Compliance Briefing — PCI DSS version 4.0 released
The PCI Security Standards Council published PCI DSS v4.0 on 31 March 2022, expanding requirements for authentication, e-commerce, and risk-based testing with transition timelines into 2025.
The PCI SSC released PCI DSS 4.0 on 31 March 2022, updating controls for multi-factor authentication, e-commerce scripts, customized approaches, and targeted risk analyses. Organizations must adopt the standard by March 2025, with several new requirements (such as automated log reviews and stricter encryption) becoming effective after March 2025.
Merchants, service providers, and engineering teams should map gaps from version 3.2.1 to 4.0, prioritize MFA coverage and payment page integrity monitoring, and plan evidence for customized controls and assessor expectations during the transition period.
Continue in the Compliance pillar
Return to the hub for curated research and deep-dive guides.
Latest guides
-
Third-Party Risk Oversight Playbook — Zeph Tech
Operationalize OCC, Federal Reserve, EBA, and MAS outsourcing expectations with lifecycle controls, continuous monitoring, and board reporting.
-
Compliance Operations Control Room — Zeph Tech
Implement cross-border compliance operations that satisfy Sarbanes-Oxley, DOJ guidance, EU DORA, and MAS TRM requirements with verifiable evidence flows.
-
SOX Modernization Control Playbook — Zeph Tech
Modernize Sarbanes-Oxley (SOX) compliance by aligning PCAOB AS 2201, SEC management guidance, and COSO 2013 controls with data-driven testing, automation, and board reporting.




