PCI DSS v4.0 became mandatory April 1, 2024; the 13 future-dated requirements became mandatory March 31, 2025 (Source: PCI SSC, 2026). Ecommerce merchants using redirect/iframe to PCI-validated processors (Shopify, Stripe, PayPal) typically qualify for SAQ A with minimal scope. Direct-processing merchants need an annual QSA assessment at $30K-$150K. Future-dated requirements center on MFA, encryption, automated log review, payment page script monitoring, and targeted risk analyses.
Last verified: Sep 14, 2026.
At a glance
- v4.0 mandatory: April 1, 2024
- 13 future-dated requirements mandatory: March 31, 2025
- SAQ A: redirects/iframe to validated processors
- SAQ D: direct cardholder data storage/processing
- QSA assessment for Level 1 merchants: $30K-$150K
The 13 PCI DSS 4.0 future-dated requirements
These requirements became mandatory March 31, 2025, and any organization that cannot fully implement them must document a targeted risk analysis and compensating controls. The most operationally significant changes for ecommerce merchants center on MFA, encryption, and continuous monitoring.
| Requirement | Description | Merchant Impact |
|---|---|---|
| 8.4.2 | MFA for all access into the CDE, not just remote access | High - extends MFA to internal admin access |
| 8.6.1 / 8.6.2 / 8.6.3 | Application and system account authentication management | High - service account inventory and rotation |
| 10.4.1.1 | Automated log review mechanisms for audit log events | Medium - requires SIEM or log automation |
| 11.3.1.2 / 11.3.1.3 | Internal vulnerability scans via authenticated scanning | Medium - requires authenticated scan credentials |
| 11.6.1 | Change- and tamper-detection mechanisms on payment pages | High for ecommerce - requires page integrity monitoring |
| 12.3.1.1 / 12.3.1.2 / 12.10.4.1 / 12.10.4.2 | Targeted risk analyses for each customized approach | High - documented risk analyses required |
| 3.5.1.1 / 3.5.1.2 / 3.6.1.4 | Encryption of account data at rest for all CDE storage | High if storing PAN; minimal for redirect/iframe merchants |
Source: PCI SSC PCI DSS v4.0 future-dated requirements summary, 2026.
SAQ selection guide
Choosing the correct Self-Assessment Questionnaire determines scope and cost. Most ecommerce merchants using modern processors qualify for SAQ A with the smallest scope.
| SAQ | Eligible Merchants | Requirements Count |
|---|---|---|
| SAQ A | Outsourced to PCI DSS validated processor; no electronic CHD storage, processing, or transmission | 22 requirements |
| SAQ A-EP | Uses redirect or iframe to PCI DSS validated processor but has page that collects card data before redirect | 139 requirements |
| SAQ B | Standalone dial-out terminal; no electronic CHD storage | 41 requirements |
| SAQ B-IP | Standalone PTS-approved payment terminal with IP connection to processor | 78 requirements |
| SAQ C-VT | Virtual terminal; merchant enters CHD one transaction at a time | 79 requirements |
| SAQ C | Payment application systems connected to Internet; no electronic CHD storage | 160 requirements |
| SAQ P2PE | Uses validated P2PE solution with no electronic CHD storage | 33 requirements |
| SAQ D | Merchant stores, processes, or transmits CHD; not eligible for other SAQ | 329 requirements |
Source: PCI SSC SAQ Instruction Guide, 2026.
QSA assessment cost
Direct-processing merchants need annual QSA assessments; SAQ merchants self-assess. QSA assessment cost depends on environment complexity, transaction volume, and the QSA firm.
| Merchant Level | Volume | Assessment Type | Cost (2026) |
|---|---|---|---|
| Level 1 | Over 6M Visa transactions/year | Annual on-site QSA assessment + ROC | $50,000 - $250,000 |
| Level 2 | 1M-6M Visa transactions/year | Annual SAQ + quarterly network scan | $5,000 - $25,000 internal |
| Level 3 | 20K-1M ecommerce or 1M other | Annual SAQ + quarterly network scan | $2,000 - $10,000 internal |
| Level 4 | Under 20K ecommerce or other thresholds | Annual SAQ + quarterly network scan | $1,000 - $5,000 internal |
Source: PCI SSC merchant level definitions and QSA pricing surveys, 2026.
How to reduce PCI scope
Three scope-reduction levers cut cost dramatically: tokenization, network segmentation, and validated P2PE solutions. Tokenization replaces PAN with a token that has no value outside the merchant's environment, eliminating that system from PCI scope. Network segmentation isolates the CDE from the rest of the corporate network. Validated P2PE solutions move the merchant's CHD handling into a PCI-listed hardware and software combination that dramatically reduces SAQ scope.
Internal links
See related compliance guides: PCI DSS compliance cost, Cyber insurance application checklist, and Stripe vs Adyen vs Braintree.
FAQs
See FAQ section above for PCI DSS 4.0 deadline guidance, future-dated requirements detail, SAQ selection, QSA assessment cost, and scope-reduction tactics.
PCI DSS 4.0 documentation requirements
PCI DSS 4.0 documentation requirements expanded versus v3.2.1. New requirements include targeted risk analyses for customized approaches and updated evidence for emerging technologies.
| Document | Purpose | Update Frequency |
|---|---|---|
| System Security Plan (SSP) | Documents all security controls in scope | Annual review + change-driven updates |
| Network Diagram | Shows CDE boundaries and data flows | Annual review + change-driven updates |
| Information Security Policy | Governs all security practices | Annual review |
| Risk Assessment | Documents threats, vulnerabilities, likelihood, impact | Annual |
| Penetration Test Report | Documents pen test methodology, findings, remediation | Annual + significant changes |
| Targeted Risk Analyses | Justifies customized approaches for specific requirements | Per customized requirement |
Source: PCI SSC documentation requirements, 2026.
FAQ expansion
Q: Does PCI DSS 4.0 require annual penetration testing? Yes. PCI DSS 4.0 requires penetration testing at least annually and after any significant change to the CDE. Tests must cover all CDE components and perimeter networks, follow a defined methodology, include both application and network layers, and result in a documented remediation plan.
Q: What is a customized approach in PCI DSS 4.0? A customized approach allows organizations to meet the intent of a requirement using alternative methods. Each customized approach requires a targeted risk analysis that demonstrates the alternative provides equivalent or greater security. Customized approaches were introduced in PCI DSS 4.0 to allow innovation while maintaining security intent.
Q: Can small merchants self-assess PCI DSS? Yes. Most Level 2-4 merchants self-assess using the appropriate SAQ (A, A-EP, B, B-IP, C-VT, C, P2PE, D). SAQ completion does not require a QSA. Level 1 merchants (over 6M Visa transactions/year) must complete an annual on-site QSA assessment and submit a Report on Compliance (ROC).






