Secured integration to the future

Secured integration to the future

PCI DSS v4.0.1: What is PCI DSS used for, why is it important, and how does it differ from version 4.0?

Майстер-клас: секрети випікання найсмачніших млинців!

19.02.2025

PCI DSS (Payment Card Industry Data Security Standard) is a global security standard for the payment card industry, designed to protect cardholder confidential information. Since the release of PCI DSS v4.0 in 2022, updates have been made, leading to the introduction of PCI DSS v4.0.1 in 2024.
In this article, we will examine what this new version includes, why it was introduced, and the key differences from version 4.0.

Why was the update to v4.0.1 needed?

PCI DSS v4.0.1 is not a completely new version of the standard but rather a refinement and correction of the previous version. The key reasons for its release include:
1. Error correction - Addressing inaccuracies identified in v4.0.2. Clarifying wording - Refining requirement language to reduce ambiguity and ensure more precise implementation.3. Updating the standard to address modern cybersecurity threats and technological challenges.

Key differences between PCI DSS v4.0.1 and v4.0

1. Editorial Changes and Corrections – Some requirements in PCI DSS v4.0 were revised for clarity and accuracy.2. The PCI Security Standards (PCI SSC), updated specific definitions to improve precision. 3. Corrections in Audit Requirements – Changes to auditing and certification processes have been updated to simplify compliance for organizations.4. Clarifications in Cryptographic Protection Requirements – This includes additional guidelines on encryption and security keys, particularly:     ● Requirement 3.5.1: Clarified methods for rendering the PAN (Primary Account Number) unreadable.5. Updates to Vulnerability Risk Ranking and Remediation Timelines – Enhancements have been made to clarify how vulnerabilities should be prioritized and addressed:     ● Requirement 6.3.3: Now states that critical software updates must be applied within one month of release.      ● In v4.0, high-priority updates were included, whereas v4.0.1 distinguishes between critical and high - priority updates.6. Multi-Factor Authentication (MFA) Enhancements –     ● Requirement 8.4.2 - Specifies that MFA must be applied to all administrators and users with non-console (remote) access to critical systems.     ● Requirement 8.4.3: Provides more detailed implementation guidelines for MFA mechanisms used for remote access.

What does this mean for organizations?

For companies that have already started PCI DSS v4.0 implementation, the transition to v4.0.1 should be straightforward. . However, organizations should review the updates to:
● Ensure compliance with all new requirements.● Prepare for potential changes in audit procedures, as auditors may now request additional information based on the updated terminology and audit requirements.● Update internal policies and procedures to align with the revised standard.

Conclusion

PCI DSS v4.0.1 is not a major overhaul but rather a refinement of v4.0, improving clarity and security. Organizations that handle payment card data should adapt their processes to meet the new requirements, ensuring compliance and strengthening the highest level of payment data security.
For a detailed overview of all changes in PCI DSS v4.0.1, follow the official link.

IT Specialist - secure integration into the future.

Author: Anastasiia Karmazina, Lead IT Auditor, Audit and Certification Department for Banking and Payment Systems.