1Introduction
PCI DSS sets technical and operational requirements for any organisation that stores, processes or transmits cardholder data. Version 4.0 was published in March 2022 and v3.2.1 was retired on 31 March 2024.
2Discussion
Key changes include expanding multi-factor authentication to all access into the cardholder data environment, requiring integrity controls for scripts on payment pages to counter skimming, and targeted risk analysis to set the frequency of some controls. A new customised approach lets organisations meet security objectives with alternative controls.
3Conclusion
Future-dated requirements became mandatory on 31 March 2025. For payment businesses, compliance is both a contractual obligation and a foundation of customer trust.
Sources
همفکران فناوری شریفThis article summarises the official sources cited, prepared by the Hamfekran Fanavari Sharif team for finance leaders.
Want to see these solutions in your organisation?Book a free demo
همفکران فناوری شریف

