PCI 4.0.1 Requirements

Posted by:

|

On:

|

PCI 4.0 Requirements — Effective APR 2025TRACKER for NEW APR 2025 
DOCUMENTS/EVIDENCE – Storage is kept to a minimum for SAD Stored Prior to Authorization
    Any Sensitive Authentication Data (SAD) stored prior to authorization must be reviewed for retention criteria and purged at least quarterly.
Documents/Evidence Required:
    a) Provide the Pol/Proc that defines the data retention, purge processes
    b) Provide evidence or review data stores to confirm retention/purge of
        SAD data
NEW APR 20253.2.1
DOCUMENTS/EVIDENCE – SAD Stored Prior to Authorization must be Encrypted
    Any Sensitive Authentication Data (SAD) stored prior to authorization must be encrypted with strong encryption.
   Req 3.3.2 for all entities that store SAD
   Req 3.3.3 for Issuers that store SAD

Documents/Evidence Required:
    a) Provide documented business justification for storage of SAD
    b) Provide evidence or review data stores to confirm SAD is encrypted if stored
NEW APR 20253.3.2,
3.3.3 (for Issuers)
DOCUMENTS/EVIDENCE – When using remote-access technologies, technical controls prevent Copy and/or relocation of PAN.
  
A technical control prevents copy of PAN with the exception of specifically authorized users.

Documents/Evidence Required:
   a) Provide the vendor/product/ver and details of tech solution
   b) Provide the configuration settings to meet this requirement
   c) Provide the list of users that are specifically authorized to copy PAN
   d) Provide evidence or review systems to confirm the tech solution is
       implemented and only authorized staff are allowed to copy PAN.
NEW APR 20253.4.2
DOCUMENTS/EVIDENCE – Hashes used to render PAN unreadable are keyed cryptographic hashes with key management
    Hashes used to render PAN unreadable are keyed Cryptographic hashes

Documents/Evidence Required:
   a) Provide documentation/details of how keyed hashing is implemented
   b) Provide evidence or review data stores (and logs) to confirm PAN is
       rendered unreadable.
NEW APR 20253.5.1.1
EVIDENCE – If disk/partiion level encryption is used for non-removable media then also encrypted with another method (to meet 3.5.1)
    Disk/partition level encryption must also include a field/column/db level encryption to protect PAN as per 3.5.1

Documents/Evidence Required:
    a) Provide evidence or review data stores to confirm PAN is rendered
        unreadable as per 3.5.1 controls
NEW APR 20253.5.1.2
DOCUMENTS – The same Encryption Keys must not be used for Prod and Test environments.    (Service Provider Only)

 Documents/Evidence Required:
    a) Provide documentation/details to confirm Enc Keys are not used in
        Prod & Test
NEW APR 20253.6.1.1
DOCUMENTS/EVIDENCE – Certificates for PAN over public networks must be valid and not expired/revoked.     Also must have an inventory of trusted keys/certificates use for protected PAN transmission

Documents/Evidence Required:
   a) Provide Pol/Proc and/or documentation related to certificate handling
   b) Provide evidence or review configurations to confirm certificates are
       valid & not expired.
   c) Provide inventory of trusted keys/certificates used for PAN transmission
NEW APR 20254.2.1
4.2.1.1
DOCUMENTS/EVIDENCE Targeted Risk Analysis – Freq of Perodic Evals for systems without AV
  This TRA should address ESX and similar systems that do not have AntiMalware SW installed.

Documents/Evidence Required:
   a) Provide the TRA for this req
   b) Provide evidence of periodic evalutions of system components
       as per TRA
NEW APR 20255.2.3.1
DOCUMENTS/EVIDENCE Targeted Risk Analysis – If periodic malware scans are used then complete a TRA to define Freq of Malware Scans
  This TRA is required if malware scans are “periodic”.

Documents/Evidence Required:
   a) Provide the TRA for this req
   b) Provide evidence of periodic malware scans as per TRA
       (likely supplied via the system sampling evidence)
NEW APR 20255.3.2.1
EVIDENCE – Malware automatically scans USB’s(or removable media) when installed
   Removable media must be scanned (or use continuous behavioral analysis) when the media is inserted/connected/mounted.

Documents/Evidence Required:
    a)  Provide evidence that use of Removable Media (USBs) are blocked
                           or
    b) Provide evidence of scan tool… (Rem Media Scanned when installed)
         – Configuration settings for Scanning or Behavior Analysis
         – Evidence the scan tool is installed/working on systems
         – Evidence of logs or scan results for scan tool
NEW APR 20255.3.3
EVIDENCE – Processes/mechanisms are in place to detect/protect against Phishing attacks.

Documents/Evidence Required:
   a) Provide vendor/product/ver details on the Phishing solution implemented
   b) Provide evidence to verify Phishing solution is operational
NEW APR 20255.4.1
EVIDENCE – Maintain an inventory of custom software, including 3rd party components, to facilitate vulnerability/patch mgmt.

Documents/Evidence Required:
   a) Provide inventory of custom software & 3rd party components including
       version(s) in use
NEW APR 20256.3.2
EVIDENCE – Public facing web applications must be protected by a Web App Firewall (WAF)

Documents/Evidence Required:
   a) Provide details of WAF/version implemented
   b) Provide/review configuration settings of WAF to include URL’s protected,
       generating logs, configured to block or alert, etc.
   c) If WAF configured to alert, provide evidence alerts are immediately
       investigated.  (Qty 3)
          
NEW APR 20256.4.2
DOCUMENTS/EVIDENCE – Payment page scripts that are loaded and executed in the consumer’s browser are managed as follows:
    – A method is implemented to confirm that each script is authorized.
    – A method is implemented to assure the integrity of each script.
   – An inventory of all scripts is maintained with written justification

Documents/Evidence Required:
   a) Provide the vendor/product/ver of the product and details of the solution
   b) Provide Pol/Proc/details related to managing payment page scripts
   c) Provide inventory of payment page scripts and written justification
   d) Provide evidence or review systems to confirm how payment page scripts
       are authorized and the integrity is validated.
NEW APR 20256.4.3
DOCUMENTS/EVIDENCE – User Access and privileges are reviewed every 6 months
  User accounts and user access, including 3rd party/vendor accounts, must be reviewed every 6 months, confirm access is appropriate, access issues are addressed and mgmt acknowledgement that access is appropriate.

Documents/Evidence Required:
 
   a) Provide Pol/Proc related to user access review processes
   b) Provide documented Review #1
   c) Provide documented Review #2 (6 month or less since Review #1)
 
NEW APR 20257.2.4
DOCUMENTS/EVIDENCE – All App/System accounts and privileges are assigned as follows:
     – Based upon least privilige
     – Access limited to systems/app/processes required for their use

Documents/Evidence to Provide:
    a) Provide the Pol/Proc that specifies app/system account management
    b) Provide evidence that application/system accounts are managed as
        per this requirement.(6 month or less since Review #1)
NEW APR 20257.2.5
DOCUMENTS/EVIDENCE TRA – Targeted Risk Analysis – All access by App/System accounts, and related privileges, are reviewed as defined by a TRA.
  Provide the TRA which defines the frequency of when application and system accounts (and related access privileges) will be reviewed.

Documents/Evidence to Provide:
    a) Provide the Pol/Proc that specifies the process for review of app/system
        account access and privileges.
   b) Provide the TRA
   c) Provide evidence of the application/system account reviews as per TRA
NEW APR 20257.2.5.1
EVIDENCE – If passwords are used for authentication factors (for Req 8.3.1) then passwords must be 12 characters and include both numeric and alpha characters.

Evidence to Provide:
  a) Provide Active Directory password settings for users/systems
      authenticated via AD.
  b) System sample evidence to be reviewed to confirm password settings
     
NEW APR 20258.3.6
EVIDENCE – If “customer users” can access CHD (with single factor authentication) then passwords must change every 90 days or be dynamically analyzed   (Service Providers Only)

Evidence to Provide:
  a) Identify the apps/systems that allow customer users to access CHD.    
  b) Provide password settings from these apps/systems to show
      compliance with this requriement.
NEW APR 20258.3.10.1
EVIDENCE – MFA is implemented for all NON-CONSOLE access into the CDE.
    This control is different than 8.4.1 which requires MFA for Non-Console ADMIN access.   This control requires MFA for all NON-CONSOLE access into the CDE even if it is View Only, etc. (non-admin).    An example, a IT support team member that can login to a network system or server to confirm it is operational — they may have ReadOnly access into the CDE (which requires MFA).    (SOC team, etc.)

Evidence to Provide:
  a) Confirm do non-admin users have the ability to perform NON-CONSOLE
      access to CDE systems?
      If yes, provide details on which users have this access.
  b) Provide evidence and reviews of users with non-admin NON-CONSOLE
      access to the CDE — to confirm MFA is required
NEW APR 20258.4.2
DOCUMENTS/EVIDENCE – MFA systems are implemented as follows:
  – The MFA system is not susceptible to replay attacks.
  – MFA systems cannot be bypassed by any users, including administrative users unless specifically documented, and authorized by management on an exception basis, for a limited time period.

Evidence to Provide:
  a) Provide vendor/product/ver documentation/details to confirm MFA is not
      suceptible to replay attacks.
  b) Provide MFA system configurations to confirm proper configuration
      as per vendor documentation.
  c) Provide evidence or system reviews to confirm MFA is required.
NEW APR 20258.5.1
DOCUMENTS/EVIDENCE – If App/System accounts can be used for Interactive Login, they are managed as follows:
 – Interactive use is prevented unless needed for an exceptional circumstance.
 – Interactive use is limited to the time needed for the exceptional circumstance.
 – Business justification for interactive use is documented.
 – Interactive use is explicitly approved by management.
 – Individual user identity is confirmed before access to account is granted.
 – Every action taken is attributable to an individual user.

Evidence to Provide:
  a) Provide list of App/System accounts that allow Interactive Login.
       (Note: this evidence may be collected individually for each system type
                 or application, etc.)
  b) Provide details of use of the App/System account is managed to meet
      this full requirement (see list above).
NEW APR 20258.6.1
DOCUMENTS/EVIDENCE – Passwords for App/System accounts (that allow interactive login) are not hard coded in scripts, config filed, source code.

Evidence to Provide:
  a) Provide list of App/System accounts that allow Interactive Login.
       (Note: this evidence may be collected individually for each system type
                 or application, etc.)
  b) Provide evidence/details to show App/System account is managed to meet
      this full requirement. 
      (possibly the results from a search of scripts, config files, source code)
NEW APR 20258.6.2
DOCUMENTS/EVIDENCE TRA – Targeted Risk Analysis – Passwords for App/System accounts are changed (and complex) as defined by TRA.

Documents/Evidence to Provide:

   a) Provide the Pol/Proc that specifies app/system account passwords must
        be regularly changed and complex.
   b) Provide the TRA
   c) Provide evidence of the application/system account password changes
       as per TRA
NEW APR 20258.6.3
DOCUMENTS/EVIDENCE TRA – Targeted Risk Analysis – Frequency of POI Inspections is defined by a TRA. 
     This requirement typically would only apply to Merchants.

Documents/Evidence to Provide:

    a) Provide the TRA
    b) Provide evidence of the POI device inspections as per the TRA
NEW APR 20259.5.1.2.1
Evidence – Automated tools are used for review of Logs
    Logs must be reviewed by an automated log review tool

Documents/Evidence to Provide:
  a) Provide the vendor/product/ver of the automated log review tool
  b) Provide configuration evidence of the log review tool
NEW APR 2025
10.4.1.1
DOCUMENTS/EVIDENCE TRA – Targeted Risk Analysis – Frequency of Log Reviews for All Other Systems (not defined in 10.4.1) are defined in a TRA.

Documents/Evidence to Provide:

    a) Provide the TRA
    b) Provide evidence of documented reviews of logs as per the TRA
NEW APR 202510.4.2.1
DOCUMENTS/EVIDENCE – Failures of Critical Security Systems are detected, alerted and addressed promptly
   Processes must be defined for both Merchants and Service Providers to detect and alert on the failure of critical security systems.

Documents/Evidence to Provide:
    a) Provide the Pol/Proc or documentation to show how failures are detected
        and addressed as per this req.
    b) Provide evidence of Alerting related to failures of critical security systems.
        (Qty 3)
NEW APR 202510.7.2
DOCUMENTS/EVIDENCE – Failures of Critical Security Systems are promptly addressed
Processes must be defined for both Merchants and Service Providers to promptly address the failure of critical security systems.

Documents/Evidence to Provide:
    a) Provide the Pol/Proc or documentation to show how failures are detected
        and addressed as per this req.
    b) Provide evidence of prompt Remediation related to failures of critical
        security systems.   (Qty 3)
NEW APR 202510.7.3
DOCUMENT Targeted Risk Analysis – All other Vulns (not crit/high) are addressed as per TRA
Provide a TRA for when other vulnerabilities (Medium/Low) will be addressed

Documents/Evidence to Provide:
    a) Provide the TRA
    b) Provide vulnerability scan reports to show Medium/Low vulns are
        being address as per TRA
NEW APR 202511.3.1.1
DOCUMENTS/EVIDENCE –  Internal vulnerability scans are performed via authenticated scanning as follows:
  – Systems unable to accept credentials for auth scanning are documented.
  – Sufficient privileges are used for systems that accept credentials for
    scanning.
  – If accounts used for authenticated scanning can be used for interactive
    login, they are managed in accordance with Requirement 8.2.2

Documents/Evidence to Provide:
 Provide the following evidence:
   a) Provide Config/Setup details from the Int Vuln Scan tool to perform
       Authenticated Scanning (Observe or screenshots)
   b) Provide a list of IVS Credentials used for Scanning and identify if
       “Interactive Login” is allowed.  Confirm managed as per 8.2.2
   c) Provide list of any systems that are not able to accept credentials for
       authenticated scanning
NEW APR 202511.3.1.2
DOCUMENT – Multi-Tenant Service Providers support customers External Penetration Testing.    (Multi-Tenant SP’s Only)

Documents/Evidence to Provide:
    a) Provide evidence to show compliance with this requirement.
NEW APR 202511.4.7
DOCUMENTS/EVIDENCE –  IDS/IPS systems detect, alert or prevent and address Covert Malware Communications Channels (CMCC)  (Service Provider Only)

Documents/Evidence to Provide:
   a) Provide vendor, product/ver and details on the technical solution
   b) Provide documents and config settings to detect, alert, address CMCC’s
   c) Provide the Inc Resp plan (12.10.1) which defines a response to CMCC’s
NEW APR 202511.5.1.1
DOCUMENTS/EVIDENCE TRA – Targeted Risk Analysis – Unauthorized changes to Payment Pages are detected and responded to:
  – Alerting of unauthorized changes to the security-impacting HTTP headers
    and the payment pages as received by the consumer browser.
 – The mechanism is configured to evaluate the received HTTP headers
    and payment pages.
 – The mechanism functions are performed as follows:
              – At least once weekly                 
    OR    – Periodically as defined in TRA

Documents/Evidence to Provide:

   a) Provide vendor, product/ver and details on the technical solution
   b) Provide evidence to confirm the change tool is implemented for all
       payment pages.
   c) Provide evidence to confirm the change tool functions are performed
       either every 7 days or based upon a specific TRA
   d) Provide the TRA if one is defined for this requirement.
NEW APR 202511.6.1
DOCUMENTS TRA – Targeted Risk Analysis – A TRA is provided for all requirements which specify a TRA

Documents/Evidence to Provide:

  a) TRA for 5.2.3.1 – Freq of evaluation for systems without AV
  b) TRA for 5.3.2.1 – Freq of AV scans if periodic scanning implemented
  c) TRA for 7.2.5.1 – Freq of privilege review for App/System accounts
  d) TRA for 8.6.3  – Freq of password change for App/System accounts
  e) TRA for 9.5.1.2.1 – Freq of POI device inspections
  f) TRA for 10.4.2.1 – Freq of log review for all other systems (not 10.4.1)
  g) TRA for 11.3.1.1 – Timeframe to address Med/Low vulnerabilities
  h) TRA for 11.6.1 – Unauth changes to HTTP Headers/payment Pages
                           performed at defined frequency or 7 days
  i) TRA for 12.10.4.1 – Freq of training for incident response staff.
NEW APR 202512.3.1
DOCUMENTS – Crypto cipher suites/protocols are documented and reviewed every 12 month. 

Documents/Evidence to Provide:
    a) Provide documentation of crypto suites/protocols in use and
        confirmation it is current (within 12 mth).
NEW APR 202512.3.3
DOCUMENTS – Hardware/Software technologies in use are reviewed every 12 months.
   Review of HW/SW should consider security patching, continued patching support, “end of life”, documented/approved plan to remediate outdated technologies.

Documents/Evidence to Provide:
    a) Provide documented review of HW/SW and versions as well as
        confirmation it is current (within 12 mth).
NEW APR 202512.3.4
DOCUMENTS – PCI scope is documented and reviewed every 6 months and upon significant change    (Service Provider Only)

Documents/Evidence to Provide:

    a) Provide documented scope review #1
    a) Provide documented scope review #2
    a) Provide documented scope review related to each Significant Change
NEW APR 202512.5.2.1
DOCUMENTS – Significant changes to organizational structure results in a documented PCI scope review.    (Service Provider Only)

Documents/Evidence to Provide:

    a) Provide documented scope review related to Significant Org changes
NEW APR 202512.5.3
DOCUMENTS/EVIDENCE – Security Awareness program is reviewed at least every 12 months and updated to address new threats and vulnerabilities.

Documents/Evidence to Provide:
  a) Provide evidence of Security Awareness Program review (within 12 mth)
  b) Provide evidence of Security Awareness program training
NEW APR 202512.6.2
DOCUMENTS – Security Awareness training includes awareness of threats and vulnerabilities that coupon impact the security of CHD/SAD including Phishing and Social Engineering.

Documents/Evidence to Provide:

  a) Provide security awareness training content to confirm it includes
      training related to Phishing and Social Engineering.
NEW APR 202512.6.3.1
DOCUMENTS – Security Awareness training includes awareness of acceptable use of End-User Technologies as per 12.2.1

Documents/Evidence to Provide:

  a) Provide security awareness training content to confirm it includes
      training related to awareness of acceptable use of End-User Tech.
NEW APR 202512.6.3.2
DOCUMENTS/EVIDENCE Targeted Risk Analysis – The frequency of training for Incident Response staff is defined by a TRA

Documents/Evidence to Provide:
    a) Provide the TRA
    b) Provide evidence of training for incident response staff as per TRA
NEW APR 202512.10.4.1
DOCUMENTS/EVIDENCE – The Incident Response Plan includes monitoring/alerting related to change and tamper detection mechanisms for payment pages.

Documents/Evidence to Provide:
    a) Provide the Incident Response Plan to confirm it meets this req
    b) Provide evidence changes to payment pages generate an alert and
        trigger a related Incident Response. (Qty 3)
NEW APR 202512.10.5
DOCUMENTS/EVIDENCE – The Incident Response Plan is initiated upon detection of Stored PAN anywhere it is not expected.

Documents/Evidence to Provide:
   a) Provide the Incident Response Plan to confirm it meets this req
   b) Provide evidence of incidents initiated in the event PAN is found anywhere
       it is not expected. (Qty 3)
NEW APR 202512.10.7
Multi-Tenant SP Only — There are several Appendix #1 Requirements to consider for Multi-Tenant Service Providers.

    (Details not listed — see the PCI DSS for details)
NEW APR 2025A1.1

Posted by

in