PCI DSS 4.0.1: What You Need to Know

PCI DSS 4.0.1 clarified the payment-security standard before requirements introduced with PCI DSS 4.0 became mandatory on 31 March 2025. This guide separates those two changes and shows what businesses accepting card payments should check.

Payment card resting on a laptop keyboard

PCI DSS 4.0.1 is the current version of the payment-security standard, but it did not introduce a new collection of controls. It was a limited revision published in June 2024, while a separate deadline made requirements already announced with PCI DSS 4.0 effective on 31 March 2025.

The important distinction: PCI DSS v4.0.1 clarified wording and guidance but added no new or deleted requirements. The March 2025 deadline applied to requirements that had already been introduced with PCI DSS v4.0.

What PCI DSS 4.0.1 actually changed

The PCI Security Standards Council published v4.0.1 after receiving questions and feedback about PCI DSS v4.0. The revision corrected formatting and typographical errors, clarified the intent of several requirements and improved supporting guidance.

That matters because businesses should use the current document without treating every clarification as a new security obligation. The standard still covers the systems, people and processes that store, process or transmit cardholder data, along with systems that can affect their security.

PublishedJune 2024
PurposeClarification and correction
New requirementsNone
Avoid

Do not describe v4.0.1 as a separate new set of controls introduced in 2025.

What became mandatory in March 2025

PCI DSS v4.0 included requirements that were treated as best practices during the transition. They became effective on 31 March 2025 and remain part of v4.0.1. The exact controls that apply depend on your payment flow, assessment type and responsibilities.

Payment pages

Organisations may need to authorise payment-page scripts and detect unauthorised changes or tampering.

Authentication

Passwords or passphrases generally require at least 12 characters when the system supports them, and multi-factor authentication has broader coverage.

Risk-based work

Some control frequencies must be supported by a documented targeted risk analysis rather than an informal schedule.

Technical testing

Authenticated internal vulnerability scanning and stronger evidence of segmentation may apply to the assessed environment.

These are examples, not a substitute for the official standard or the assessment questionnaire that applies to your organisation.

What your business should check

Start with scope rather than a generic compliance-level table. Your acquiring bank or payment brand normally determines how compliance must be validated and whether you should use a Self-Assessment Questionnaire or a Report on Compliance.

Confirm the validation route

Ask your acquirer or payment brand which reporting method and assessment document apply to your organisation.

Map the payment flow

Record where card data enters, which systems and providers can reach it and which web scripts can affect the payment page.

Compare the right document

Review your controls against PCI DSS v4.0.1 and the current official SAQ or ROC template for your environment.

Close gaps and keep evidence

Give every action an owner and deadline, then retain scan results, access reviews, change records and provider evidence.

A practical decision guide

SituationRecommended actionAvoid
Payment processing is outsourcedConfirm the provider's PCI status and your remaining responsibilities with your acquirer.Assuming outsourcing removes every PCI responsibility.
Your website can affect a payment pageInventory scripts, authorise changes and confirm the SAQ eligibility criteria.Treating a hosted checkout as automatically out of scope.
Your merchant level is unclearAsk the acquirer or payment brand that accepts your compliance evidence.Copying a generic level table from an unrelated website.

Outsourcing can reduce the number of controls directly applicable to your environment, but it does not automatically remove your responsibility to protect payment data, manage providers and validate compliance.

The useful next move is simple: confirm the correct assessment route, map the real payment flow and compare it with the current official documents. That produces a defensible plan without overstating what v4.0.1 changed.

Found this useful?Share it with someone.
LinkedInXBluesky

Need more practical IT guides?

Explore step-by-step tutorials, expert insights, and actionable guidance to help you work smarter, stay secure, and solve real problems.

Browse More Articles