Get Demo
↑

PCI DSS v4 Future-Dated Requirements (March 31, 2025)

The 51 PCI DSS v4.0.

Published: September 2026 Compliance · PCI DSS 10–14 min read

When PCI DSS v4.0 shipped, a defined subset of its new requirements was labeled a best practice until 31 March 2025. After that date those IDs must be fully considered in a PCI DSS assessment. That set is 51 requirement entries — not every new control in v4.0, and not every change introduced by the later v4.0.1 limited revision.

Related: What is PCI DSS v4.0.1 · 12-requirement hub · Customized Approach · TRA required elements · Gap assessment.

Sourcing: Requirement IDs come from PCI DSS – Summary of Changes from PCI DSS Version 3.2.1 to 4.0 (r2), §6 Summary of New Requirements, column 31 March 2025 (totals row: 51). The Summary of Changes from PCI DSS Version 4.0 to 4.0.1 does not re-list these IDs; PCI SSC confirmed v4.0.1 added no requirements and did not change the 31 March 2025 effective date. Each ID below still carries the “best practice until 31 March 2025” Applicability Note in PCI DSS v4.0.1.

What This List Is Not

Footnote Key

The 51 Future-Dated Requirement IDs

Requirement 3

3.2.1† · 3.3.2 · 3.3.3† · 3.4.2 · 3.5.1.1 · 3.5.1.2 · 3.6.1.1

Requirement 4

4.2.1† · 4.2.1.1

Requirement 5

5.2.3.1 · 5.3.2.1 · 5.3.3 · 5.4.1

Requirement 6

6.3.2 · 6.4.2 · 6.4.3

Requirement 7

7.2.4 · 7.2.5 · 7.2.5.1

Requirement 8

8.3.6 · 8.3.10.1‡ · 8.4.2 · 8.5.1 · 8.6.1 · 8.6.2 · 8.6.3

Requirement 9

9.5.1.2.1

Requirement 10

10.4.1.1 · 10.4.2.1 · 10.7.2 · 10.7.3§

Requirement 11

11.3.1.1 · 11.3.1.2 · 11.4.7‡ · 11.5.1.1‡ · 11.6.1

Requirement 12

12.3.1 · 12.3.3 · 12.3.4 · 12.5.2.1‡ · 12.5.3‡ · 12.6.2 · 12.6.3.1 · 12.6.3.2 · 12.10.4.1 · 12.10.5† · 12.10.7

Appendix A

A1.1.1‡ · A1.1.4‡ · A1.2.3‡ · A3.3.1†

Not in this list (examples of immediate v4.x new requirements): roles-and-responsibilities IDs such as 2.1.2–11.1.2, 12.3.2 (Customized Approach TRA — immediate when Customized is used), 12.5.2, and 12.9.2. See the Customized Approach guide for 12.3.2.

How to Use This List

  1. Confirm merchant vs service provider and which Appendix A sections apply.
  2. Map each in-scope ID to owners, evidence, and remediation status in a gap assessment.
  3. Where an ID calls for a targeted risk analysis for activity frequency, use the required elements in 12.3.1 / 12.3.2 — do not invent a proprietary TRA layout the standard does not prescribe.
  4. Re-check wording in PCI DSS v4.0.1 (not only secondary blogs); Applicability Notes remain authoritative for scope and effective-date language.

How CyberSilo Helps

Score the March 2025 IDs Against Your CDE

CyberSilo helps merchants and service providers gap the future-dated set, collect evidence, and prepare for assessment against PCI DSS v4.0.1.

Frequently Asked Questions

Are the 51 future-dated IDs all of the new requirements in PCI DSS v4.0?

No. PCI DSS v4.0 introduced 64 new requirements in total: 13 effective immediately for v4.0 assessments and 51 that were best practices until 31 March 2025. This page lists only the 51.

Did PCI DSS v4.0.1 change the March 31, 2025 deadline?

No. The limited revision from v4.0 to v4.0.1 added no requirements and did not change the effective date of the future-dated set.

Is Requirement 12.3.2 future-dated?

No. 12.3.2 (targeted risk analysis for each requirement met with the Customized Approach) is effective immediately for entities using the Customized Approach. It is not in the March 31, 2025 set.

What is PCI DSS v4.0.1 · 12-requirement hub · Customized Approach · TRA required elements · Gap assessment · PCI DSS hub