Secure Minds System

PCI-DSS v4.0.1 Compliance Consulting

PCI-DSS v4.0.1 Compliance Consulting

Secure Minds runs PCI DSS v4.0.1 compliance engagements — applicability scoping, gap assessment against all 12 requirements, future-dated requirement implementation, and SAQ/ROC preparation. This is practitioner-led work, delivered by consultants with 15+ years of hands-on GRC and technical security implementation experience.

Where the Standard Stands

PCI DSS v4.0 replaced v3.2.1 on 31 March 2024. The PCI Security Standards Council issued clarifying errata as v4.0.1 shortly after. Critically, the 51 requirements that were originally “future-dated” became mandatory on 31 March 2025 — that deadline has already passed. Any organization still treating these as optional is out of compliance today, not at some future date. If your last assessment predates March 2025, assume you have gaps against the now-mandatory requirement set until proven otherwise.

The 12 Requirements

Goal Requirements Covers
Build & Maintain a Secure Network Req. 1–2 Network security controls, secure configurations for all system components
Protect Account Data Req. 3–4 Stored account data protection, strong cryptography for transmission over open/public networks
Maintain a Vulnerability Management Program Req. 5–6 Malware protection, secure systems and software development
Implement Strong Access Control Req. 7–9 Need-to-know access restriction, identification/authentication, physical access restriction
Regularly Monitor & Test Networks Req. 10–11 Logging and monitoring, regular security testing of systems and networks
Maintain an Information Security Policy Req. 12 Organizational policy and targeted risk analyses supporting the other 11 requirements

Key New v4.0 Requirements We See Organizations Miss

Requirement What It Mandates
8.4.2 Multi-factor authentication for ALL access into the CDE — not just remote access; MFA terminating outside the CDE does not satisfy this requirement
11.6.1 A change- and tamper-detection mechanism deployed on payment pages to alert on unauthorized modification of HTTP headers and page content, evaluated at least once every 7 days or per a targeted risk analysis
6.4.3 All payment-page scripts must be authorized, integrity-verified, and formally inventoried with business or technical justification

These three requirements — MFA scope, script management, and payment-page tamper detection — account for the majority of the post-March-2025 findings we see in gap assessments. Most legacy PCI programs built for v3.2.1 do not cover any of them.

Our Methodology

Phase What We Deliver
Scoping Cardholder Data Environment (CDE) boundary definition, network segmentation validation, merchant/service-provider level determination
Gap Assessment Control-by-control assessment against all 12 requirements including the now-mandatory future-dated set
Remediation Technical control implementation (MFA, script management, tamper detection, logging) and policy/procedure documentation
Validation Support SAQ completion support or QSA-led ROC coordination, ASV scan management, penetration testing coordination per Req. 11

Typical Engagement Timeline

For a mid-market merchant or service provider: scoping and gap assessment (3–4 weeks), remediation (6–12 weeks depending on how many of the new v4.0 requirements are unaddressed), and validation (SAQ self-assessment: 1–2 weeks; QSA-led ROC: 4–8 weeks including on-site/remote assessment). Organizations with mature ISO/IEC 27001:2022 programs typically move faster — access control and logging evidence overlaps significantly with Annex A controls.

Frequently Asked Questions

Are the PCI DSS v4.0 future-dated requirements still optional?
No. All future-dated requirements became mandatory on 31 March 2025. This deadline has passed — there is no grace period remaining.

Do we need a QSA, or can we self-assess?
It depends on your merchant or service-provider level, set by your acquiring bank or the card brands based on transaction volume. Level 1 merchants and most Level 1–2 service providers require a QSA-led Report on Compliance (ROC); lower levels can typically self-assess via the applicable SAQ.

What’s the difference between PCI DSS v4.0 and v4.0.1?
v4.0.1 is a clarifying errata release, not a substantive requirements change — it corrects wording ambiguities and testing procedure inconsistencies found after v4.0’s initial publication. If you’re compliant with v4.0’s requirements, you’re aligned with v4.0.1.

How does PCI DSS relate to our ISO 27001 or SOC 2 program?
Significant overlap on access control, logging, vulnerability management, and change management. We scope combined engagements so evidence gathered once satisfies multiple frameworks rather than being collected three separate times.

Discuss Today to scope your PCI DSS v4.0.1 engagement.