PCI Assessments Center
Loading your workspace…
PCI DSS 3.2.1 is retired. Every merchant and service provider is now assessed against PCI DSS v4.0.1. This guide covers what actually changed, the two requirements that trip up small and mid-sized businesses the most — MFA and authenticated internal scans — and the practical steps to get ready.
The PCI Security Standards Council released PCI DSS v4.0 in March 2022 and the minor errata release v4.0.1 in June 2024. PCI DSS 3.2.1 was formally retired on 31 March 2024. Since 1 April 2024 every SAQ and every Report on Compliance must be completed against v4.0.1 — there is no falling back to 3.2.1.
A second wave of “future-dated” requirements — the ones marked as best practice through 31 March 2025 — became mandatory on 1 April 2025. Those are the ones this guide focuses on, because they are the changes that force new tooling, new evidence, and new conversations with third parties.
Under 3.2.1, multi-factor authentication was required for administrative access and remote access into the cardholder data environment (CDE). Under v4.0.1 Requirement 8.4.2, MFA is required for all non-console access into the CDE — administrator or not. That includes a support engineer opening a ticket console, a developer SSHing into a jump box, and a finance user opening a payment application that lives inside the CDE.
Two more sub-requirements matter for SMBs: 8.4.3 (MFA for all remote access originating from outside the entity's network into the CDE, regardless of user type) and 8.5.1, which sets minimum MFA implementation properties — factors must be independent, replay-resistant, and can't be bypassed by any user, including admins, unless explicitly documented and authorised.
Requirement 11.3.1.2 is new to v4.0.1 and is the change most SMBs discover late. Internal vulnerability scans must now run with credentials — the scanner authenticates into the target system and inspects it from the inside, not just from the network. That surfaces missing patches, weak local configurations, and dormant packages that unauthenticated scans miss entirely.
Practically, this means your scanner needs a service account on every in-scope system, and that account needs enough privilege to enumerate installed software and configuration state. Coordinate with your MSSP or scanning vendor early — retro-fitting authenticated scans across a large fleet is a multi-week project, not a same-week change.
Any control you perform at a frequency other than the standard needs a documented risk analysis justifying the frequency. This is a paperwork requirement — but it is a new one and QSAs are asking for it.
If your site takes card data — even through an iframe — you must inventory and integrity-check the scripts loaded on the payment page. This added Content Security Policy hygiene and script-monitoring tooling to a lot of SAQ A-EP scopes.
Almost every requirement family now asks you to document who is responsible for the control. A single named owner per requirement family is enough for most SMBs.
Minimum interactive-account password length moved from 7 to 12 characters (or the maximum the system supports, if less than 12).
The fastest way to see how the v4.0.1 changes affect your organisation is to run the guided self-assessment — it walks the official PCI SSC eligibility criteria and cites the requirement number behind every question. When you need a signed SAQ or Attestation of Compliance, a QSA takes it from there.