{"id":48492,"date":"2024-04-02T14:42:43","date_gmt":"2024-04-02T12:42:43","guid":{"rendered":"https:\/\/www.usd.de\/?p=48492"},"modified":"2024-04-11T09:24:51","modified_gmt":"2024-04-11T07:24:51","slug":"pci-dss-v4-transition-phase-ends","status":"publish","type":"post","link":"https:\/\/www.usd.de\/en\/pci-dss-v4-transition-phase-ends\/","title":{"rendered":"PCI DSS v4.0: The Transition Phase Is Over. What Will Change for You?"},"content":{"rendered":"\n<p>On March 31, 2024, the previous version 3.2.1 of the Payment Card Industry Data Security Standard (PCI DSS) expired. While companies were able to decide for themselves which version of the standard to base their PCI assessment on during the two-year transition phase, the guideline has been clear: since April 1, 2024, all assessments for the annual review of PCI DSS compliance must be carried out in accordance with version 4.0.<\/p>\n\n\n\n<p>Are you facing your first PCI DSS v4.0 assessment this year? Are you wondering what will change for you? In this blog post, we give you a brief overview:<\/p>\n\n\n\n<div style=\"height:23px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 class=\"wp-block-heading\">Are PCI DSS v4.0 assessments different?<\/h2>\n\n\n\n<p>No, the assessment process remains essentially the same. Planning, conducting and dealing with findings will not change with the new version. Our assessors will continue to start with a kick-off and may request initial documents as part of the assessment planning before the actual assessment is carried out. Assessments may continue to be carried out remotely, provided the environment under assessment allows it.<\/p>\n\n\n\n<p>Most of the changes can be found in the relevant documentation, the evidences and, of course, in the requirements themselves.<\/p>\n\n\n\n<div style=\"height:23px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 class=\"wp-block-heading\">Update of RoC and AoC<\/h2>\n\n\n\n<p>After successful completion of the assessment, your QSA will create a \"Report on Compliance\" (RoC) and an \"Attestation of Compliance\" (AoC) for you to prove compliance with the PCI DSS. These two documents have been revised as part of the new version 4.0, but their structure has remained the same. Your PCI assessor is already using the new templates, so there is no need for you to familiarize yourself with the revised documents.<\/p>\n\n\n\n<div style=\"height:23px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 class=\"wp-block-heading\">More detailed evidence required<\/h2>\n\n\n\n<p>The RoC describes how the individual PCI DSS requirements are implemented in your company, i.e. the security situation, the environment, the systems and the protection of cardholder data in your company. It also documents how the PCI assessor proceeded when checking the respective requirement.<\/p>\n\n\n\n<p>PCI DSS v4.0 will require more detailed evidence in the RoC from now on. Confirmation of compliance will no longer be sufficient, but references to specific configurations, screenshots or documentation will also be required. Example: While it was previously sufficient for your assessor to confirm that your company complies with the requirement for a minimum password length, the PCI DSS v4.0 RoC now requires proof that this is enforced.<\/p>\n\n\n\n<div style=\"height:23px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 class=\"wp-block-heading\">New requirements<\/h2>\n\n\n\n<p>A total of 64 new requirements were introduced with version 4.0. Only a comparatively small number, specifically 13 requirements, have become mandatory as of April 1, 2024. These must be implemented in time for your next assessment if they have not already been implemented.<\/p>\n\n\n\n<p>The remaining new security requirements in PCI DSS v4.0 are marked as \"future-dated\". The <a href=\"https:\/\/www.pcisecuritystandards.org\/\" target=\"_blank\" rel=\"noopener\">PCI Council<\/a> has granted an additional year to implement these requirements. However, these must also be fully implemented as described in the standard by March 31, 2025 at the latest. Until these requirements officially come into effect, they count as best practice.<\/p>\n\n\n\n<p>What does this mean for you? Your PCI assessor will discuss the status of implementation in the next assessment, but will only document recommendations rather than a finding in the event of non-compliance or insufficient compliance. While this might sound reassuring for now, we recommend that you start reviewing and implementing future-dated requirements in good time, as some of these will require quite some effort and have significant consequences.<\/p>\n\n\n\n<p>The following future-dated requirements, for example, require extensive implementation:<\/p>\n\n\n\n<p><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Requirement 3.5.1.2<\/strong>: Disk encryption is only acceptable for removable media<\/li>\n\n\n\n<li><strong>Requirement 3.5.1.1<\/strong>: Hashing of PANs must use keyed cryptographic hashing algorithm<\/li>\n\n\n\n<li><strong>Requirement 3.4.2<\/strong>: Prevention of PAN copying while using remote-access technologies<\/li>\n\n\n\n<li><strong>Requirement 6.4.3, 11.6.1<\/strong>: Payment Page protection<\/li>\n\n\n\n<li><strong>Requirements 7.2.5, 7.2.5.1, 8.6.1-3, 10.2.1.2<\/strong>: Handling of technical accounts<\/li>\n<\/ul>\n\n\n\n<div style=\"height:23px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<div class=\"wp-block-columns is-layout-flex wp-container-core-columns-is-layout-9d6595d7 wp-block-columns-is-layout-flex\">\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\" style=\"flex-basis:66.66%\">\n<p>\"The first PCI certification according to the new standard is an important milestone for many companies,\" explains Torsten Schlotmann, Head of PCI Security Services at usd AG. \"But we strongly advise addressing the future-dated requirements as soon as posssible since they present some major technical challenges. Take advantage of our <a href=\"https:\/\/www.usd.de\/en\/category\/pci-news-en\/\">blog posts<\/a>, <a href=\"https:\/\/www.youtube.com\/@usdAG\" target=\"_blank\" rel=\"noopener\">webinar recordings<\/a> and <a href=\"https:\/\/www.usd.de\/en\/cst-academy\/events\/\">upcoming webinars<\/a> on PCI DSS v4.0 or <a href=\"https:\/\/www.usd.de\/en\/contact-form-pci\/\">get in touch<\/a> with my team. We will support you, no matter where you stand.\"<\/p>\n<\/div>\n\n\n\n<div class=\"wp-block-column is-vertically-aligned-center is-layout-flow wp-block-column-is-layout-flow\" style=\"flex-basis:33.33%\">\n<figure class=\"wp-block-image aligncenter size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"384\" height=\"384\" src=\"https:\/\/www.usd.de\/wp-content\/uploads\/software-security-zitat-ts-1.jpg\" alt=\"\" class=\"wp-image-48524\" style=\"width:160px\"\/><figcaption class=\"wp-element-caption\">Torsten Schlotmann<\/figcaption><\/figure>\n<\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>On March 31, 2024, the previous version 3.2.1 of the Payment Card Industry Data Security Standard (PCI DSS) expired. While companies were able to decide for themselves which version of the standard to base their PCI assessment on during the two-year transition phase, the guideline has been clear: since April 1, 2024, all assessments for [&hellip;]<\/p>\n","protected":false},"author":90,"featured_media":48491,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_et_pb_use_builder":"off","_et_pb_old_content":"","_et_gb_content_width":"","inline_featured_image":false,"footnotes":""},"categories":[373,394,389],"tags":[8476,434,6470,6471,440,484,3423,8477,8478],"class_list":["post-48492","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news-en","category-pci-en","category-security-audits-en","tag-payment-card-industry-data-security-standard-en","tag-pci-en","tag-pci-assessment-en","tag-pci-audit-en","tag-pci-dss-en","tag-pci-dss-4-0-en","tag-pci-dss-v4-0-en","tag-pci-dss-version-4-0-en","tag-transition-en"],"_links":{"self":[{"href":"https:\/\/www.usd.de\/en\/wp-json\/wp\/v2\/posts\/48492","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.usd.de\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.usd.de\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.usd.de\/en\/wp-json\/wp\/v2\/users\/90"}],"replies":[{"embeddable":true,"href":"https:\/\/www.usd.de\/en\/wp-json\/wp\/v2\/comments?post=48492"}],"version-history":[{"count":5,"href":"https:\/\/www.usd.de\/en\/wp-json\/wp\/v2\/posts\/48492\/revisions"}],"predecessor-version":[{"id":48675,"href":"https:\/\/www.usd.de\/en\/wp-json\/wp\/v2\/posts\/48492\/revisions\/48675"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.usd.de\/en\/wp-json\/wp\/v2\/media\/48491"}],"wp:attachment":[{"href":"https:\/\/www.usd.de\/en\/wp-json\/wp\/v2\/media?parent=48492"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.usd.de\/en\/wp-json\/wp\/v2\/categories?post=48492"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.usd.de\/en\/wp-json\/wp\/v2\/tags?post=48492"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}