What are the New Pci Dss 4.0 Requirements for 2026?

As of 2026, the transition to PCI DSS 4.0 is mandatory for all organizations, as the previous version (3.2.1) has been retired. The updated standard moves away from a one-size-fits-all approach, allowing businesses to tailor security controls to their specific environments while mandating several critical updates.

To meet the 2026 requirements, businesses must implement the following key controls:

  • Multi-Factor Authentication (MFA): Mandatory for all administrative access to systems that handle cardholder data and for all access to the cardholder data environment (CDE).
  • Enhanced Encryption: Strong cryptography must be applied to all cardholder data both at rest and in transit.
  • Continuous Security Monitoring: Organizations must move toward ongoing monitoring combined with quarterly vulnerability scans conducted by an Approved Scanning Vendor (ASV).
  • Formal Security Awareness Training: Under version 4.0, a formal staff training program—covering phishing identification and secure payment procedures—is no longer optional but a compliance mandate.
  • Strict Access Controls: Implementation of role-based user permissions is required to limit data exposure.
  • Annual Validation: Merchants must identify their specific compliance level (Levels 1-4) and complete the appropriate Self-Assessment Questionnaire (SAQ) or Report on Compliance (ROC) annually.

Related FAQs