What is PCI DSS Version 4?

Issue 5 2023 News & Events, Security Services & Risk Management


Johannes Briel.

A new version of the Payment Card Industry (PCI) Data Security Standard (DSS), a set of security standards developed to protect cardholder data and ensure the secure processing of payment, will become mandatory as of 1 April 2024. Version 4 completely replaces version 3.2.1 and introduces several significant changes that aim to enhance data security and address evolving threats. These include a risk-based approach, enhanced flexibility, scalability, and alignment with modern security practices, and greater emphasis on education and security awareness across the board.

These new requirements have a significant impact on any business that handles card payment information, and organisations need to be prepared ahead of time to ensure compliance when the old version of the standard is retired on 31 March 2024.

The key changes

There are a total of 49 new requirements in PCI DSS 4 and 64 total changes ranging from evolving requirements, clarification or guidance and structure or format of the standard. All changes are designed to ensure that the standard evolves and continues to meet the changing requirements of the payment card industry.

The aim is to promote security as a continuous process, rather than a once-off exercise, and as such, the new standard incorporates a more flexible approach ‘customised approach’ as an enhanced way for entities to meet the security objective of the control that addresses the risk and alternative validation methods for auditors.

Certain security controls will become mandatory, including web application firewalls and multi-factor authentication (MFA) for all interactions relating to cardholder data. Other elements include changes to password requirements to enhance security, authentication of internal vulnerability assessments and an increased emphasis on security awareness, particularly around phishing and social engineering. Training will also become mandatory for all employees under the new version of the standard. In addition, automation of log reviews has become a requirement, as there is simply far too much data for effective manual reviews.

Security is a journey, not a destination

It's important to understand that achieving and maintaining PCI DSS compliance is not a one-time event or a fixed state. It's an ongoing process that requires continuous effort, monitoring, and improvement. Here's why security is considered a journey.

Cybersecurity threats and attack techniques in the payment card space have evolved significantly as more businesses have moved online, and security as a continuous process has become essential to protect payment data, which has become an increasingly attractive target for cybercriminals. PCI DSS 4 aims to address this by mandating clearly defined and assigned roles and responsibilities for each requirement, for merchants and third-party service providers. The new standard also provides additional guidance to help entities better understand how to implement and maintain security.

Because security can no longer be a static framework, the new version of the standard also increases flexibility for organisations that use various methods to achieve their security objectives. This supports payment technology innovation and gives organisations the ability to adapt their security practices through targeted risk assessments and analysis. To support this, the customised approach offers enhanced validation methods and procedures.

Don’t go at it alone

With the new recommendations and requirements introduced in PCI DSS 4, it can be challenging to understand how it applies to your business. This is particularly true when it comes to cloud-based and hybrid environments, which add a layer of complexity. While it is possible to do this in-house if you have an internal security auditor, for most businesses this is simply not the case, and even so, would require a heavy lift in terms of understanding and interpreting the changes. Enlisting the help of a Qualified Security Assessor (QSA) can help to ease the transition and ensure that all areas are effectively covered.

A QSA can take you through a gap analysis to identify where changes to the standard will have an effect and require changes to be made. From there, they can compile a roadmap to remediate gaps and align with version 4, ready for its implementation. This is important in helping to clarify scope and understand the requirements for meeting the new standards, in terms of both process and technology. A QSA will also be able to conduct a mock audit to validate any changes made and ensure they can be adjusted and adapted to align with the new standard.




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Hytera supports communication upgrade for Joburg
News & Events Infrastructure Government and Parastatal (Industry)
By equipping Johannesburg’s metro police and emergency services with multimode radios which integrate TETRA and LTE networks, Hytera is bridging coverage gaps and improving response times across the city.

Read more...
The global generative AI market surpassed $130 billion in 2024
News & Events AI & Data Analytics
According to a new research report from the IoT analyst firm, Berg Insight, the Generative AI (GenAI) market grew substantially in 2024, experiencing triple-digit growth rates in all three major segments: GenAI hardware, foundation models, and development platforms.

Read more...
Your Wi-Fi router is about to start watching you
News & Events Surveillance Security Services & Risk Management
Advanced algorithms are able to analyse your Wi-Fi signals and create a representation of your movements, turning your home's Wi-Fi into a motion detection and personal identification system.

Read more...
ProtecLink 2025: Ithegi Electronics supports a safer, smarter security ecosystem
News & Events
If you are a security buyer, operations lead, or technology partner, do not miss ProtecLink 2025, to be held in Polokwane on 16 September 2025, at the Polokwane Royal Hotel.

Read more...
IZI Group acquires G4S Cash Solutions South Africa
News & Events
IZI Africa, a sister company within the IZI Group, has acquired G4S Cash Solutions (SA) following the receipt of all necessary regulatory approvals. This transaction marks a significant consolidation in the South African cash handling industry.

Read more...
Secutel maintains ISO certifications
News & Events Fire & Safety
Secutel Technologies has successfully recertified all four of its ISO standards, a reflection of its continued commitment to excellence, client trust, and operational integrity.

Read more...
SABRIC appoints Andre Wentzel as interim CEO
News & Events Financial (Industry) Associations
The South African Banking Risk Information Centre (SABRIC) has announced the appointment of Andre Wentzel as interim chief executive officer, effective immediately.

Read more...
Choicejacking bypasses smartphone charging security
News & Events Information Security
Choicejacking is a new cyberthreat that bypasses smartphone charging security defences to confirm, without the victim’s input or consent, that the victim wishes to connect in data-transfer mode.

Read more...
Paxton cuts emissions by over a third
Paxton News & Events
Paxton has announced a significant reduction in its carbon footprint, cutting emissions by 961 tonnes of CO2e in its 2023 second reporting year.

Read more...
Most wanted malware
News & Events Information Security
Check Point Software Technologies unveiled its Global Threat Index for June 2025, highlighting a surge in new and evolving threats. Eight African countries are among the most targeted as malware leaders AsyncRAT and FakeUpdates expand.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.