PCI DSS 4.0.1
PCI Compliance Testing & DSS 4.0.1 Readiness
If your business stores, processes or transmits cardholder data, PCI DSS isn’t optional — and since 31 March 2025, neither are the 51 future-dated requirements in v4.x. iFlock scopes your cardholder data environment, runs the scanning and testing the standard requires, and gets you validation-ready — working alongside your assessor, not instead of one.
What changed in PCI DSS — and why it got harder
PCI DSS has moved from a once-a-year checklist to a standard that expects controls running all year round. Here is what that means in practice for a business that takes card payments in 2026.
Every v4.x requirement is now in force
PCI DSS v4.0 introduced 64 new requirements. Of those, 51 were future-dated — and they became mandatory on 31 March 2025. v4.0 and v4.0.1 are the only active versions; v3.2.1 was retired in March 2024. There is no “best practice until later” column left to shelter behind. Source: PCI Security Standards Council
Small e-commerce merchants lost the easy path
Since 1 April 2025, a merchant using an embedded payment form — an iframe served by their processor — can only use SAQ A if they confirm their site is not susceptible to script attacks. That means implementing the controls in Requirements 6.4.3 and 11.6.1, or obtaining assurance from a PCI DSS compliant provider that their embedded solution covers it. Merchants using a full redirect are not affected. Source: PCI SSC FAQ 1588
Scanning and testing are on a clock
External ASV scans run at least every three months and after any significant change, with internal scans on the same cycle. Internal and external penetration testing is required at least annually and after significant change, and segmentation controls must be tested at least annually — every six months for service providers. Holding that cadence is exactly what continuous vulnerability management is for.
The attacks aren’t aimed where most people look
In Verizon’s 2026 DBIR retail snapshot, exploiting a known vulnerability was the number one way in at 42% — ahead of credential abuse (14%) and phishing (9%) — and 68% of retail breaches involved a third party. Patch discipline and vendor oversight are PCI work now, not just IT housekeeping. Source: Verizon 2026 Data Breach Investigations Report, retail snapshot
v5.0 is coming, but it isn’t here
The PCI Security Standards Council has signalled that a future update will address AI systems, but no release date has been announced. Build on v4.0.1 now — a solid v4.x programme is the shortest path to whatever comes next. If you have other frameworks in flight, our compliance & risk and audit readiness teams run them alongside PCI.
Book a PCI readiness call
51
of the 64 new PCI DSS v4.x requirements became mandatory on 31 March 2025
PCI Security Standards Council
42%
of retail breaches start with an exploited vulnerability — the sector’s number one way in
Verizon 2026 DBIR, retail snapshot
68%
of retail breaches involved a third party somewhere in the chain
Verizon 2026 DBIR, retail snapshot
$33.41B
lost to card fraud worldwide in 2024, with 41.87% of it in the United States
The Nilson Report, January 2026
What’s included
What iFlock’s PCI services cover
Scoping & gap analysis
We map exactly which systems fall inside your cardholder data environment and where you fall short of v4.0.1 today, so effort goes where it counts. Segmentation done properly is the cheapest way to shrink an assessment.
The right validation path
There are several SAQ types, four merchant levels and a full Report on Compliance at the top. We work out which one applies to you and help you complete it accurately the first time.
ASV scanning
The quarterly external scans PCI DSS requires, on the schedule it requires — plus help clearing the findings, rather than a PDF of them landing on your desk.
Penetration testing
Requirement 11.4 calls for internal and external testing annually and after significant change. Our white-hat team does this work every week — see penetration testing.
Payment page script controls
The Requirement 6.4.3 and 11.6.1 controls that keep skimming code off your checkout page — and keep e-commerce merchants eligible for SAQ A under the 2025 criteria.
Remediation & evidence
We help fix what we find and assemble the evidence your assessor will ask for, so the assessment isn’t an archaeology project six weeks before the deadline.
How we work
What a PCI engagement looks like
- 1
Scope
We define the cardholder data environment and every system that connects to it or could affect it — the step that decides how big everything else gets.
- 2
Assess
A gap analysis against PCI DSS v4.0.1, plus the vulnerability scanning and penetration testing the standard requires.
- 3
Remediate
A prioritised plan written in plain language, and our people working alongside yours to close the gaps rather than just listing them.
- 4
Validate
We prepare your SAQ or your Report on Compliance evidence pack and work alongside your QSA — yours, or one we recommend.
- 5
Sustain
Quarterly scanning, annual testing and the continuous controls v4.x expects, so next year’s validation is a formality. Available through our managed security programme.
Questions
PCI compliance FAQs
Is iFlock a PCI QSA?
No — and we say so plainly. iFlock is not a Qualified Security Assessor and does not issue Reports on Compliance. We get you ready, run the scanning and testing, and work alongside your assessor. We can work with your preferred QSA or recommend one for you.
Which version of PCI DSS applies right now?
PCI DSS v4.0.1. Together with v4.0 it is one of only two active versions — v3.2.1 was retired on 31 March 2024 — and all 51 future-dated v4.x requirements became mandatory on 31 March 2025. The Council has signalled a future v5.0 addressing AI systems, but no release date has been announced.
Do we need a SAQ or a full Report on Compliance?
It depends on your merchant level, which the card brands set from your annual transaction volume, and on how you handle card data. Most small and mid-sized merchants complete a Self-Assessment Questionnaire; Level 1 merchants and many service providers need a Report on Compliance signed by a QSA. We settle this during scoping so you are not preparing for the wrong thing.
We use a hosted checkout — are we out of scope?
Rarely completely. A full redirect to your processor keeps your scope small. An embedded payment form served in an iframe does not: since 1 April 2025, SAQ A eligibility also requires confirming your site is not susceptible to script attacks, either through Requirements 6.4.3 and 11.6.1 or through assurance from your provider.
How often do we have to scan and test?
External ASV scans at least every three months and after any significant change, with internal vulnerability scans on the same cycle. Internal and external penetration testing at least annually and after significant change. Segmentation controls tested at least annually — every six months if you are a service provider.
What actually happens if we’re not compliant?
Non-compliance is settled between you, your acquiring bank and the card brands rather than by the PCI Security Standards Council. In practice it means monthly non-compliance fees, worse transaction rates, liability for fraud losses and forensic investigation costs after a breach, and in the worst case losing the ability to accept cards at all. The amounts are set by your acquirer and the brands — so ask them, and then make sure you never find out.
Find out where you actually stand on PCI
A no-obligation conversation with an engineer who does this work — not a sales call. We will tell you which validation path applies, what your scope really looks like, and what it takes to close the gap.