
Discover key takeaways from industry leaders and our tips for organizations making the journey toward PCI 4.0 compliance
Do you deal with payment cards? Did you miss the PCI SSC Community Meeting? Let me get you up to speed.
Last week in Portland, experts and professionals from the payment card industry came together to discuss the latest data security and compliance developments. Among the many valuable insights, a few themes stood out.
In just six short months, PCI 3.2.1 is set to retire.
What does this mean? Organizations that handle payment card data need to get ahead of PCI 4.0 ASAP. The changes between versions are significant, and making the appropriate updates to reach compliance may take longer than expected.
2. Get to know requirements 11.6.1 and 6.4.3; you’ll hear them nonstop.
Here's a quick refresher:
11.6.1: Organizations need to deploy a change-and-tamper detection mechanism to alert for unauthorized modifications to HTTP headers and contents of payment pages.
6.4.3: For all payment page scripts that are loaded and executed in the consumer’s browser, a method must be implemented to confirm that each script is authorized and to assure the integrity of each script.
If you are outsourcing payment pages, using iFrames, redirects or handling them yourself - these requirements will apply. Moreover, they're in scope for every SAQ level, all the way down to SAQ - A!
For these requirements, meeting compliance may be a heavier lift than expected. These are some of the concerns I heard:
The roadmap to PCI 4.0 compliance can be overwhelming, and addressing these questions will require a strategic approach. However, with the right planning and tools, organizations can meet compliance without breaking the bank.
Here are my tips for organizations navigating PCI 4.0:
The upcoming shift from PCI 3.2.1 to PCI 4.0 poses big challenges for payment card industry players. Navigating requirements like 11.6.1 and 6.4.3 can be tricky, but with smart planning, teamwork, and the right tech tools, companies can stay compliant without causing major disruptions.
Interested in learning more about how we're handling PCI 4.0 at DataStealth? Send us a message!
Written by Lindsay Kleuskens, Business Development of DataStealth.io