The planning of PCI DSS v4.0 began in 2017. Although it generally takes a year to complete a new version, this one was finalised only in 2022, as more than 200 companies contributed with 6,000 comments.
This comprehensive feedback resulted in the setting of the following four major goals for v4.0:
I. For PCI DSS Standard to continue to meet the security standards of the payment industry in view of evolving threats:
· Multi-factor authentication requirements tightened,
· Passwords requirements updated,
· In the context of current cyber concerns, standards regarding e-commerce and phishing are implemented.
II. To encourage security as a continuous process:
· A condition to assign roles and responsibility for each requirement,
· Guidance added to implement and make the maintenance of security easier to understand,
· With new reporting alternative, areas to improve are emphasised and transparency provided for the report reviewers.
III. To increase flexibility so that organisations can achieve security goals with different means:
· Permission requirement for group, shared and public accounts is introduced,
· Targeted risk analysis introduced to clarify what actions needed to be taken and how frequently,
· New and Customized Approach is offered, which allows organisations to use new methods to achieve the security goals.
IV. To diversify verification methods and procedures, the information summarised in AoC, Compliance Report or SAQ are aligned.