The Payment Card Industry Data Security Standard (PCI DSS), which underwent a significant update in March 2022, has recently been revised.
On 11 June 2024, the Payment Card Industry Security Standards Council (PCI SSC) released a limited revision to the PCI Data Security Standard (PCI DSS), updating it to version 4.0.1.
This update is primarily aimed at correcting formatting and typographical errors and clarifying the focus and intent of some of the requirements and guidance. Importantly, this revision does not introduce any new requirements or remove existing ones. However, it’s crucial for organisations that process, store, transmit, or impact the security of cardholder data and sensitive authentication data.
PCI DSS v4.0.1 is a limited revision to the previous version 4.0, released in March 2022. This update addresses stakeholder feedback and questions received since the release of v4.0, emphasising the continuous effort to enhance payment account data security and promote the broad adoption of consistent data security measures globally.
PCI SSC involved a broad range of stakeholders in the review process. From December 2023 through January 2024, feedback was gathered from the PCI SSC Board of Advisors, the Global Executive Assessor Roundtable (GEAR), and Principal Participating Organisations, who provided insights and suggestions during a Request for Comments (RFC) period.
Risk Associates is a proud member of the PCI GEAR. This collaborative approach helped refine the changes and ensure they support the industry’s adoption of PCI DSS v4.0.