- Full name
- PCI Data Security Standard v4.0 / v4.0.1
- Region
- International (mandated by payment-card brands)
- Applies to
- Any entity that stores, processes, or transmits cardholder data, plus the service providers that support them. The standard scales with merchant volume but applies to all in-scope environments.
PCI DSS v4.0 (with the v4.0.1 errata effective from March 2025) is the current Payment Card Industry Data Security Standard. The v4.0 revision significantly strengthened identity requirements — particularly around multi-factor authentication, automated user management, and credential strength — and moved several controls from best-practice into mandatory after the 31 March 2025 transition date.