PCI DSS 4.0.1 is the current version of the payment-security standard, but it did not introduce a new collection of controls. It was a limited revision published in June 2024, while a separate deadline made requirements already announced with PCI DSS 4.0 effective on 31 March 2025.
The important distinction: PCI DSS v4.0.1 clarified wording and guidance but added no new or deleted requirements. The March 2025 deadline applied to requirements that had already been introduced with PCI DSS v4.0.
What PCI DSS 4.0.1 actually changed
The PCI Security Standards Council published v4.0.1 after receiving questions and feedback about PCI DSS v4.0. The revision corrected formatting and typographical errors, clarified the intent of several requirements and improved supporting guidance.
That matters because businesses should use the current document without treating every clarification as a new security obligation. The standard still covers the systems, people and processes that store, process or transmit cardholder data, along with systems that can affect their security.
Use PCI DSS v4.0.1 and the matching official assessment document for your environment.
Do not describe v4.0.1 as a separate new set of controls introduced in 2025.
What became mandatory in March 2025
PCI DSS v4.0 included requirements that were treated as best practices during the transition. They became effective on 31 March 2025 and remain part of v4.0.1. The exact controls that apply depend on your payment flow, assessment type and responsibilities.
Organisations may need to authorise payment-page scripts and detect unauthorised changes or tampering.
Passwords or passphrases generally require at least 12 characters when the system supports them, and multi-factor authentication has broader coverage.
Some control frequencies must be supported by a documented targeted risk analysis rather than an informal schedule.
Authenticated internal vulnerability scanning and stronger evidence of segmentation may apply to the assessed environment.
These are examples, not a substitute for the official standard or the assessment questionnaire that applies to your organisation.
What your business should check
Start with scope rather than a generic compliance-level table. Your acquiring bank or payment brand normally determines how compliance must be validated and whether you should use a Self-Assessment Questionnaire or a Report on Compliance.
Ask your acquirer or payment brand which reporting method and assessment document apply to your organisation.
Record where card data enters, which systems and providers can reach it and which web scripts can affect the payment page.
Review your controls against PCI DSS v4.0.1 and the current official SAQ or ROC template for your environment.
Give every action an owner and deadline, then retain scan results, access reviews, change records and provider evidence.
A practical decision guide
Outsourcing can reduce the number of controls directly applicable to your environment, but it does not automatically remove your responsibility to protect payment data, manage providers and validate compliance.
The useful next move is simple: confirm the correct assessment route, map the real payment flow and compare it with the current official documents. That produces a defensible plan without overstating what v4.0.1 changed.
