PCI DSS v4.0.1 is the current standard
On June 11, 2024, the PCI Security Standards Council (PCI SSC) published Payment Card Industry Data Security Standard (PCI DSS) v4.0.1. It is a limited revision of v4.0: clarifications and guidance edits, with no requirements added or removed. v4.0.1 is the current version of the standard.
This item was added to the change feed at launch so followers can see the kind of version update a PCI DSS subscription covers. It is not a new announcement.
What changed
PCI DSS v4.0, published March 31, 2022, was the largest rewrite of the standard since v1.0. It added a customized approach, stronger continuous-security expectations, and new requirements with a phased rollout. v4.0.1 did not reopen that rewrite. It corrected and clarified the v4.0 text so assessors and organizations were working from the same wording.
The future-dated v4 requirements that had been optional after v4.0 was published became mandatory on March 31, 2025. Organizations still assessing against v3.2.1 after that date were past the retirement of the old standard.
What did not change
The 12 requirements and the SAQ versus Report on Compliance (ROC) validation model did not change in v4.0.1. Your acquirer or payment brand still decides which validation path you use. A v4.0.1 assessment is still a point-in-time record tied to a defined cardholder data environment, not a permanent certificate.
What to do now
- Confirm with your acquirer or payment brand which PCI DSS version and validation path (SAQ or ROC) they currently require.
- If you have not yet closed the v4 future-dated requirements that became mandatory on March 31, 2025, treat those gaps as current findings, not as a future project.
- Get v4.0.1 documents from the PCI SSC Document Library, not from a vendor copy of v4.0.
- See the PCI DSS page for who it applies to, how validation works, and what to ask the party that receives your paperwork.
- Follow PCI DSS on this site for later Council updates, FAQ changes, and version news.