News
PCI DSS v4: Requirements You Must Now Follow
PCI DSS v4 introduced several requirements as best practices during a transition period. These requirements have since become mandatory for organisations assessing their PCI DSS compliance.
Neha Dvivedi · 16 August 2026
The key story is that PCI DSS v4 has moved several requirements from the transition phase into active compliance. Organisations that deferred these requirements during the transition now need to understand how they affect their current PCI DSS assessment. This change is important for businesses that planned to address the requirements later and may now face additional technical work.
Why Businesses Are Feeling the Pressure
Several deferred requirements involve more than updating policies or preparing documents. They may require changes to authentication systems, payment-page security, script monitoring, and risk-assessment processes. Service providers may also need to meet broader security expectations. These changes can involve development work, new tools, and updates to existing systems, so businesses may need more time to prepare than expected.
Payment Page Security Gets More Attention
E-commerce businesses may face particular challenges with requirements related to scripts running on payment pages. Attackers can use unauthorised scripts to capture card data when customers enter their payment details. PCI DSS therefore places greater focus on knowing which scripts are used, understanding why they are needed, protecting their integrity and detecting unauthorised changes.
This can become difficult for merchants that use many third-party tools for analytics, chat, tag management and marketing. Each script adds another item the business needs to review and monitor. Businesses may also need to work closely with their marketing and technology teams to reduce unnecessary scripts and improve payment page security.
Businesses Need to Review Their Current Position
Organisations should first check which PCI DSS v4 requirements applied during their last assessment and identify any requirements that were deferred during the transition period. They should then conduct a gap assessment against the current requirements to understand what still needs attention.
Businesses should prioritize technical changes because engineering work often takes longer than documentation. Script inventories, integrity monitoring and authentication updates may require system changes and testing before an assessment. Early planning can give businesses more time to address these gaps.
ISO and information security consultants can also help organisations review their existing controls, identify gaps and build a structured plan for improvement. However, businesses should confirm current PCI DSS requirements and assessment timelines with their relevant payment partners or acquirer, as validation deadlines can vary.
What this covers
See how this looks as a working system
Reading about a requirement and seeing the documentation that satisfies it are different things. In a short demo we open the actual manual, procedures and records set for PCI DSS, show you how each clause is answered and where your existing way of working already fits. You will know what implementation involves before you commit to it.
More reading
- The Best Way to Simplify PCI Compliance is to Handle Less Cardholder Data
PCI DSS is pushing businesses to rethink how much card data they handle. Reducing card data can simplify security controls and lower PCI DSS scope.
16 August 2026
- Automotive Suppliers Face Stricter Cybersecurity Assessments
Cybersecurity is becoming a key part of supplier evaluations in the automotive industry. Vehicle manufacturers now check how suppliers protect data and systems alongside quality, cost, and delivery.
13 September 2026
- Automotive OEM Vendor Cybersecurity Assessment: Controls, Scoring and ISO Standards Mapping
What does an automotive vendor cybersecurity assessment cover?
13 September 2026
