PCI DSS 3.2.1 is retired. Every merchant and service provider is now assessed against PCI DSS v4.0.1. This guide covers what actually changed, the two requirements that trip up small and mid-sized businesses the most — MFA and authenticated internal scans — and the practical steps to get ready.
The PCI Security Standards Council released PCI DSS v4.0 in March 2022 and the minor errata release v4.0.1 in June 2024. PCI DSS 3.2.1 was formally retired on 31 March 2024. Since 1 April 2024 every SAQ and every Report on Compliance must be completed against v4.0.1 — there is no falling back to 3.2.1.
A second wave of “future-dated” requirements — the ones marked as best practice through 31 March 2025 — became mandatory on 1 April 2025. Those are the ones this guide focuses on, because they are the changes that force new tooling, new evidence, and new conversations with third parties.
Under 3.2.1, multi-factor authentication was required for administrative access and remote access into the cardholder data environment (CDE). Under v4.0.1 Requirement 8.4.2, MFA is required for all non-console access into the CDE — administrator or not. That includes a support engineer opening a ticket console, a developer SSHing into a jump box, and a finance user opening a payment application that lives inside the CDE.
Two more sub-requirements matter for SMBs: 8.4.3 (MFA for all remote access originating from outside the entity's network into the CDE, regardless of user type) and 8.5.1, which sets minimum MFA implementation properties — factors must be independent, replay-resistant, and can't be bypassed by any user, including admins, unless explicitly documented and authorised.
Requirement 11.3.1.2 is new to v4.0.1 and is the change most SMBs discover late. Internal vulnerability scans must now run with credentials — the scanner authenticates into the target system and inspects it from the inside, not just from the network. That surfaces missing patches, weak local configurations, and dormant packages that unauthenticated scans miss entirely.
Practically, this means your scanner needs a service account on every in-scope system, and that account needs enough privilege to enumerate installed software and configuration state. Coordinate with your MSSP or scanning vendor early — retro-fitting authenticated scans across a large fleet is a multi-week project, not a same-week change.
The fastest way to see how the v4.0.1 changes affect your organisation is to run the guided self-assessment — it walks the official PCI SSC eligibility criteria and cites the requirement number behind every question. When you need a signed SAQ or Attestation of Compliance, a QSA takes it from there.