Skip to content
Reference
A grey concrete bank building
Resource

Every future-dated requirement in PCI DSS 4.0.1 became mandatory on March 31, 2025 — here's what merchants still need to lock down.

PCI DSS 4.0.1 Compliance Checklist for Ecommerce Businesses

A practical checklist covering the PCI DSS 4.0.1 requirements ecommerce merchants and their payment pages need to satisfy now that all future-dated controls are enforced.

PV

Parivestra Research Desk

22 July 2026 · 1 min read

Share

PCI DSS 4.0.1 is the current version of the Payment Card Industry Data Security Standard, and as of March 31, 2025, every requirement — including those that were previously future-dated — is now fully enforceable. Any business that stores, processes, or transmits cardholder data needs to work through this checklist.

Core requirement areas (1-6)

Network security — Install and maintain firewalls/network controls that isolate the cardholder data environment (CDE) from the rest of your network.

Secure configuration — Never use vendor-supplied default passwords or security settings on any system component.

Data protection — Protect stored cardholder data with strong encryption, and encrypt transmission of cardholder data across open, public networks.

Vulnerability management — Protect all systems against malware and keep anti-virus/anti-malware mechanisms current.

Secure development — Develop and maintain secure systems and software, including regular patching.

Access control basics — Restrict access to cardholder data on a strict business need-to-know basis.

Monitoring, testing and governance (7-12)

Identify and authenticate access — Assign a unique ID to every person with system access; MFA is now mandatory for anyone accessing the CDE, not just administrators.

Restrict physical access — Lock down physical access to systems and media that hold cardholder data.

Log and monitor — Track and log all access to network resources and cardholder data, with real-time alerting.

Payment page script integrity (new in 4.0) — Requirement 6.4.3 mandates managing and authorizing all scripts on payment pages, and 11.6.1 requires a change-detection mechanism that alerts on unauthorized modifications — both aimed at stopping digital skimming (Magecart-style) attacks.

Test security regularly — Run quarterly vulnerability scans and periodic penetration tests.

Maintain a policy — Document and maintain an information security policy covering all personnel.

Sources

Security Boulevard: PCI DSS 4.0 Checklist for 2026, UpGuard: How to Comply with PCI DSS 4.0.1.

Frequently asked questions

Yes — PCI DSS applies to any business that stores, processes, or transmits cardholder data, though the validation level (self-assessment questionnaire vs. on-site audit) scales with transaction volume.

4.0.1 adds roughly 60 new requirements versus 3.2.1, including mandatory MFA for all CDE access and real-time monitoring of scripts loaded on payment pages to catch e-skimming attacks.

Yes — if a PCI-compliant processor or gateway tokenizes card data before it touches your servers, much of your environment can fall outside PCI scope, which is usually the fastest way for a small merchant to reduce audit burden.