific objective of a requirement.
Compliance is verified through an assessment process based on the organization's transaction volume and risk level. Smaller merchants may only need to complete a Self-Assessment Questionnaire (SAQ) and periodic network scans, while larger entities require an external audit conducted by a Qualified Security Assessor (QSA).
Once all requirements are met, the organization completes a Report on Compliance (ROC) or an Attestation of Compliance (AOC). This documentation serves as formal evidence that the entity has implemented the necessary controls to secure cardholder data.
Getting started
- Identify every location where cardholder data is stored, processed, or transmitted to define your "cardholder data environment" (CDE).
- Reduce compliance scope by implementing network segmentation or using tokenization services to remove sensitive data from internal systems.
- Determine your merchant level based on annual transaction volume to identify which assessment method and forms are required.
- Conduct a gap analysis against the PCI DSS v4.0 requirements to identify where current security controls are missing or insufficient.
- Develop and document formal security policies and procedures that align with the standard's mandates.
Controls & requirements
- Req 1 Install and maintain network security controls
- Req 2 Apply secure configurations
- Req 3 Protect stored account data
- Req 4 Encrypt cardholder data in transit
- Req 5 Protect against malicious software
- Req 6 Develop and maintain secure systems
- Req 7 Restrict access by business need to know
- Req 8 Identify users and authenticate access
- Req 9 Restrict physical access to cardholder data
- Req 10 Log and monitor all access
- Req 11 Test security of systems and networks regularly
- Req 12 Support information security with policies
Common misconceptions
- "PCI compliance is a one-time certification." Compliance is an ongoing requirement involving continuous monitoring and annual assessments, not a permanent certificate.
- "Using a third-party payment processor removes all compliance obligations." While outsourcing reduces the number of applicable requirements, the merchant remains responsible for ensuring their own environment does not compromise data before it reaches the provider.