PCI Security Standards Council Blog Updates - PCI DSS Version 4.0

PCI Security Standards Council Blog Updates - PCI DSS Version 4.0

By Nancy Rand
Posted in Security
On March 17, 2022

The PCI Council published a blog announcing the coming of PCI DSS version 4.0 at the end of March 2022 https://blog.pcisecuritystandards.org/countdown-to-pci-dss-v4.0. The blog contains a PCI DSS Version 4.0 Implementation timeline.

The new standard document, the Summary of Changes v3.2.1 to 4.0 will be released along with the Report on Compliance ROC Template and Attestations of Compliance AOC documents at the end of March 2022.

The Self-Assessment Questionnaires SAQs will be available shortly after.

Training for QSAs and ISAs to support version 4.0 is to be available in June 2022.

The current standard PCI DSS version 3.2.1 will remain effective until March 31, 2024, when PCI DSS version 4.0 will be the only active version. A transition period will exist between March 2022 and March 31, 2024, where both versions will be active.

Future dated requirements will become effective March 31, 2025.

Nancy Rand

Nancy Rand

Nancy has more than 20 years’ experience in information technology and security, solving business issues and implementing best-practice solutions that support organizational objectives. Her expertise includes leveraging, optimizing, and implementing diverse technology platforms, and management of large-scale technology projects.