Overview
As the Payment Card Industry–Data Security Requirements (PCI-DSS) marks its 20th anniversary, the areas of accountability are expanding beyond card payment data to encompass a holistic view of merchants’ data security ecosystems across all commerce channels. Although the scope of PCI-DSS is not increasing, per se, as it relates to the security requirements for payment data, merchants must attest to having compliant security processing places across the enterprise. For the first time, merchants can construct their compliance checklists that address the risks in their businesses rather than using a template provided by the PCI standards.
Key questions discussed in this report:
- What is likely to be the impact of PCI 4.0 for merchants?
- How should merchants prepare for PCI 4.0?
- What is changing with PCI 4.0 that is more significant than previous changes?
Companies Mentioned:
American Express, Discover, JCB, Mastercard, PCI Security Standards Council, LLC, Verizon Business, Visa
Book a Meeting with the Author
Related content
PCI DSS v4.0: Reframing Compliance, Cost, and Cybersecurity for Merchants
PCI DSS has undergone continual revision since its inception over 20 years ago. In 2025, PCI expanded horizontally with the advent of version 4.0, which looks at all aspects of an ...
3D Secure’s Next Act: From Checkout Friction to Trust Orchestration
3D Secure was developed to help e-commerce merchants guard against fraud by authenticating cardholders at checkout. But merchants balance fraud losses, liability shifts, checkout c...
Every Merchant Needs a Chief Payments Officer
Payments are no longer just a cost center for merchants; they’re a strategic lever for growth. As responsibilities fragment across finance, IT, and operations, hidden costs and mis...
Make informed decisions in a digital financial world