RSI Security

PCI DSS 4.0 Timeline: When Do You Need to Comply?

computer

PCI DSS Version 4.0 was released in March 2022, which means the clock has officially started ticking toward the deadline for complying with the new requirements. But what does this mean for your organization? How much time do you have to ensure you’re fully compliant?

This guide will cover what you need to know about the PCI DSS 4.0 timeline.

 

What Is the PCI DSS 4.0 Timeline?

The official release date of PCI DSS v4.0 draft was March 31, 2022, but the compliance deadline allows for the time needed to make the transition to the new requirements. PCI DSS v3.2.1 will remain active until March 31, 2024, giving organizations two years to learn and implement the new standards. After that date, PCI DSS 4.0 will supersede v3.2.1.

Both versions will be active until that date, and organizations will have an additional year—until March 31, 2025—to verify that they are compliant with PCI DSS 4.0.

 

What is PCI DSS 4.0?

The Payment Card Industry Data Security Standard (PCI DSS) exists to improve the security of payment card account data, and PCI DSS 4.0 is the latest version of this standard. 

PCI DSS 4.0 establishes a baseline standard for technical and operational requirements to keep sensitive account data secure as it is used and transmitted throughout the payment processing ecosystem. It was developed to better address emerging security threats, clarify guidance, and facilitate more customized security solutions.

 

Request a Free Consultation

 

Who needs to comply?

PCI DSS requirements apply anywhere account data is stored, transmitted, processed, or where the security of the cardholder data environment can be affected.

Account data includes:

RSI Security will advise your organization and identify what updates are needed to ensure your security policy and procedures align with the updated PCI DSS standards.

What Are the PCI Requirements?

PCI DSS 4.0 comprises 12 requirements, organized into six categories:

Each requirement also comprises several sub-requirements, or cybersecurity controls that organizations must implement to meet the standard. For example, the three access control requirements break down further to include specific password lengths and Multi-factor authentication (MFA), among other controls.

 

Steps to Take to Become Compliant

So, what steps should your organization take to ensure timely compliance with the new requirements? We recommend the following:

 

Get Ready for the Switch to PCI DSS 4.0

Version 4.0 of the Payment Card Industry Data Security Standard will help your organization remain better secured against emerging security threats against cardholder data and the organizations that handle it. The deadline will provide plenty of time for learning and transitioning to the new requirements, but it’s critical to develop a plan to keep things on track.

Contact RSI Security today to learn more about the PCI DSS 4.0 timeline and assess your organization’s PCI compliance strategy!

 

 


Download Our PCI DSS Checklist

Assess where your organization currently stands with being PCI DSS compliant by completing this checklist. Upon filling out this brief form you will receive the checklist via email.

Exit mobile version