Share this article
At the end of March 2022, PCI DSS released its latest update, bringing further security and guidance to the way organisations handle payment card information. No matter the size of your business, or the volume of payments you take, it’s important that you understand what impact these changes will have on the way you run your organisation.
We’re going to take a closer look at just how much PCI DSS V4.0 differs from its predecessor, and what steps you need to take going forward.
One of the most obvious changes to the PCI standard is that it has grown. In an effort to provide as much detail as possible, the PCI SSSC has increased the size and number of information guides available. Some of the information which was previously resigned to supplementary guides has now been deemed important enough to be included in the standard itself – providing greater clarity and context.
With this increase in length comes an increase in the total number of requirements for compliance, though it may not seem like it on first glance. The PCI SSC has flattened some multi-part requirements into a single requirement, but nothing has been taken out. Acceptable use, for example, comprised four requirements in PCI DSS v3.2.1 but only one in PCI DSS v4.0.
What’s more, Future Dated Requirements are also included in the fresh model, with a live date of Q1 2025. You should be aware of these, but they need not burden your organisation changes too much at this point, especially if there could be costs involved.
A welcome change to PCI DSS v4.0 is that it’s much more technology friendly. Where v3.2.1 sometimes felt behind the times, the latest PCI DSS model celebrates agnostic descriptions such as ‘network security control’ in place of ‘firewall’, and ‘system’ in place of ‘server’. This allows a greater number of organisations to apply PCI DSS guidelines to their chosen tech much more easily.
Finally, more so than any other model to come before it, PCI DSS v4.0 recognises the importance of risk assessment. Events like crypto periods, end-of-life for products and security products have famously caused struggles for organisations in the past, causing issues. These elements have now been integrated much more readily into the PCI DSS guidelines, making it easier than ever to follow best practice in a context specific way.
The first thing to bear in mind regarding these changes is there is no need to panic or rush in your decision making, as the timeline for transition is generous. As the development of v4.0 has introduced significant changes, PCI DSS v3.2.1 is expected to be around until the beginning of 2024. In line with this the updated Self Assessment Questionnaires (SAQs) for version 4.0 aren’t currently expected to be released until late 2022 or early 2023.
However, this doesn’t mean you should wait until this time to act. Now is the time to get familiar with the new PCI DSS guidelines, and seek out support from a Qualified Security Assessor. Review the standard, understand what your customers expect from you, and work with your QSA to build an effective plan. Most organisations will have at least one more cycle of assessment using PCI DSS v3.2.1 guidelines, but it’s advised that you don’t wait until that completes before you start planning ahead with the new criteria in mind.
Looking for help with the new changes to PCI DSS? Get the support you need to achieve PCI DSS v4.0 compliance by getting in touch with the experts at SRM today. Click here to contact a member of our team.