PCI DSS v4.0.1: Key Updates and Clarifications

PCI DSS v4.0.1: Key Updates and Clarifications


The PCI Security Standards Council (PCI SSC) has recently released a limited revision to the PCI DSS, resulting in the publication of PCI DSS v4.0.1. This update addresses stakeholder feedback and questions received since PCI DSS v4.0 was published in March 2022. The changes focus on correcting formatting and typographical errors, as well as clarifying the intent and focus of some requirements and guidance.


Importantly, no new requirements have been added, nor have any existing requirements been removed. As with all new versions of PCI DSS, there will be a period where both the current and updated versions will be active. PCI DSS v4.0 will be retired on 31st December 2024, after which PCI DSS v4.0.1 will be the only active version supported by PCI SSC.


For a comprehensive overview of the changes, please refer to the "Summary of Changes from PCI DSS v4.0 to v4.0.1" available in the PCI SSC Document Library.


Here are some of the notable updates included in this revision:


  • Enhancements made in 3.3 provide clarity for issuers and companies involved in issuing services.

  • The update in 6.4.3 offers clarification on the inventory of scripts and its relevance to the organisation's webpages.

  • Notable guidance has been added in 11.3 concerning the vulnerability management process.

  • The refinement in 11.6.1 addresses security-impacting HTTP headers and script contents of payment pages.

  • Various requirement sections now include enhanced guidance on Customer Approach Objectives.

  • Requirement 12 now features detailed guidance tailored for Third-Party Service Providers (TPSPs).


PCI DSS v4.0.1: Key Updates and Clarifications (pci-proxy.com)

To view or add a comment, sign in

More articles by Paul Fitzgerald

  • How Network Tokens Helps Your Business

    How Network Tokens Helps Your Business

    Enabling Secure Payment Processing with Network Tokenization Network tokenization is a transformative approach to…

  • What Does PCI-Proxy Do.........

    What Does PCI-Proxy Do.........

    Take Control of Payment Data Security and PCI Compliance with PCI-Proxy In an era where digital security and trust are…

  • November Blues (PCI-DSS Edition)

    November Blues (PCI-DSS Edition)

    November’s here, skies sullen and gray, The year’s winding down in a frosty display. But while leaves fall, and the…

  • Friday Fun Facts About PCI-DSS

    Friday Fun Facts About PCI-DSS

    Here are some fun and interesting facts about PCI DSS (Payment Card Industry Data Security Standard): Born from the…

  • PCI DSS v4.0.1 SAQs summary

    PCI DSS v4.0.1 SAQs summary

    PCI DSS (Payment Card Industry Data Security Standard) v4.0.

  • How Network Tokens Help The Gaming Industry

    How Network Tokens Help The Gaming Industry

    In the context of the Payment Card Industry (PCI) and the gaming industry, network tokens play a crucial role in…

  • Best Advice For Conference Attendees

    Best Advice For Conference Attendees

    Attending a conference can be a valuable experience if you approach it strategically. Here’s how to get the best out of…

  • Enhancing the Gaming Industry with PCI-Proxy and PCI-DSS Compliance

    Enhancing the Gaming Industry with PCI-Proxy and PCI-DSS Compliance

    The gaming industry, characterized by its rapid growth and global reach, presents unique challenges when it comes to…

  • Importance of PCI DSS:

    Importance of PCI DSS:

    The Payment Card Industry Data Security Standard (PCI DSS) is a comprehensive set of security requirements designed to…

  • Upcoming PCI DSS 6.4.3 and 11.6.1 requirements

    Upcoming PCI DSS 6.4.3 and 11.6.1 requirements

    The Payment Card Industry Data Security Standard (PCI DSS) is a set of security standards designed to ensure that all…

    1 Comment

Insights from the community

Others also viewed

Explore topics