PCI DSS
The cardholder-data standard every merchant and service provider that touches payment card data is measured against. v4.0 retired 2024-12-31; the 51 future-dated v4.x requirements became mandatory 2025-03-31.
v4.0.1 · PCI Security Standards Council · published 2024-06-11
01Standing
Named, with the authority's acquisition path recorded; onboarding is refused until a control set is registered.
PCI DSS cannot be onboarded yet: Freely published; not ingested as a control catalog. Onboarding is enabled once a control set is registered, so a new project never opens into an empty workspace.
PCI DSS cannot be onboarded yet: Freely published; not ingested as a control catalog. Onboarding is enabled once a control set is registered, so a new project never opens into an empty workspace.
02Registry record
- Registry status
- Roadmap · modelledWe model the regime — control families and at least one crosswalk map on disk — but no control catalog is ingested.
- Control units
- Not on record — no catalog ingested and no authority-published count cited.
- Control families
- Network security · Account data · Vulnerability management · Access control · Monitoring and testing
- Applies to
- payments · retail · SaaS · global
- Verification
- Secondary — corroborated across independent sources; the authority blocks automated fetch or does not state it plainly. checked 2026-08-06
- Pending change
- PCI SSC opened a request-for-comments on v4.0.1 running 2026-06-03 to 2026-07-20. No successor version has been announced.Expected: Unannounced
03Version ledger
| v3.2.1 | Superseded | date not published |
| v4.0 | Superseded · supersedes v3.2.1 | 2022-03-31 |
| v4.0.1 | Current edition · supersedes v4.0 | 2024-06-11 |