As of 2026-09-26, v4.0.1 is the only active version, and every requirement, including those once future-dated, has applied since March 31, 2025. PCI SSC ran a request for comments on v4.0.1 from June 3 to July 20, 2026, and has announced no successor version or date.
Checked on . Standards change, so confirm against the official source before you rely on it.
PCI DSS, the Payment Card Industry Data Security Standard, is a baseline of technical and operational requirements designed to protect payment account data. The PCI Security Standards Council (PCI SSC) maintains it, and it applies to entities that store, process, or transmit cardholder data or sensitive authentication data, or that could affect the security of the cardholder data environment.
PCI SSC doesn't enforce compliance. Whether you must comply, and how you validate, is decided by the organizations that manage compliance programs, such as the payment brands and your acquirer.
Version 4.0.1 was a limited revision of v4.0 with no new or deleted requirements. The 51 requirements that were future-dated in v4.0 became effective on March 31, 2025.
02
PCI DSS readiness, from scope to evidence
Readiness helps you understand scope, organize controls and evidence, and remediate gaps before your self-assessment or formal QSA assessment.
Readiness
PCI DSS readiness, scoping, and remediation advisory
What’s included
Scoping: trace where payment card data flows and which systems, people, and service providers are in scope, and look for ways to reduce it
Gap assessment against the PCI DSS v4.0.1 requirements that apply to you
Self-Assessment Questionnaire support: preparing the SAQ your acquirer says applies
Remediation advisory: a prioritized plan your team carries out, with our review
Policy and evidence preparation for your SAQ or formal assessment
A good fit when
You’re validating for the first time, or after a change to how you take payments
You want to shrink your scope before anyone assesses it
You use SAQ A and need to check the 2025 changes
What readiness isn’t
Readiness work doesn't validate your compliance. We don't complete or sign your Self-Assessment Questionnaire or Attestation of Compliance for you; your organization does.
PCI SSC rules bind whoever performs your formal assessment. Under its FAQ 1562, a QSA Employee who designed, developed, or implemented controls for a customer may not assess those controls.
Readiness work stays on the preparation side of that line. Your team makes the changes with our advice and review, and the validation itself is a formal assessment by a PCI SSC-listed QSA Company, or your organization’s own SAQ if your acquirer accepts one.
Practitioners who worked on your readiness engagement don't take part in your formal assessment, examination, or certification audit, including as a subcontractor or specialist to the assessor.
Security Inspect doesn't perform ASV scans, PCI Forensic Investigator (PFI) investigations, or P2PE, Software Security Framework (SSF), PIN, or 3DS assessments. Each is a separate PCI SSC program with its own qualification and listing.
ASV scans. Approved Scanning Vendor program: external vulnerability scans for Requirement 11.3.2
PFI investigations. PCI Forensic Investigator program: investigations after a suspected payment card compromise
P2PE assessments. Point-to-point encryption solution assessments, under the P2PE Assessor program
SSF assessments. Software Security Framework assessments, under the Secure Software and Secure SLC Assessor programs
PIN assessments. PIN transaction security assessments, under the Qualified PIN Assessor program
3DS assessments. 3-D Secure environment assessments, under the 3DS Assessor program
Your acquirer or the payment brands decide which validation form you need, so ask them before you plan the work. PCI SSC maintains the standard but doesn’t enforce compliance itself.
PCI DSS validation paths: who performs each and who signs
Outcome
Who performs it
Who signs
Report on Compliance (ROC) with an Attestation of Compliance (AOC)
A QSA Company listed by PCI SSC, through a QSA Employee. An individual’s QSA qualification is active only while they work for a listed QSA Company.
The QSA Company’s assessor signs for the assessment; an officer of your organization signs the attestation of compliance.
Self-Assessment Questionnaire (SAQ) with its attestation
Your own organization.
An executive officer of your organization. If a QSA or ISA helped, the attestation records that involvement.
An Approved Scanning Vendor (ASV) listed by PCI SSC.
The ASV issues the scan report. You engage the ASV directly.
06
Deliverables
Deliverables // Readiness
What readiness delivers
Scoping summary and data-flow review
Gap assessment against PCI DSS v4.0.1
Prioritized remediation plan
Evidence checklist for your QSA assessment or SAQ
07
How it works, from scope to validation
Fig. 01 // Scope → validation
01
Scope
Find where payment card data goes and which systems, people, and providers the standard reaches.
02
Evidence
Compare what you do with the v4.0.1 requirements that apply, and collect the records that show it.
03
Remediation
Your team fixes what’s missing, in priority order, with advice and review along the way.
04
Validation · outside the readiness work
A PCI SSC-listed QSA Company that had no part in the first three stages assesses the controls and documents the result in a ROC. If your acquirer accepts an SAQ, your organization completes and signs it instead.
01
Confirm how you validate
Ask your acquirer or the payment brands whether you need a ROC or an SAQ, and which SAQ applies.
02
Scope
Map payment card data flows, systems, and service providers, and look for ways to reduce what’s in scope.
03
Gather evidence
Compare your controls and evidence with the PCI DSS v4.0.1 requirements that apply to you.
04
Remediate
Agree on a prioritized plan. Your team makes the changes; the readiness practitioner advises and reviews.
05
Validate
A PCI SSC-listed QSA Company that had no part in the readiness work assesses your controls and documents the result in a ROC, or your organization completes its own SAQ if your acquirer accepts one.
08
What PCI DSS readiness costs
Pricing // USD
Readiness
PCI DSS Readiness
From$8,000
Typical scoped range: $8,000 to $22,000
One-time project
Non-binding. Final pricing follows a written scope and proposal.
What affects the final price
Pricing depends on environment size, complexity, testing depth, locations, applications, accounts, user roles, compliance objectives, and delivery timeline. Every engagement begins with a written scope and proposal. Taxes, travel, remediation, third-party audit or certification fees, licensing, and emergency work are separate. Readiness services do not include independent certification, attestation, legal advice, or a guarantee of passing.
PCI DSS v4.0.1 is the only active version of the standard as of 2026-09-27. PCI SSC published it on June 11, 2024 as a limited revision of v4.0, with no added or deleted requirements, and retired v4.0 on December 31, 2024.
Version 4.0 introduced 64 new requirements. Of those, 51 were future-dated: best practice until March 31, 2025, and required since then, so they're fully considered in any assessment after that date. They include the payment page script controls in Requirements 6.4.3 and 11.6.1 and the documented targeted risk analyses that Requirement 12.3.1 describes for requirements that call for one.
If your last validation predates March 31, 2025, expect your next one to cover those requirements in full. Plan the evidence early, because several of them, such as the payment page controls, depend on a working process rather than a single configuration change.
PCI SSC ran a request for comments on v4.0.1 from June 3 to July 20, 2026, to gather input on the standard's future. As of 2026-09-27, it hasn't announced a successor version or a date for one.
A Self-Assessment Questionnaire (SAQ) is PCI SSC's validation tool for merchants and service providers that are eligible to self-assess. For PCI DSS v4.0.1 there are ten: A, A-EP, B, B-IP, C, C-VT, P2PE, SPoC, D for Merchants, and D for Service Providers. Each one is built for a specific kind of payment environment, defined by the eligibility criteria in the SAQ itself.
PCI SSC's advice on choosing is to ask first: contact your merchant bank (acquirer), the payment brands, or other compliance entity to confirm whether you may self-assess and which SAQ fits your environment. The summaries below are a starting point, not a substitute for each SAQ's own criteria, which PCI SSC clarified for SAQs A, A-EP, and C-VT in the v4.0.1 editions of October 2024.
The ten PCI DSS SAQs, summarized from each SAQ's eligibility criteria
SAQ
Built for
SAQ A
Card-not-present merchants (e-commerce or mail and telephone order) that have completely outsourced all account data functions to third parties validated as compliant with PCI DSS, and retain account data, if at all, only on paper that wasn't received electronically
SAQ A-EP
E-commerce merchants that partially outsource payment processing, whose website doesn't itself receive account data but can affect the security of the payment transaction or the payment page
SAQ B
Merchants that use only imprint machines or standalone, dial-out terminals, with no electronic account data storage
SAQ B-IP
Merchants that use only standalone PIN Transaction Security (PTS) point-of-interaction devices, listed by PCI SSC, with an IP connection to the payment processor and no electronic account data storage
SAQ C
Merchants with payment application systems, such as point-of-sale systems, connected to the internet, with no electronic account data storage
SAQ C-VT
Merchants that key transactions one at a time into a third party's web-based virtual payment terminal on an isolated device, with no electronic account data storage
SAQ P2PE
Merchants that enter account data only into payment terminals from a validated point-to-point encryption (P2PE) solution listed by PCI SSC
SAQ SPoC
Merchants that accept payments through a Software-based PIN Entry on COTS (SPoC) solution listed by PCI SSC
SAQ D for Merchants
Merchants that are eligible to self-assess but don't meet the criteria for any other SAQ type
SAQ D for Service Providers
Service providers that a payment brand has defined as eligible to self-assess; it's the only SAQ for service providers
Two PCI DSS requirements target e-commerce skimming, where malicious code running in the consumer's browser captures card data from a payment page. Both were best practice until March 31, 2025 and are required now.
Requirement 6.4.3 covers every payment page script loaded and executed in the consumer's browser, including scripts from third and fourth parties. Each needs a method to confirm it's authorized, a method to assure its integrity, and a place in an inventory with a written business or technical justification for why it's necessary.
Requirement 11.6.1 adds a change- and tamper-detection mechanism that alerts personnel to unauthorized modification of the security-impacting HTTP headers and the script contents of payment pages as the consumer's browser receives them. It runs at least weekly, or at a frequency set by a targeted risk analysis under Requirement 12.3.1. For both requirements, scripts inside a third-party service provider's embedded payment form, such as an iframe, are that provider's responsibility.
From March 31, 2025, SAQ A no longer includes 6.4.3, 11.6.1, or 12.3.1. Merchants using it instead confirm that their site isn't susceptible to attacks from scripts that could affect their e-commerce systems, and PCI SSC notes the change doesn't remove or diminish the underlying requirements. Its March 2025 information supplement, Payment Page Security and Preventing E-Skimming, gives guidance on both requirements.
Compliance · 11 min readWhich PCI DSS SAQ do you need? SAQ types and scopeWhich PCI DSS Self-Assessment Questionnaire fits your payment setup: SAQ A, A-EP, B, B-IP, C, C-VT, P2PE, SPoC and D, who decides, and how scope drives it.
Compliance · 9 min readPCI DSS v4.0.1 explained: versions and 2025 requirementsPCI DSS v4.0.1 explained: how it differs from v4.0, the requirements that took effect March 31, 2025, and what the 2026 request for comments means.
Compliance · 10 min readPCI DSS 6.4.3 and 11.6.1: payment page script securityPCI DSS requirements 6.4.3 and 11.6.1 in plain terms: payment page script inventory, authorization and integrity, tamper detection, and SAQ A eligibility.
Testing · 9 min readPenetration testing vs vulnerability scanningVulnerability scanning vs penetration testing: what each finds, how often each runs, where PCI DSS requires ASV scans, and how the two work together.
Testing · 5 min readHow to scope a penetration test you can act onHow to scope a penetration test you can act on: the question to answer, written authorization, targets and exclusions, rules of engagement and retest.
Testing · 10 min readPenetration testing types and how often to testPenetration test types and cadence: web app, API, external and internal network tests, and what PCI DSS, SOC 2, HIPAA and ISO 27001 say about frequency.
13
Frequently asked questions
Which version of PCI DSS applies right now?
As of 2026-09-26, PCI DSS v4.0.1 is the only active version. PCI DSS v4.0 was retired on December 31, 2024, and every v4.0.1 requirement, including the 51 that were future-dated, has applied since March 31, 2025. PCI SSC ran a request for comments on v4.0.1 in June and July 2026, but it hasn't announced a new version or a date for one.
Do we need a QSA, or can we self-assess?
Your acquirer or the payment brands decide. Some organizations validate with a Report on Compliance completed by a PCI SSC-listed QSA Company; others use a Self-Assessment Questionnaire, which the organization completes and signs itself. Ask your acquirer which validation form applies before you plan the work.
Can we display a PCI badge once we've validated?
PCI SSC says it doesn't issue an official seal, mark, or logo for entities that achieve PCI DSS compliance. Its QSA Program Guide also says the compliant and certified phrases and check-mark logos built on the PCI name may not be used. Your acquirer or the payment brands tell you what evidence of validation to provide and to whom.
How do we check a QSA Company or an ASV?
Use PCI SSC's public lists. The QSA Company list shows whether a company is in good standing or in remediation and which regions it serves, the ASV list shows approved scanning vendors, and the professionals lookup confirms an individual's qualification status. An individual's QSA qualification is active only while they work for a listed QSA Company.
What changed for SAQ A in 2025?
From March 31, 2025, SAQ A no longer includes Requirements 6.4.3, 11.6.1, and 12.3.1, and merchants using it must confirm that their site isn't susceptible to attacks from scripts. PCI SSC says the change doesn't remove or diminish the underlying requirements in PCI DSS itself.
Educational information, not legal advice
Information on this website is general and educational. It isn't legal advice, and it doesn't create a client relationship.
This website doesn't accept cardholder data. Don't send card numbers, card security codes, or compliance documents such as ROCs and AOCs through our contact form.
Service boundary
Security Inspect is not a law firm or a CPA firm and does not provide legal opinions or issue SOC 2 reports. ISO/IEC 27001 certification is performed independently by an accredited certification body. CMMC organization-level assessment authority depends on an active C3PAO listing. Specific PCI services depend on the company’s active PCI SSC program listing and scope.
Talk to a PCI DSS practitioner
Tell us how you take payments, who’s asking you to validate, and by when. We’ll identify a sensible readiness scope and explain the next validation step.