Every future-dated requirement in PCI DSS 4.0.1 became mandatory on March 31, 2025 — here's what merchants still need to lock down.
PCI DSS 4.0.1 Compliance Checklist for Ecommerce Businesses
A practical checklist covering the PCI DSS 4.0.1 requirements ecommerce merchants and their payment pages need to satisfy now that all future-dated controls are enforced.
PCI DSS 4.0.1 is the current version of the Payment Card Industry Data Security Standard, and as of March 31, 2025, every requirement — including those that were previously future-dated — is now fully enforceable. Any business that stores, processes, or transmits cardholder data needs to work through this checklist.
Core requirement areas (1-6)
Network security — Install and maintain firewalls/network controls that isolate the cardholder data environment (CDE) from the rest of your network.
Secure configuration — Never use vendor-supplied default passwords or security settings on any system component.
Data protection — Protect stored cardholder data with strong encryption, and encrypt transmission of cardholder data across open, public networks.
Vulnerability management — Protect all systems against malware and keep anti-virus/anti-malware mechanisms current.
Secure development — Develop and maintain secure systems and software, including regular patching.
Access control basics — Restrict access to cardholder data on a strict business need-to-know basis.
Monitoring, testing and governance (7-12)
Identify and authenticate access — Assign a unique ID to every person with system access; MFA is now mandatory for anyone accessing the CDE, not just administrators.
Restrict physical access — Lock down physical access to systems and media that hold cardholder data.
Log and monitor — Track and log all access to network resources and cardholder data, with real-time alerting.
Payment page script integrity (new in 4.0) — Requirement 6.4.3 mandates managing and authorizing all scripts on payment pages, and 11.6.1 requires a change-detection mechanism that alerts on unauthorized modifications — both aimed at stopping digital skimming (Magecart-style) attacks.
Test security regularly — Run quarterly vulnerability scans and periodic penetration tests.
Maintain a policy — Document and maintain an information security policy covering all personnel.
Sources
Security Boulevard: PCI DSS 4.0 Checklist for 2026, UpGuard: How to Comply with PCI DSS 4.0.1.
Frequently asked questions
Yes — PCI DSS applies to any business that stores, processes, or transmits cardholder data, though the validation level (self-assessment questionnaire vs. on-site audit) scales with transaction volume.
4.0.1 adds roughly 60 new requirements versus 3.2.1, including mandatory MFA for all CDE access and real-time monitoring of scripts loaded on payment pages to catch e-skimming attacks.
Yes — if a PCI-compliant processor or gateway tokenizes card data before it touches your servers, much of your environment can fall outside PCI scope, which is usually the fastest way for a small merchant to reduce audit burden.
