News

PCI DSS v4: Requirements You Must Now Follow

PCI DSS v4 introduced several requirements as best practices during a transition period. These requirements have since become mandatory for organisations assessing their PCI DSS compliance.

Neha Dvivedi · 16 August 2026

The key story is that PCI DSS v4 has moved several requirements from the transition phase into active compliance. Organisations that deferred these requirements during the transition now need to understand how they affect their current PCI DSS assessment. This change is important for businesses that planned to address the requirements later and may now face additional technical work.

Why Businesses Are Feeling the Pressure

Several deferred requirements involve more than updating policies or preparing documents. They may require changes to authentication systems, payment-page security, script monitoring, and risk-assessment processes. Service providers may also need to meet broader security expectations. These changes can involve development work, new tools, and updates to existing systems, so businesses may need more time to prepare than expected.

Payment Page Security Gets More Attention

E-commerce businesses may face particular challenges with requirements related to scripts running on payment pages. Attackers can use unauthorised scripts to capture card data when customers enter their payment details. PCI DSS therefore places greater focus on knowing which scripts are used, understanding why they are needed, protecting their integrity and detecting unauthorised changes.

This can become difficult for merchants that use many third-party tools for analytics, chat, tag management and marketing. Each script adds another item the business needs to review and monitor. Businesses may also need to work closely with their marketing and technology teams to reduce unnecessary scripts and improve payment page security.

Businesses Need to Review Their Current Position

Organisations should first check which PCI DSS v4 requirements applied during their last assessment and identify any requirements that were deferred during the transition period. They should then conduct a gap assessment against the current requirements to understand what still needs attention.

Businesses should prioritize technical changes because engineering work often takes longer than documentation. Script inventories, integrity monitoring and authentication updates may require system changes and testing before an assessment. Early planning can give businesses more time to address these gaps.

ISO and information security consultants can also help organisations review their existing controls, identify gaps and build a structured plan for improvement. However, businesses should confirm current PCI DSS requirements and assessment timelines with their relevant payment partners or acquirer, as validation deadlines can vary.

What this covers

See how this looks as a working system

Reading about a requirement and seeing the documentation that satisfies it are different things. In a short demo we open the actual manual, procedures and records set for PCI DSS, show you how each clause is answered and where your existing way of working already fits. You will know what implementation involves before you commit to it.

Ask us about this

Tell us what is being asked of you and by whom.

What are you looking for?

We reply within one working day. Your details stay with our consultants.

More reading

All articles