PCI-DSS v4.0: What Changed and How to Prepare
PCI-DSS (Payment Card Industry Data Security Standard) is the set of security requirements demanded by card brands (Visa, Mastercard, Amex, among others) for any organization that stores, processes, or transmits cardholder data. Version 4.0 brought the most significant update since 3.2.1.
What changed in v4.0
Key changes include mandatory multi-factor authentication (MFA) for all access to the cardholder data environment — not just administrators —, stricter encryption requirements, greater emphasis on continuous monitoring over point-in-time checks, and the introduction of the 'customized approach': instead of following only the traditional prescriptive method, organizations can demonstrate they meet a requirement's security objective through their own documented path, validated by a QSA.
The 4 merchant levels
The required compliance level depends on transaction volume: Level 1 (over 6 million transactions/year) requires an annual audit by a QSA (Qualified Security Assessor); Levels 2 through 4 generally allow self-assessment via SAQ, with the SAQ type varying based on how the card is processed — physical store, redirected e-commerce, or direct processing.
The 12 requirements, grouped into 6 goals
Build and maintain secure networks; protect cardholder data (with encryption at rest and in transit); maintain a vulnerability management program; implement strong access control measures; regularly monitor and test networks; and maintain a formal information security policy. Each goal breaks down into specific, auditable technical requirements.
Where to start
Before anything else, reduce scope: segmenting your network to isolate the cardholder data environment from the rest of your infrastructure is the single decision that most cheapens and simplifies PCI-DSS compliance. Then prioritize MFA on all access, encryption of data at rest and in transit, and an up-to-date inventory of where card data actually flows — many organizations discover, just from this exercise, data flows they didn't even know existed.
PCI-DSS as part of a broader compliance portfolio
Companies that process payments rarely have only PCI-DSS on their list — GDPR, SOC 2, and ISO 27001 frequently share the same underlying technical controls (encryption, access control, monitoring). Treating these requirements as shared evidence across frameworks, instead of isolated projects, is the difference between audits that keep piling up and a compliance program that actually scales — it's exactly the model Aranis applies when adding new frameworks to its control catalog.
Reducing the scope of your cardholder data environment isn't a shortcut — it's the architectural decision that determines whether PCI-DSS costs your team weeks or months of the year.