What changed in PCI DSS v4.0 that will actually affect us?
PCI DSS v4.0 significantly impacts organisations by shifting focus from annual compliance to continuous security. Key changes include the introduction of a "Customized Approach," allowing greater flexibility but requiring robust risk analysis and documentation. Enhanced requirements for evolving threats, such as phishing and automated attacks, and expanded multi-factor authentication scope necessitate updated security controls and awareness training. This version mandates a more proactive and adaptive security posture.
The most significant practical change in PCI DSS v4.0 is the introduction of the "Customized Approach" for implementing requirements. This approach allows organisations to design and implement controls that differ from the prescribed "Defined Approach" requirements, provided they can demonstrate that their custom controls meet the requirement's objective and achieve an equivalent level of security. While this offers greater flexibility, it places a substantial burden on organisations to conduct thorough targeted risk analyses, document their control design, implementation, and operational effectiveness comprehensively, and ensure assessors can validate these custom controls. This shift moves away from a purely prescriptive checklist mentality towards a more risk-based, continuous security management model, demanding a deeper understanding of underlying security principles and robust internal governance.
Practitioners must also contend with new and updated requirements addressing evolving threats and technologies. This includes expanded multi-factor authentication (MFA) requirements for all access to the Cardholder Data Environment (CDE) and for all non-console administrative access to systems within the CDE. There are also new requirements specifically targeting phishing and automated attacks, mandating controls like anti-phishing mechanisms and bot protection. Organisations must update their security awareness programmes to reflect these new threat vectors. Furthermore, the standard introduces a transition period, with PCI DSS v3.2.1 retiring on 31 March 2024, after which all assessments must be conducted against v4.0. Some new requirements are considered best practices until 31 March 2025, becoming mandatory thereafter, providing a phased implementation window for certain controls.
Sources
- PCI Data Security Standard v4.0, Introduction
- PCI Data Security Standard v4.0, Requirements and Guidance
- PCI DSS v4.0 Summary of Changes from PCI DSS v3.2.1 to v4.0