signzy

API Marketplace

downArrow
Logo
Responsive
Decorative line

PCI DSS v4.0 Global Standard

GlobalGlobal2022PaymentsCybersecurity

Overview

The Payment Card Industry Data Security Standard (PCI DSS) v4.0 is the latest global framework for securing cardholder data, published by the PCI Security Standards Council in March 2022. It replaces version 3.2.1 and becomes fully enforceable by March 31, 2025. The update introduces more flexible compliance paths, stronger authentication measures, and new controls for evolving payment technologies.
PCI DSS v4.0 outlines twelve core requirements to protect cardholder data across its lifecycle. It emphasizes continuous risk assessment, customized implementation, and expanded use of multi-factor authentication (MFA). The standard applies to any entity that stores, processes, or transmits payment card data, including merchants, payment processors, fintech companies, banks, and card issuers globally.

Key Obligations

  • Implement and maintain 12 baseline controls for cardholder data protection
  • Use multi-factor authentication for all access to cardholder data environments
  • Monitor and test networks regularly to identify vulnerabilities
  • Restrict access to cardholder data to authorized personnel only
  • Conduct annual risk assessments and document compliance status

FAQ