Payment Card Industry Data Security Standard version 4.0 Changes and the Impact to Self-Assessments
The new Payment Card Industry Data Security Standards (PCI DSS) compliance framework version 4.0 calls for several changes to the Standards that impact the various Self-Assessment Questionnaires (SAQs).
It should be noted that while the biggest change with version 4.0 may be that entities have the option of using the new customized approach versus the defined approach, this article will not discuss the customized approach because it is not permitted to be used when completing a Self-Assessment Questionnaire.
In addition to the rollout of the customized approach, there are several other changes (refer to the Table below), which the PCI Security Standards Council (SSC) has categorized as follows:
Finally, each of the 12 PCI DSS Requirements call for the assignment of roles and responsibilities for all activities in each respective requirement, impacting SAQ D.
Several changes require additional and/or enhanced security protections impacting various SAQs, such as the following:
Details for requirements noted in the table above:
Requirements that are effective immediately with any v4.0 assessment (and all assessments beginning 3/31/2024) include:
We recommend beginning your assessment of the PCI DSS v4.0 framework now.
RubinBrown has decades of experience in the technology industry. Discover how our cybersecurity services are vital to ensure your sensitive data is thoroughly protected from potential cyber attacks.
Published: 08/21/2023
Readers should not act upon information presented without individual professional consultation.
Any federal tax advice contained in this communication (including any attachments): (i) is intended for your use only; (ii) is based on the accuracy and completeness of the facts you have provided us; and (iii) may not be relied upon to avoid penalties.