Get Demo
↑

PCI DSS Requirement 4: Encrypting Cardholder Data in Transit

PCI DSS v4.0.1 Requirement 4 - strong cryptography for PAN on open, public networks; trusted certs; no insecure protocol fallback.

Published: September 2026 Compliance · PCI DSS 8-12 min read

PCI DSS Requirement 4 in v4.0.1 is titled Protect Cardholder Data with Strong Cryptography During Transmission Over Open, Public Networks. If PAN crosses the Internet or other untrusted networks, strong cryptography and trustworthy certificates are mandatory.

Related: Requirement 3 (at rest) · PCI DSS hub.

Requirement 4 Structure

Clause
Focus
4.1
Processes and mechanisms for protecting CHD in transit (4.1.1 policies; 4.1.2 roles)
4.2
PAN is protected with strong cryptography during transmission

Deep Dives

Certificate validity/revocation checks in 4.2.1 and the inventory in 4.2.1.1 were best practice until 31 March 2025 and are now required.

How CyberSilo Helps

Map PCI DSS v4.0.1 Controls to Continuous Evidence

CyberSilo CSA and ThreatHawk SIEM help US merchants and service providers collect QSA-ready evidence across the 12 requirements.

Frequently Asked Questions

Are TLS 1.0 and 1.1 acceptable?

No. 4.2.1 requires protocols that support only secure versions/configurations and do not fall back to insecure versions, algorithms, key sizes, or implementations.

Do self-signed certificates work?

Self-signed certs where issued-by and issued-to Distinguished Names match are not acceptable. An internal CA-issued certificate can be acceptable if authorship is confirmed, the cert is verified (for example hash/signature), and it has not expired.

What about PAN sent by email or chat?

4.2.2 requires strong cryptography whenever PAN is sent via end-user messaging technologies - including when a customer asks for it that way.

PCI DSS hub · PCI DSS v4.0.1: What Changed · USA v4.0.1 services

📰 More from CyberSilo

Latest Articles

Stay ahead of evolving cyber threats with our expert insights

✅ Link copied!