What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
A CISO should be able to explain which PCI DSS version the organization is validating against, whether the requirements effective since 31 March 2025 apply to its environment, how payment flows determine assessment scope, and who owns payment-page security. PCI DSS v4.0.1 clarified and corrected the earlier v4.0 release; it did not add or remove requirements. The decisions below help leadership set ownership and ask for the right evidence, but they do not replace the standard or an assessment.
1. What changed in PCI DSS 4.0.1?
PCI DSS v4.0.1 is a limited revision to v4.0, not a new control set. The PCI Security Standards Council (PCI SSC) says the update corrects formatting and typographical errors and clarifies the focus and intent of some requirements and guidance. It adds or deletes no requirements. Confirm that the organization and its assessor are using the applicable standard and validation documents. PCI SSC’s June 11, 2024 announcement describes the revision.
2. Are the future-dated PCI DSS requirements in effect now?
Yes. The effective date for the future-dated requirements was 31 March 2025, and v4.0.1 did not move it. In a March 2025 interview, PCI SSC’s Director of Data Security Standards described 64 new requirements released in PCI DSS, 51 of them future-dated. That count describes the transition history; it does not mean v4.0.1 introduced 64 requirements. Requirements applicable to the organization must now be considered in its assessment. PCI SSC’s March 26, 2025 podcast and guidance discuss the transition, while FAQ 1585 addresses implementation timing.
3. Which assessment and reporting path fits our payment environment?
Start with how payment data moves, not with the name of a provider or the questionnaire the organization used last year. Map payment flows, account-data handling, systems, payment pages, and third parties that can affect payment security. Then confirm the applicable assessment and reporting route with the entity that accepts the compliance result, typically the payment brand or acquirer. PCI SSC publishes standards and guidance, but does not enforce compliance or decide whether a particular implementation is compliant. Its FAQ 1585 explains that compliance-program and reporting questions should go to the relevant compliance-accepting entity.
Free tools Windows power users keep installed
One-click scans. No signup required.
#1 Best Overall
- Which systems store, process, or transmit account data?
- Which systems, scripts, services, or people can affect the security of payment or the systems handling it?
- What validation route and reporting format does the acquirer or payment brand require?
- Which responsibilities are performed by the organization and which by a service provider, and what evidence demonstrates each?
4. Who owns payment-page script and tamper controls?
Requirements 6.4.3 and 11.6.1 address payment-page script authorization and integrity, and detection of unauthorized changes to payment-page content or HTTP headers. They are intended to reduce e-skimming risk. Assign named ownership across application development, e-commerce operations, security monitoring, and relevant service providers; define who maintains evidence and who investigates alerts. PCI SSC’s March 10, 2025 Payment Page Security and Preventing E-Skimming information supplement offers implementation guidance, but it does not add, extend, replace, or supersede PCI DSS requirements.
5. Does using a third-party payment provider take us out of scope?
No. Outsourcing payment functions does not, by itself, establish that every merchant system or page is out of scope or remove the merchant’s responsibilities. Determine what the provider handles, what the merchant still operates, and whether merchant-controlled pages or connected systems can affect payment security. Document the division of responsibility and evidence it with the provider and the compliance-accepting entity’s current instructions. Eligibility for a self-assessment questionnaire (SAQ) should be confirmed with the organization receiving the result, not inferred from a vendor relationship.
6. What changed for SAQ A?
In January 2025, PCI SSC revised SAQ A by removing requirements 6.4.3 and 11.6.1, as well as supporting requirement 12.3.1, from that questionnaire. It also added an eligibility criterion requiring confirmation that the merchant’s site is not susceptible to script attacks that could affect its e-commerce system. PCI SSC says these questionnaire changes do not remove or diminish the underlying PCI DSS requirements. SAQ A is for qualifying merchants that fully outsource account-data functions and do not electronically store, process, or transmit account data on their systems or premises. Check the current SAQ and eligibility instructions with the entity accepting the validation. See PCI SSC’s January 30, 2025 update.
7. How should superseded requirements appear in reports?
PCI SSC’s reporting FAQ says that, after 31 March 2025, requirements marked as superseded should be reported as not applicable in a Report on Compliance (ROC) or SAQ. Its example is requirement 6.4.1 being superseded when 6.4.2 becomes effective. Follow the current validation-document instructions and confirm the applicable assessment scope when preparing a report. See PCI SSC FAQ 1593.
8. Who decides which validation approach and specialist support we need?
The acquirer or payment brand managing the compliance program typically determines which validation and reporting approach it accepts. Ask that entity whether the organization is eligible for an SAQ, requires another assessment route, or needs external scanning. Where appropriate, a Qualified Security Assessor (QSA) can support assessment work and an Approved Scanning Vendor (ASV) can provide external vulnerability scanning. Verify provider qualifications and current program standing before engagement. PCI SSC’s payment-page security supplement also directs organizations to their compliance-accepting entity for program-specific questions.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

